From erik.sjolund@gmail.com Thu Apr 26 11:27:06 2018 Return-Path: Received: from mail-io0-f194.google.com (mail-io0-f194.google.com [209.85.223.194]) by krbdev.mit.edu (Postfix) with ESMTPS id D1C5F45C25; Thu, 26 Apr 2018 11:27:06 -0400 (EDT) Received: by mail-io0-f194.google.com with SMTP id t123-v6so31514949iof.7; Thu, 26 Apr 2018 08:27:06 -0700 (PDT) Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=j3NT2Ay+9Vb3tKPm4ikTkSA6++Q85C8iXNKRss+bfsE=; b=iCNkjOS+K4C8ykliSiFXRAWdiUY66t0rqCmxJfmuP9hUMjEA54YfD+w4sBCU3zxj7a 84wYPHkOqR8RihVGXiiMiLbl107BtYQM2TDsaOD3Dh3aOsHNvDX82iuWEZHKh6S1XePx CubJZqFH5sNvBVh7iAFaT9sG1N5vE73mWj+UsdNgSF2qGyK3yq7gpIAgeUagGGSixkpX p7v2nOVxEEcWmK7+C1tjKKeUTcHC13ms1DPA0IcMc5u39RpRRyxCgn3lsAloBumNQZOx Ap9FVzynUSyw/4MvxdeHqjKdtfAQzL3hwBdDXQU5d4IDbCaqsmGa0FqzuYxKjVPdfNS0 A0Lg== X-Google-Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=j3NT2Ay+9Vb3tKPm4ikTkSA6++Q85C8iXNKRss+bfsE=; b=KzwlbstSuJ+/xHkl9UHCIMDB+fWUO3sFA6y/8Gw0A9T2SL/OJQBzNj32RYphy3NDoQ jeikPRlmTblMO0yAZruZpF8eSK3KYAOmefraRqETNN6kceNnQMY2C5w374ilcxzNNaBS Rwct5jMQJjvlTNtyPW0gBaWqPsivhGh7YVJE47jpctVtdy2T4Ovrccfin2D26Cjnte0q uMfpjdSmnZRpW5sm7+WbyEf9A92V69QlsAm8gc9MCUkZnRDVuY+vGaA+VDG4ZfpeUpkV WaA5vyvEyulp4xbFdwUhJycLLgeAWzhqv+JFgAH86xixF4AH9IpTeJTXdjm7DAKjf0Vy MQEw== X-GM-Message-State: ALQs6tDYEMfpndfsN9O++G2ZrjYurm9nLEnbnn2RNLqyKCHdlghodzrV m0QOri32AYzp8FLjttAovKJ67sP4h0bublYC4EU= X-Google-SMTP-Source: AB8JxZoDozbTlNchy64kVOtAJ28+nLNIwVZT+bQyCzdj3iDHiiotWQV8mv6Pz1doduwKbP5DheigEhpBEKzjU9pPx0A= X-Received: by 2002:a6b:2b10:: with SMTP id r16-v6mr34597806ior.204.1524756425239; Thu, 26 Apr 2018 08:27:05 -0700 (PDT) MIME-Version: 1.0 Received: by 2002:a4f:f7db:0:0:0:0:0 with HTTP; Thu, 26 Apr 2018 08:27:04 -0700 (PDT) In-Reply-To: References: From: Erik Sjölund Date: Thu, 26 Apr 2018 17:27:04 +0200 Message-ID: Subject: Re: [krbdev.mit.edu #8661] git commit To: rt-comment@krbdev.mit.edu, rt@krbdev.mit.edu CC: Tavis Ormandy Content-Type: text/plain; charset="UTF-8" RT-Send-Cc: Content-Length: 680 Thanks! That makes it easier to read the code. On Thu, Apr 26, 2018 at 5:22 PM, Greg Hudson via RT wrote: > > Move zero argc check earlier in ksu > > For improved auditability, check for a zero argc value earlier in > main() so that the first two calls to com_err() can't pass a NULL > whoami value--which would be harmless, but that may not be obvious to > a reader. > > https://github.com/krb5/krb5/commit/e1b5b824f5d7388a67d0854b56d3906c4fbdd778 > Author: Greg Hudson > Commit: e1b5b824f5d7388a67d0854b56d3906c4fbdd778 > Branch: master > src/clients/ksu/main.c | 5 +++-- > 1 files changed, 3 insertions(+), 2 deletions(-) >