已关闭
[Bug]: pg_basebackup 释放口令前只清零前 8 字节 #8482
Wwwing301创建于  9月7日关闭于  24 天前
Wwwing301
9月7日 创建

测试类型

安全

测试版本

7.0.0LTS

问题描述

pg_basebackup 等工具在释放数据库口令前会调用 ClearAndFreePasswd() 清零内存。当前代码使用 sizeof(dbpassword) 作为长度,但 dbpassword 是指针,所以 64 位进程中结果始终是 8,而不是口令的真实长度。

使用 32 字节测试口令时,释放前只有前 8 字节被清零,后 24 字节仍保留原内容。

操作系统和硬件信息

Ubuntu 22.04.5 LTS,x86_64,指针宽度 8 字节。

测试环境

企业版单机

被测功能

本次只运行独立 C++ 最小测试。测试程序在释放前检查自己的合成口令缓冲区,不读取其他进程。
pg_basebackup、pg_receivexlog 和 pg_recvlogical 共用的口令内存清理函数。

预置条件

安装支持 C++17 的 g++,并将附件 poc.cc 保存到当前目录。

操作步骤

g++ -std=gnu++17 -O0 -g poc.cc -o poc
./poc full-wipe-control
./poc current-trigger

预期输出

释放口令前应清零整个缓冲区。32 字节测试口令的残留字节数应为 0。

实际输出

完整清零对照:

RESIDUAL=0 POINTER_SIZE=8

当前函数:

RESIDUAL=24 POINTER_SIZE=8

日志信息

相关代码:

  • src/bin/pg_basebackup/streamutil.cpp:37,120-127,217-231
  • src/bin/pg_basebackup/pg_basebackup.cpp:1419,2188
  • src/bin/pg_basebackup/pg_receivexlog.cpp:225
  • src/bin/pg_basebackup/pg_recvlogical.cpp:326,969

提单组织

社区用户

测试代码

#include <cstdio>
#include <cstdlib>
#include <cstring>
#include <string>

using errno_t = int;
char *dbpassword = nullptr;
static unsigned char observed[33];
static constexpr std::size_t observed_size = 32;

static errno_t memset_s(void *dest, std::size_t dest_max, int value, std::size_t count)
{
    if (dest == nullptr || count > dest_max) return 1;
    std::memset(dest, value, count);
    return 0;
}

static void tracked_free(void *ptr)
{
    std::memcpy(observed, ptr, observed_size);
    std::free(ptr);
}

static void current_clear_and_free()
{
    if (dbpassword != nullptr) {
        if (memset_s(dbpassword, sizeof(dbpassword), 0, sizeof(dbpassword)) != 0) std::abort();
        tracked_free(dbpassword);
        dbpassword = nullptr;
    }
}

static void correct_clear_and_free()
{
    if (dbpassword != nullptr) {
        const std::size_t length = std::strlen(dbpassword);
        if (memset_s(dbpassword, length + 1, 0, length + 1) != 0) std::abort();
        tracked_free(dbpassword);
        dbpassword = nullptr;
    }
}

int main(int argc, char **argv)
{
    if (argc != 2) return 2;
    dbpassword = ::strdup("0123456789abcdefghijklmnopqrstuv");
    if (dbpassword == nullptr || std::strlen(dbpassword) != observed_size) return 3;
    const std::string mode(argv[1]);
    if (mode == "current-trigger") current_clear_and_free();
    else if (mode == "full-wipe-control") correct_clear_and_free();
    else return 2;
    std::size_t residual = 0;
    for (unsigned char value : observed) residual += value != 0;
    std::printf("RESIDUAL=%zu POINTER_SIZE=%zu\n", residual, sizeof(dbpassword));
    if (mode == "current-trigger")
        return residual == observed_size - sizeof(dbpassword) ? 0 : 4;
    return residual == 0 ? 0 : 4;
}
likedislike
opengauss_bot
opengauss_bot成员
9月7日 评论:

This issue requires an assignee. Since you haven't specified one, we've assigned TestManager as the default assignee for this issue.

likedislike
opengauss_botopengauss_bot成员
9月7日 将 TestManager 设为负责人
opengauss_bot
opengauss_bot成员
9月7日 评论:

Welcome To openGauss Community

Hey @Wwwing301 , thanks for your contribution to the community.

Bot Usage Manual

I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands. You can self-configure the PR merge rules for this repository. For more details, please refer to Here.

Contact Guide

If you have any questions, please contact the SIG: StorageEngine, AI, CM, CloudNative, SecurityTechnology, SQLEngine ,
and any of the maintainers: @CarrotGo, @chendong76, @chenxiaobin19, @congzhou2603, @dodders, @hwworkholic, @jemappellehc, @libiao2024, @muyulinzhong, @quemingjian, @shenzheng4, @shirley_zhengx, @superlchf, @totaj, @wlff234, @wofanzheng, @ywzq1161327784 ,
and any of the committers: @Igali, @bihua111, @cailei19, @h_ray, @levy53071, @libiao2024, @lihaixiao, @mrzack, @wangfeihuo, @wuyuechuan, @xiong_xjun, @zhangfengzhi123, @zhangxubo, @zhangzq131, @zjh_hw .

likedislike
opengauss_botopengauss_bot成员
9月7日 添加了label:sig/Tools
liuzhen001liuzhen001成员
9月7日 关联了看板:openGauss 7.0.0-LTS
IIgali成员
9月8日 将 zcj112 设为负责人
IIgali成员
9月9日 移除了负责人 TestManager
chendong76chendong76成员
29 天前 将 Eurekaxun 设为负责人
chendong76chendong76成员
29 天前 移除了负责人 zcj112
徐文贵徐文贵成员
28 天前 关联了pull request:[7.0.0] 修复口令清零、SHOW 清理及加解密问题
徐文贵徐文贵成员
28 天前 关联了pull request:[master] 修复口令清零、SHOW 清理及加解密问题
徐文贵
徐文贵成员
27 天前 评论:

B023【白盒】
image.png

likedislike
徐文贵徐文贵成员
27 天前 issue状态由 待办的 改变为 待回归
l1azzzy
l1azzzy成员
24 天前 评论:

验收日期:2026-9-15
验收结论:验收通过
验收版本:7.0.0.B023
image.png
image.png

likedislike
l1azzzyl1azzzy成员
24 天前 issue状态由 待回归 改变为 已验收
l1azzzyl1azzzy成员
24 天前 关闭了 issue