This command was used for example to suspend-to-ram (man page example).
On Linux running this command inherits OOM killer immunity. This could be
abused by an other local user on the same machine (abusing resources).
To keep the use-case for suspend-to-ram an user could write a wrapper script
for it, outside the scope of slock.
Simplify argument handling, because the post-lock command parameter is removed.
Reported by: Acts1631 <acts1631kjv@proton.me>
Make sure to explicitly clear memory that is used for password input. memset
is often optimized out by the compiler.
Brought to attention by the OpenBSD community, see:
https://marc.info/?t=146989502600003&r=1&w=2
Thread subject: x11/slock: clear passwords with explicit_bzero
Changes:
- explicit_bzero.c import from libressl-portable.
- Makefile: add COMPATSRC for compatibility src.
- config.mk: add separate *BSD section in config.mk to simply uncomment it on
these platforms.