Skip to content

[17099] Fix chain of trust issues#3294

Merged
MiguelCompany merged 7 commits intomasterfrom
bugfix/17099
Feb 15, 2023
Merged

[17099] Fix chain of trust issues#3294
MiguelCompany merged 7 commits intomasterfrom
bugfix/17099

Conversation

@MiguelCompany
Copy link
Copy Markdown
Member

@MiguelCompany MiguelCompany commented Feb 13, 2023

Description

This should fix #3239 using the proposed solution.
A regression test has been added following the misbehavior described.

@Mergifyio backport 2.9.x 2.8.x 2.6.x 2.1.x

Contributor Checklist

  • Commit messages follow the project guidelines.
  • The code follows the style guidelines of this project.
  • Tests that thoroughly check the new feature have been added/Regression tests checking the bug and its fix have been added; the added tests pass locally
  • Any new/modified methods have been properly documented using Doxygen.
  • Changes are ABI compatible.
  • Changes are API compatible.
  • N/A Documentation builds and tests pass locally.
  • N/A New feature has been added to the versions.md file (if applicable).
  • N/A New feature has been documented/Current behavior is correctly described in the documentation.
  • Applicable backports have been included in the description.

Reviewer Checklist

  • Check contributor checklist is correct.
  • Check CI results: changes do not issue any warning.
  • Check CI results: failing tests are unrelated with the changes.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
@MiguelCompany
Copy link
Copy Markdown
Member Author

@richiprosima Please test this.

@MiguelCompany MiguelCompany added this to the v2.10.0 milestone Feb 14, 2023
Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
@MiguelCompany MiguelCompany merged commit b6b178e into master Feb 15, 2023
@MiguelCompany MiguelCompany deleted the bugfix/17099 branch February 15, 2023 12:04
@MiguelCompany
Copy link
Copy Markdown
Member Author

https://github.com/Mergifyio backport 2.9.x 2.8.x 2.6.x 2.1.x

mergify bot pushed a commit that referenced this pull request Feb 15, 2023
* Refs #17099. Added malicious permissions file.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Added regression test.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Put common code on auxiliary method.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Fix issue.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Uncrustify and comment.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Check input before allocating output.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Improve error messages.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

---------

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
(cherry picked from commit b6b178e)
mergify bot pushed a commit that referenced this pull request Feb 15, 2023
* Refs #17099. Added malicious permissions file.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Added regression test.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Put common code on auxiliary method.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Fix issue.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Uncrustify and comment.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Check input before allocating output.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Improve error messages.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

---------

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
(cherry picked from commit b6b178e)
mergify bot pushed a commit that referenced this pull request Feb 15, 2023
* Refs #17099. Added malicious permissions file.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Added regression test.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Put common code on auxiliary method.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Fix issue.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Uncrustify and comment.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Check input before allocating output.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Improve error messages.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

---------

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
(cherry picked from commit b6b178e)
@mergify
Copy link
Copy Markdown
Contributor

mergify bot commented Feb 15, 2023

backport 2.9.x 2.8.x 2.6.x 2.1.x

✅ Backports have been created

Details

mergify bot pushed a commit that referenced this pull request Feb 15, 2023
* Refs #17099. Added malicious permissions file.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Added regression test.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Put common code on auxiliary method.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Fix issue.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Uncrustify and comment.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Check input before allocating output.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Improve error messages.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

---------

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
(cherry picked from commit b6b178e)
EduPonz pushed a commit that referenced this pull request May 12, 2023
* Refs #17099. Added malicious permissions file.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Added regression test.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Put common code on auxiliary method.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Fix issue.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Uncrustify and comment.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Check input before allocating output.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

* Refs #17099. Improve error messages.

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>

---------

Signed-off-by: Miguel Company <MiguelCompany@eprosima.com>
(cherry picked from commit b6b178e)

Co-authored-by: Miguel Company <miguelcompany@eprosima.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[16903] Chain of trust issues with a single CA certificate

2 participants