Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prevent crash on failure to source secure randomness #2300

Draft
wants to merge 1 commit into
base: development
Choose a base branch
from
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions src/config/password.c
Original file line number Diff line number Diff line change
Expand Up @@ -185,7 +185,7 @@ static char * __attribute__((malloc)) balloon_password(const char *password,
{
// Parameter check
if(password == NULL || salt == NULL)
return NULL;
return strdup("");

struct timespec start, end;
// Record starting time
Expand Down Expand Up @@ -370,7 +370,7 @@ char * __attribute__((malloc)) create_password(const char *password)
// genrandom() returns cryptographically secure random data
uint8_t salt[SALT_LEN] = { 0 };
if(!get_secure_randomness(salt, sizeof(salt)))
return NULL;
return strdup("");

// Generate balloon PHC-encoded password hash
return balloon_password(password, salt, true);
Expand Down
Loading