Page MenuHomeFreeBSD

netdump: Don't store sensitive key data we don't need
ClosedPublic

Authored by cem on May 10 2019, 8:35 PM.
Tags
None
Referenced Files
Unknown Object (File)
Fri, Apr 17, 2:42 PM
Unknown Object (File)
Wed, Apr 15, 7:14 PM
Unknown Object (File)
Tue, Apr 7, 8:34 AM
Unknown Object (File)
Mar 30 2026, 3:35 AM
Unknown Object (File)
Mar 29 2026, 7:17 AM
Unknown Object (File)
Mar 28 2026, 8:14 PM
Unknown Object (File)
Dec 26 2025, 3:27 AM
Unknown Object (File)
Dec 17 2025, 7:55 PM
Subscribers

Details

Summary

The diocskerneldump_arg and netdump_conf (with embedded diocskerneldump_arg)
before it were copied in whole to the global nd_conf variable. After EKCD,
the diocskerneldump_arg contains sensitive key material. Before this
revision, de-configuring netdump would not remove the the key material from
global nd_conf.

Netdump doesn't have any use for the key data (that is handled in the core
dumper code), so just don't store it.

Unfortunately, I think this dates to the initial import of netdump in
r333283.

Diff Detail

Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 24191
Build 23034: arc lint + arc unit