Mercurial > prosody-hg
view plugins/mod_auth_insecure.lua @ 14181:6fb6e383123f 13.0
util.signal: Fix signalfd closure on non-Linux systems
The loop was incorrect for 0-indexed arrays. It started at signalfd_num, which
is the total number of signalfds, and decremented to 1 (condition was >0). So
if 1 signalfd was registered, it would check only signalfds[1]. At capacity
(32 signalfds) it would read past the end of the array. In every case, it
would always skip the entry at position [0], leading to a leak.
The swap-with-tail removal of the matched item used the post-decrement
operator, leading to accessing the array slot just beyond the tail.
Finally, it didn't break after finding a match. Probably harmless, but there
isn't expected to be more than a single entry per fd, as far as I can tell.
| author | Matthew Wild <mwild1@gmail.com> |
|---|---|
| date | Mon, 25 May 2026 16:02:39 +0100 |
| parents | 74b9e05af71e |
| children |
line wrap: on
line source
-- Prosody IM -- Copyright (C) 2008-2010 Matthew Wild -- Copyright (C) 2008-2010 Waqas Hussain -- -- This project is MIT/X11 licensed. Please see the -- COPYING file in the source package for more information. -- -- luacheck: ignore 212 local datamanager = require "prosody.util.datamanager"; local new_sasl = require "prosody.util.sasl".new; local saslprep = require "prosody.util.encodings".stringprep.saslprep; local host = module.host; local provider = { name = "insecure" }; assert(module:get_option_string("insecure_open_authentication") == "Yes please, I know what I'm doing!"); function provider.test_password(username, password) return true; end function provider.set_password(username, password) local account = datamanager.load(username, host, "accounts"); password = saslprep(password); if not password then return nil, "Password fails SASLprep."; end if account then account.updated = os.time(); account.password = password; return datamanager.store(username, host, "accounts", account); end return nil, "Account not available."; end function provider.user_exists(username) return true; end function provider.create_user(username, password) local now = os.time(); return datamanager.store(username, host, "accounts", { created = now; updated = now; password = password }); end function provider.delete_user(username) return datamanager.store(username, host, "accounts", nil); end function provider.get_sasl_handler() local getpass_authentication_profile = { plain_test = function(sasl, username, password, realm) return true, true; end }; return new_sasl(module.host, getpass_authentication_profile); end module:add_item("auth-provider", provider);
