Skip to content

iolog_pwfilt_run: keep password filter state per session - #558

Open
iefa-m wants to merge 1 commit into
sudo-project:mainfrom
iefa-m:pwfilt-per-session
Open

iefa-m wants to merge 1 commit into
sudo-project:mainfrom
iefa-m:pwfilt-per-session

Conversation

@iefa-m

@iefa-m iefa-m commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

sudo_logsrvd runs every client's I/O buffers through the one filter handle returned by logsrvd_conf_iolog_passprompt_regex, and iolog_pwfilt_run kept its is_filtered flag inside that handle, so all connections shared a single filter state. When one session prints a password prompt and another session sends terminal output before the password arrives, the flag is cleared and the password lands in ttyin in the clear; if the other session sends input first, that input is starred out instead and the password still gets through. This is the default configuration (log_passwords = false) and only needs two sessions that overlap.

Take the flag out of the handle and have iolog_pwfilt_run use a bool supplied by the caller: sudo_logsrvd keeps it in the connection closure, and the sudoers I/O plugin, which only ever has one session, keeps a static. The handle is then just the compiled patterns, so sharing it between connections is fine, and behaviour for a single session is unchanged. check_iolog_filter gains a case that interleaves two sessions over one handle.

sudo_logsrvd shares one filter handle between all connections, so a
password prompt seen in one session could be cancelled or used up by
I/O from another and the password logged in the clear.  Move the
is_filtered flag out of the handle and into the caller.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant