util: Introduce virsecureerase module

The module will provide functions for disposing secrets stored in
memory.

Note that for now it's implemented using memset, which is not really
secure.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
This commit is contained in:
Peter Krempa 2021-02-02 15:27:22 +01:00
parent 5761f8ab54
commit 43696418af
4 changed files with 74 additions and 0 deletions

View File

@ -3175,6 +3175,10 @@ virSecretLookupFormatSecret;
virSecretLookupParseSecret; virSecretLookupParseSecret;
# util/virsecureerase.h
virSecureErase;
# util/virsocket.h # util/virsocket.h
virSocketRecvFD; virSocketRecvFD;
virSocketSendFD; virSocketSendFD;

View File

@ -86,6 +86,7 @@ util_sources = [
'virscsivhost.c', 'virscsivhost.c',
'virseclabel.c', 'virseclabel.c',
'virsecret.c', 'virsecret.c',
'virsecureerase.c',
'virsocket.c', 'virsocket.c',
'virsocketaddr.c', 'virsocketaddr.c',
'virstoragefile.c', 'virstoragefile.c',

44
src/util/virsecureerase.c Normal file
View File

@ -0,0 +1,44 @@
/*
* virsecureerase.c: Secure clearing of memory
*
* This library is free software; you can redistribute it and/or
* modify it under the terms of the GNU Lesser General Public
* License as published by the Free Software Foundation; either
* version 2.1 of the License, or (at your option) any later version.
*
* This library is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* Lesser General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public
* License along with this library. If not, see
* <http://www.gnu.org/licenses/>.
*
*/
#include <config.h>
#include "virsecureerase.h"
/**
* virSecureErase:
* @ptr: pointer to memory to clear
* @size: size of memory to clear
*
* Clear @size bytes of memory at @ptr.
*
* Note that for now this is implemented using memset which is not secure as
* it can be optimized out.
*
* Also note that there are possible leftover direct uses of memset.
*/
void
virSecureErase(void *ptr,
size_t size)
{
if (!ptr || size == 0)
return;
memset(ptr, 0, size);
}

25
src/util/virsecureerase.h Normal file
View File

@ -0,0 +1,25 @@
/*
* virsecureerase.h: Secure clearing of memory
*
* This library is free software; you can redistribute it and/or
* modify it under the terms of the GNU Lesser General Public
* License as published by the Free Software Foundation; either
* version 2.1 of the License, or (at your option) any later version.
*
* This library is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* Lesser General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public
* License along with this library. If not, see
* <http://www.gnu.org/licenses/>.
*
*/
#pragma once
#include "internal.h"
void
virSecureErase(void *ptr, size_t size);