pgBackRest 2.68 commit log

v2.59.3: Weak Encryption Subkey Bug

commit   : 46cdca625a73403cad4774d97354a1fac1e91e51    
  
author   : David Steele <david@pgbackrest.org>    
date     : Sun, 4 Oct 2026 09:29:49 +0200    
  
committer: David Steele <david@pgbackrest.org>    
date     : Sun, 4 Oct 2026 09:29:49 +0200    

Click here for diff

IMPORTANT NOTE: In prior versions it was possible for weak encryption subkeys and salts to be generated if there was an error accessing system random data.  
  
Bug Fixes:  
  
* Fix possible checksum error loading encrypted info and manifest files. (Fixed by j0uinim. Reviewed by David Steele.)  
* Fix possible weak encryption subkeys/salts. (Fixed by j0uinim. Reviewed by David Steele, Stefan Fercot, Douglas J Hunley.)  

M CONTRIBUTING.md
M README.md
M doc/RELEASE.md
M doc/resource/exe.cache
M doc/resource/git-history.cache
M doc/xml/auto/metric-coverage-report.auto.xml
M doc/xml/index.xml
M doc/xml/news.xml
M doc/xml/release/2020s/2026/2.59.3.xml
M meson.build
M src/version.h

Fix possible weak encryption subkeys/salts.

commit   : 47ed78f8d54a44466a872852939edc0273172bf1    
  
author   : j0uinim <54897948+j0uinim@users.noreply.github.com>    
date     : Fri, 2 Oct 2026 18:29:39 +0200    
  
committer: David Steele <david@pgbackrest.org>    
date     : Fri, 2 Oct 2026 18:29:39 +0200    

Click here for diff

The result of RAND_bytes() was ignored in cryptoRandomBytes(). When OpenSSL is unable to get random data from the operating system, RAND_bytes() fails and leaves the buffer unchanged, so a subkey was generated from uninitialized stack memory and a salt from data already in the output buffer. No error was reported and the repository was written with weak subkeys and salts.  
  
Throw a CryptoError when RAND_bytes() fails, as other OpenSSL failures do. Test the error with a RAND_bytes() shim in the test module.  

M doc/xml/release/2020s/2026/2.59.3.xml
M src/common/crypto/common.c
M test/src/module/common/cryptoTest.c

Fix possible checksum error loading encrypted info and manifest files.

commit   : 2def063e06c6f0b7e137309c7ed0d7631a42f6cf    
  
author   : j0uinim <54897948+j0uinim@users.noreply.github.com>    
date     : Fri, 2 Oct 2026 18:25:14 +0200    
  
committer: David Steele <david@pgbackrest.org>    
date     : Fri, 2 Oct 2026 18:25:14 +0200    

Click here for diff

A read that does not block stops as soon as it has output, and end of file is set on a later read that gets no output. When a filter needed the same input again the read did not stop, so end of file could be set while output remained in the internal buffer used by the line and small readers. A read that loops until end of file then lost whatever remained in that buffer.  
  
The block cipher filter needs the same input again on flush when the buffer has less room than the final block. A large encrypted info or manifest file could lose its last lines on load, which fails the checksum. This requires the lost lines to fit in the final block, so it is unlikely in practice. A filter that holds its output until the end of its input, such as the authenticated cipher proposed in #2866, would hit this on any file larger than the buffer.  
  
Stop a read that does not block as soon as it has output, whether or not a filter needs the same input again.  

M doc/xml/release/2020s/2026/2.59.3.xml
M doc/xml/release/contributor.xml
M src/common/io/read.c
M test/src/module/common/ioTest.c

Begin v2.59.3 development.

commit   : 5b104c13460c6698dd165853be9900af334f5ba2    
  
author   : David Steele <david@pgbackrest.org>    
date     : Fri, 2 Oct 2026 18:07:27 +0200    
  
committer: David Steele <david@pgbackrest.org>    
date     : Fri, 2 Oct 2026 18:07:27 +0200    

Click here for diff

M doc/resource/git-history.cache
M doc/xml/release.xml
A doc/xml/release/2020s/2026/2.59.3.xml
M meson.build
M src/version.h