Skip to content

mod_auth_digest: cleanup IV - #787

Open
notroj wants to merge 2 commits into
apache:trunkfrom
notroj:mod_auth_digest-p4
Open

notroj wants to merge 2 commits into
apache:trunkfrom
notroj:mod_auth_digest-p4

Conversation

@notroj

@notroj notroj commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator
  • move client_id counter into the client_list struct and merge add_client() into client_generate()

notroj and others added 2 commits October 5, 2026 18:51
client_list struct; no functional change intended.

* modules/aaa/mod_auth_digest.c (struct hash_table): Add next_id field;
  note that all access must be inside client_lock.
  (client_id_counter): Remove global.
  (initialize_tables): Seed client_list->next_id rather than allocating
  and seeding client_id_counter.
  (add_client): Remove, merging into...
  (client_generate): ...here; issue the id from client_list->next_id
  inside client_lock rather than via atomics, and log allocation
  failure.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* modules/aaa/mod_auth_digest.c (client_id_t): Widen to apr_uint64_t.
  (CLIENT_ID_MAX): New.
  (initialize_tables): Cap the seed at CLIENT_ID_MAX.
  (client_generate): Issue ids in 1..CLIENT_ID_MAX.
  (client_exists, client_update_nonce, client_generate): Log ids with
  APR_UINT64_T_FMT.
  (parse_digest_header): Parse the opaque with apr_strtoi64(), returning
  INVALID if it is not in 1..CLIENT_ID_MAX.
  (authenticate_digest_user): Remove the now-unreachable invalid opaque
  check (AH01787); mention an invalid opaque in AH01782.
  (ltox): Rename to...
  (client_id_to_opaque): ...this; format with APR_UINT64_T_HEX_FMT.
  (note_digest_auth_failure): Update callers.

* test/modules/aaa/test_001_challenge_response.py
  (test_digest_013_invalid_opaque): Accept AH01782 as well as AH01787.

* test/modules/aaa/test_003_nccheck.py
  (test_digest_035_out_of_range_opaque_is_not_truncated): Try opaques
  2^32 and 2^64 above the live id.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant