Home GnuPG

Improve GCRYCTL_DISABLE_PRIV_DROP by also disabling cap_ calls.
236c040c066dUnpublished

Unpublished Commit · Learn More

Not On Permanent Ref: This commit is not an ancestor of any permanent ref.

Description

Improve GCRYCTL_DISABLE_PRIV_DROP by also disabling cap_ calls.

* src/secmem.c (lock_pool, secmem_init): Do not call any cap_
functions if NO_PRIV_DROP is set.

(cherry picked from commit 3a3d5410cc83f7069c7cb1ab384905f382292d32)
Resolved conflicts:
src/secmem.c - No need for the typo fix.

  • Signed-off-by: Werner Koch <wk@gnupg.org>

Details

Provenance
wernerAuthored on Sep 7 2015, 2:02 PM
Parents
rCb85c8d664503: rsa: Add verify after sign to avoid Lenstra's CRT attack.
Branches
Unknown
Tags
Unknown

Event Timeline