Repository navigation
fix: use calloc in read_file_into_str to avoid tainted index write - #267
Merged
Merged
Conversation
SonarCloud flags str[bytes_read] = '\0' as an array index injection (csecurity:S9340, code scanning alert #1). The write is in bounds, since bytes_read == file_size is checked just above, and the guard added earlier to appease the analyzer is always true and no longer helps. Allocate the buffer with calloc instead so it is NUL-terminated from the start, and drop the indexed write and its dead guard.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



SonarCloud flags
str[bytes_read] = '\0'inread_file_into_stras an array index injection (csecurity:S9340, code scanning alert #1).The alert is a false positive:
bytes_read == file_sizeis checked just above the write, and the buffer isfile_size + 1bytes, so the index is always the last byte of the allocation. Theif (bytes_read < file_size+1)guard added in #149/#152 to appease the analyzer is always true and no longer silences it.Rather than keep working around the analyzer, this allocates the buffer with
callocso it is NUL-terminated from the start, and removes the indexed write and its dead guard. Behaviour is unchanged.Tested with
NO_INTERNET=1 make -C src. Whether the alert clears will only be known once SonarCloud analyses this change.