From 733990e9ed6080fc0b7b947f6f70fadf596e2e7b Mon Sep 17 00:00:00 2001 From: matt335672 <30179339+matt335672@users.noreply.github.com> Date: Sat, 13 Sep 2025 16:15:34 +0100 Subject: [PATCH] Pre-master secret file: Change location for permission setting Coverity scan picked up on the result on g_chmod_hex() not being checked. This call has now been moved to the place where the file is checked for writeability, as we only really need to make it when the file is created. --- common/ssl_calls.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/common/ssl_calls.c b/common/ssl_calls.c index e1ef6e96..a10279fa 100644 --- a/common/ssl_calls.c +++ b/common/ssl_calls.c @@ -225,6 +225,12 @@ ssl_set_pre_master_secret_logfile(const char *filename) { /* Ignore this one */ } + else if (g_chmod_hex(filename, 0x640) != 0) + { + LOG(LOG_LEVEL_WARNING, "Can't set expected permissions on %s [%s]", + filename, g_get_strerror()); + + } else if ((g_keylog_filename = g_strdup(filename)) == NULL) { LOG(LOG_LEVEL_ERROR, "Out of memory setting TLS pre-master log"); @@ -256,7 +262,6 @@ log_pre_master_secret(const SSL *ssl, const char *line) } else { - g_chmod_hex(g_keylog_filename, 0x640); // Must be group readable g_file_seek_end(fd, 0); g_file_write(fd, line, strlen(line)); g_file_write(fd, "\n", 1);