krb5 commit: Fix deserializing context with missing profile

ghudson at mit.edu ghudson at mit.edu
Thu Aug 6 22:08:50 EDT 2026


https://github.com/krb5/krb5/commit/66f6fde30ec696437fecfddee778f0291a1d2ca1
commit 66f6fde30ec696437fecfddee778f0291a1d2ca1
Author: Sergey Bugaev <bugaevc at gmail.com>
Date:   Mon Jul 27 16:17:46 2026 +0300

    Fix deserializing context with missing profile
    
    k5_internalize_context() tolerates EINVAL and ENOENT failures from
    profile_ser_internalize(), which should allow it to continue if a
    configuration file (such as /etc/krb5.conf) is missing in the
    deserializing process.  However, profile_ser_internalize() only
    updates the caller's buffer pointer if the profile was initialized, so
    k5_internalize_context() attempts to read its trailer from the
    serialized profile data and fails.  Change profile_ser_internalize()
    to update the caller's buffer pointer once it has consumed a whole
    profile serialization, whether or not profile_init() succeeds.
    
    [ghudson at mit.edu: edited commit message and comment]
    
    ticket: 9231 (new)

 src/util/profile/prof_init.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/src/util/profile/prof_init.c b/src/util/profile/prof_init.c
index 783efbde2..b97d469a1 100644
--- a/src/util/profile/prof_init.c
+++ b/src/util/profile/prof_init.c
@@ -654,13 +654,13 @@ errcode_t profile_ser_internalize(profile_t *profilep,
         goto cleanup;
     }
 
-    if ((retval = profile_init((const_profile_filespec_t *) flist,
-                               profilep)))
-        goto cleanup;
-
+    /* Update the buffer pointer even if profile initialization fails, so the
+     * caller can keep deserializing from the correct position.  */
     *bufpp = bp;
     *remainp = remain;
 
+    retval = profile_init((const_profile_filespec_t *) flist, profilep);
+
 cleanup:
     if (flist) {
         for (i=0; i<fcount; i++) {


More information about the cvs-krb5 mailing list