This issue requires an assignee. Since you haven't specified one, we've assigned TestManager as the default assignee for this issue.


Welcome To openGauss Community
Hey @Wwwing301 , thanks for your contribution to the community.
Bot Usage Manual
I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands. You can self-configure the PR merge rules for this repository. For more details, please refer to Here.
Contact Guide
If you have any questions, please contact the SIG: StorageEngine, AI, CM, CloudNative, SecurityTechnology, SQLEngine ,
and any of the maintainers: @CarrotGo, @chendong76, @chenxiaobin19, @congzhou2603, @dodders, @hwworkholic, @jemappellehc, @libiao2024, @muyulinzhong, @quemingjian, @shenzheng4, @shirley_zhengx, @superlchf, @totaj, @wlff234, @wofanzheng, @ywzq1161327784 ,
and any of the committers: @Igali, @bihua111, @cailei19, @h_ray, @levy53071, @libiao2024, @lihaixiao, @mrzack, @wangfeihuo, @wuyuechuan, @xiong_xjun, @zhangfengzhi123, @zhangxubo, @zhangzq131, @zjh_hw .


B023【白盒】



验收日期:2026-9-15
验收结论:验收通过
验收版本:7.0.0.B023




测试类型
安全
测试版本
7.0.0LTS
问题描述
pg_basebackup等工具在释放数据库口令前会调用ClearAndFreePasswd()清零内存。当前代码使用sizeof(dbpassword)作为长度,但dbpassword是指针,所以 64 位进程中结果始终是 8,而不是口令的真实长度。使用 32 字节测试口令时,释放前只有前 8 字节被清零,后 24 字节仍保留原内容。
操作系统和硬件信息
Ubuntu 22.04.5 LTS,x86_64,指针宽度 8 字节。
测试环境
企业版单机
被测功能
本次只运行独立 C++ 最小测试。测试程序在释放前检查自己的合成口令缓冲区,不读取其他进程。
pg_basebackup、pg_receivexlog和pg_recvlogical共用的口令内存清理函数。预置条件
安装支持 C++17 的
g++,并将附件poc.cc保存到当前目录。操作步骤
预期输出
释放口令前应清零整个缓冲区。32 字节测试口令的残留字节数应为 0。
实际输出
完整清零对照:
当前函数:
日志信息
相关代码:
src/bin/pg_basebackup/streamutil.cpp:37,120-127,217-231src/bin/pg_basebackup/pg_basebackup.cpp:1419,2188src/bin/pg_basebackup/pg_receivexlog.cpp:225src/bin/pg_basebackup/pg_recvlogical.cpp:326,969提单组织
社区用户
测试代码