git: c91777f23a3b - main - ppp: Fix address leaks

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Wed, 16 Sep 2026 12:25:38 UTC
The branch main has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=c91777f23a3b13649cdf303515ee45a04c788af3

commit c91777f23a3b13649cdf303515ee45a04c788af3
Author:     Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-16 12:13:25 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-16 12:13:25 +0000

    ppp: Fix address leaks
    
    Avoid printing timer addresses, so as to not divulge information about
    the address space layout.
    
    In ip.c, print the actual SPI instead of a pointer to the SPI in the
    header buffer.
    
    When debug logging is enabled, don't leak pointers when logging function
    arguments or return values.
    
    Reported by:    Reo Shiseki
    MFC after:      2 weeks
    Sponsored by:   The FreeBSD Foundation
---
 usr.sbin/ppp/id.c     |  4 ++--
 usr.sbin/ppp/ip.c     |  8 ++++----
 usr.sbin/ppp/radius.c |  4 ++--
 usr.sbin/ppp/timer.c  | 19 +++++++++++--------
 usr.sbin/ppp/tty.c    |  3 +--
 5 files changed, 20 insertions(+), 18 deletions(-)

diff --git a/usr.sbin/ppp/id.c b/usr.sbin/ppp/id.c
index 35bd3f08c261..015218184b23 100644
--- a/usr.sbin/ppp/id.c
+++ b/usr.sbin/ppp/id.c
@@ -96,7 +96,7 @@ ID0ioctl(int fd, unsigned long req, void *arg)
 
   ID0set0();
   ret = ioctl(fd, req, arg);
-  log_Printf(LogID0, "%d = ioctl(%d, %lu, %p)\n", ret, fd, req, arg);
+  log_Printf(LogID0, "%d = ioctl(%d, %lu)\n", ret, fd, req);
   ID0setuser();
   return ret;
 }
@@ -132,7 +132,7 @@ ID0fopen(const char *path, const char *mode)
 
   ID0set0();
   ret = fopen(path, mode);
-  log_Printf(LogID0, "%p = fopen(\"%s\", \"%s\")\n", ret, path, mode);
+  log_Printf(LogID0, "%s = fopen(\"%s\", \"%s\")\n", ret ? "file" : "null", path, mode);
   ID0setuser();
   return ret;
 }
diff --git a/usr.sbin/ppp/ip.c b/usr.sbin/ppp/ip.c
index aea1a812e2ea..a147f997f786 100644
--- a/usr.sbin/ppp/ip.c
+++ b/usr.sbin/ppp/ip.c
@@ -780,8 +780,8 @@ PacketCheck(struct bundle *bundle, u_int32_t family,
       snprintf(logbuf + loglen, sizeof logbuf - loglen,
                "ESP: %s ---> ", ncpaddr_ntoa(&srcaddr));
       loglen += strlen(logbuf + loglen);
-      snprintf(logbuf + loglen, sizeof logbuf - loglen, "%s, spi %p",
-               ncpaddr_ntoa(&dstaddr), payload);
+      snprintf(logbuf + loglen, sizeof logbuf - loglen, "%s",
+               ncpaddr_ntoa(&dstaddr));
       loglen += strlen(logbuf + loglen);
     }
     break;
@@ -791,8 +791,8 @@ PacketCheck(struct bundle *bundle, u_int32_t family,
       snprintf(logbuf + loglen, sizeof logbuf - loglen,
                "AH: %s ---> ", ncpaddr_ntoa(&srcaddr));
       loglen += strlen(logbuf + loglen);
-      snprintf(logbuf + loglen, sizeof logbuf - loglen, "%s, spi %p",
-               ncpaddr_ntoa(&dstaddr), payload + sizeof(u_int32_t));
+      snprintf(logbuf + loglen, sizeof logbuf - loglen, "%s",
+               ncpaddr_ntoa(&dstaddr));
       loglen += strlen(logbuf + loglen);
     }
     break;
diff --git a/usr.sbin/ppp/radius.c b/usr.sbin/ppp/radius.c
index 77a38dead19e..8b1f6f2a5e45 100644
--- a/usr.sbin/ppp/radius.c
+++ b/usr.sbin/ppp/radius.c
@@ -1058,7 +1058,7 @@ radius_Authenticate(struct radius *r, struct authinfo *authp, const char *name,
   else {
     log_Printf(log_IsKept(LogRADIUS) ? LogRADIUS : LogPHASE,
 	       "Radius: Request sent\n");
-    log_Printf(LogDEBUG, "Using radius_Timeout [%p]\n", radius_Timeout);
+    log_Printf(LogDEBUG, "Using radius_Timeout\n");
     r->cx.timer.load = tv.tv_usec / TICKUNIT + tv.tv_sec * SECTICKS;
     r->cx.timer.func = radius_Timeout;
     r->cx.timer.name = "radius auth";
@@ -1284,7 +1284,7 @@ radius_Account(struct radius *r, struct radacct *ac, struct datalink *dl,
   if ((got = rad_init_send_request(r->cx.rad, &r->cx.fd, &tv)))
     radius_Process(r, got);
   else {
-    log_Printf(LogDEBUG, "Using radius_Timeout [%p]\n", radius_Timeout);
+    log_Printf(LogDEBUG, "Using radius_Timeout\n");
     r->cx.timer.load = tv.tv_usec / TICKUNIT + tv.tv_sec * SECTICKS;
     r->cx.timer.func = radius_Timeout;
     r->cx.timer.name = "radius acct";
diff --git a/usr.sbin/ppp/timer.c b/usr.sbin/ppp/timer.c
index 469f68c715de..4f2b2a98f823 100644
--- a/usr.sbin/ppp/timer.c
+++ b/usr.sbin/ppp/timer.c
@@ -80,6 +80,7 @@ timer_Start(struct pppTimer *tp)
   struct pppTimer *t, *pt;
   u_long ticks = 0;
   sigset_t mask, omask;
+  int i;
 
   sigemptyset(&mask);
   sigaddset(&mask, SIGALRM);
@@ -89,7 +90,7 @@ timer_Start(struct pppTimer *tp)
     StopTimerNoBlock(tp);
 
   if (tp->load == 0) {
-    log_Printf(LogTIMER, "%s timer[%p] has 0 load!\n", tp->name, tp);
+    log_Printf(LogTIMER, "%s timer has 0 load!\n", tp->name);
     sigprocmask(SIG_SETMASK, &omask, NULL);
     return;
   }
@@ -102,7 +103,7 @@ timer_Start(struct pppTimer *tp)
     ticks = RESTVAL(itimer) - TimerList->rest;
 
   pt = NULL;
-  for (t = TimerList; t; t = t->next) {
+  for (i = 0, t = TimerList; t; t = t->next, i++) {
     if (ticks + t->rest >= tp->load)
       break;
     ticks += t->rest;
@@ -113,10 +114,11 @@ timer_Start(struct pppTimer *tp)
   tp->rest = tp->load - ticks;
 
   if (t)
-    log_Printf(LogTIMER, "timer_Start: Inserting %s timer[%p] before %s "
-              "timer[%p], delta = %ld\n", tp->name, tp, t->name, t, tp->rest);
+    log_Printf(LogTIMER, "timer_Start: Inserting %s timer[%d] before %s "
+              "timer[%d], delta = %ld\n", tp->name, i, t->name, i + 1,
+              tp->rest);
   else
-    log_Printf(LogTIMER, "timer_Start: Inserting %s timer[%p]\n", tp->name, tp);
+    log_Printf(LogTIMER, "timer_Start: Inserting %s timer[%d]\n", tp->name, i);
 
   /* Insert given *tp just before *t */
   tp->next = t;
@@ -237,6 +239,7 @@ timer_Show(int LogLevel, struct prompt *prompt)
   struct itimerval itimer;
   struct pppTimer *pt;
   long rest;
+  int i;
 
   /*
    * Adjust the base time so that the deltas reflect what's really
@@ -253,14 +256,14 @@ timer_Show(int LogLevel, struct prompt *prompt)
 #define SECS(val)	((val) / SECTICKS)
 #define HSECS(val)	(((val) % SECTICKS) * 100 / SECTICKS)
 #define DISP								\
-  "%s timer[%p]: freq = %ld.%02lds, next = %lu.%02lus, state = %s\n",	\
-  pt->name, pt, SECS(pt->load), HSECS(pt->load), SECS(rest),		\
+  "%s timer[%d]: freq = %ld.%02lds, next = %lu.%02lus, state = %s\n",	\
+  pt->name, i, SECS(pt->load), HSECS(pt->load), SECS(rest),		\
   HSECS(rest), tState2Nam(pt->state)
 
   if (!prompt)
     log_Printf(LogLevel, "---- Begin of Timer Service List---\n");
 
-  for (pt = TimerList; pt; pt = pt->next) {
+  for (pt = TimerList, i = 0; pt; pt = pt->next, i++) {
     rest += pt->rest;
     if (prompt)
       prompt_Printf(prompt, DISP);
diff --git a/usr.sbin/ppp/tty.c b/usr.sbin/ppp/tty.c
index f0a76d648faf..2c2df6f151d2 100644
--- a/usr.sbin/ppp/tty.c
+++ b/usr.sbin/ppp/tty.c
@@ -187,8 +187,7 @@ tty_StartTimer(struct physical *p)
   dev->Timer.func = tty_Timeout;
   dev->Timer.name = "tty CD";
   dev->Timer.arg = p;
-  log_Printf(LogDEBUG, "%s: Using tty_Timeout [%p]\n",
-             p->link.name, tty_Timeout);
+  log_Printf(LogDEBUG, "%s: Using tty_Timeout\n", p->link.name);
   timer_Start(&dev->Timer);
 }