public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/dhcpcd] rawhide: Add rpminspect.yaml to ignore inet_aton() and inet_ntoa()
@ 2026-09-23  7:11 Martin Osvald
  0 siblings, 0 replies; only message in thread
From: Martin Osvald @ 2026-09-23  7:11 UTC (permalink / raw)
  To: git-commits

A new commit has been pushed.

Repo   : rpms/dhcpcd
Branch : rawhide
Commit : fd8e8a25d0679cc1b73950426481fdcdd0477b6c
Author : Martin Osvald <mosvald@redhat.com>
Date   : 2026-07-27T10:28:18+02:00
Stats  : +13/-0 in 1 file(s)
URL    : https://src.fedoraproject.org/rpms/dhcpcd/c/fd8e8a25d0679cc1b73950426481fdcdd0477b6c?branch=rawhide

Log:
Add rpminspect.yaml to ignore inet_aton() and inet_ntoa()

---
diff --git a/rpminspect.yaml b/rpminspect.yaml
new file mode 100644
index 0000000..da14b0e
--- /dev/null
+++ b/rpminspect.yaml
@@ -0,0 +1,13 @@
+---
+badfuncs:
+  allowed:
+# This is a rpminspect false positive. Both functions are deprecated in favor of inet_pton/inet_ntop,
+# but there is no exploitable security issue in dhcpcd's specific usage:
+# - inet_aton() only parses trusted admin config; error returns are checked.
+# - inet_ntoa() is used in a single-threaded context with no double-evaluation in any single format call.
+# Fixing it would require patching ~40 call sites in the upstream source to use inet_ntop(AF_INET, ...)
+# with a local buffer, which is a cosmetic/correctness improvement, not a security fix.
+    /usr/bin/dhcpcd:
+      - inet_aton
+      - inet_ntoa
+

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-23  7:11 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-23  7:11 [rpms/dhcpcd] rawhide: Add rpminspect.yaml to ignore inet_aton() and inet_ntoa() Martin Osvald

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox