Skip to content

postinstall: fix key size check to match KEYLEN - #498

Merged
jsuto merged 1 commit into
jsuto:masterfrom
krzsztf1:fix-postinstall-key-size-check
Sep 7, 2026
Merged

jsuto merged 1 commit into
jsuto:masterfrom
krzsztf1:fix-postinstall-key-size-check

Conversation

@krzsztf1

@krzsztf1 krzsztf1 commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

make_new_key() writes 56 bytes with dd but checks for 64, so the condition can never be satisfied and postinstall always aborts with 'could not read 64 bytes from /dev/urandom'. With set -o errexit it exits before chgrp and chmod, leaving the key as root:root 644.

56 is the correct size: src/config.h defines KEYLEN 56, cfg.h declares key[KEYLEN], and store.c reads exactly KEYLEN bytes. Writing 64 would add 8 bytes the daemon never reads.

The earlier version of the function wrote to $KEYTMPFILE and checked for 56; the size appears to have been changed to 64 when it was reworked to write straight to $KEYFILE.

make_new_key() writes 56 bytes with dd but checks for 64, so the condition
can never be satisfied and postinstall always aborts with 'could not read
64 bytes from /dev/urandom'. With set -o errexit it exits before chgrp and
chmod, leaving the key as root:root 644.

56 is the correct size: src/config.h defines KEYLEN 56, cfg.h declares
key[KEYLEN], and store.c reads exactly KEYLEN bytes. Writing 64 would add
8 bytes the daemon never reads.

The earlier version of the function wrote to $KEYTMPFILE and checked for 56;
the size appears to have been changed to 64 when it was reworked to write
straight to $KEYFILE.
@krzsztf1
krzsztf1 requested a review from jsuto as a code owner September 7, 2026 00:16
@jsuto
jsuto merged commit 713514f into jsuto:master Sep 7, 2026
7 of 8 checks passed
@krzsztf1
krzsztf1 deleted the fix-postinstall-key-size-check branch September 10, 2026 08:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants