Skip to content

fix: use calloc in read_file_into_str to avoid tainted index write - #267

Merged
manugarg merged 1 commit into
mainfrom
fix-sonar-tainted-index
Oct 3, 2026
Merged

manugarg merged 1 commit into
mainfrom
fix-sonar-tainted-index

Conversation

@manugarg

@manugarg manugarg commented Oct 3, 2026

Copy link
Copy Markdown
Owner

SonarCloud flags str[bytes_read] = '\0' in read_file_into_str as an array index injection (csecurity:S9340, code scanning alert #1).

The alert is a false positive: bytes_read == file_size is checked just above the write, and the buffer is file_size + 1 bytes, so the index is always the last byte of the allocation. The if (bytes_read < file_size+1) guard added in #149/#152 to appease the analyzer is always true and no longer silences it.

Rather than keep working around the analyzer, this allocates the buffer with calloc so it is NUL-terminated from the start, and removes the indexed write and its dead guard. Behaviour is unchanged.

Tested with NO_INTERNET=1 make -C src. Whether the alert clears will only be known once SonarCloud analyses this change.

SonarCloud flags str[bytes_read] = '\0' as an array index injection
(csecurity:S9340, code scanning alert #1). The write is in bounds, since
bytes_read == file_size is checked just above, and the guard added
earlier to appease the analyzer is always true and no longer helps.

Allocate the buffer with calloc instead so it is NUL-terminated from the
start, and drop the indexed write and its dead guard.
@sonarqubecloud

sonarqubecloud Bot commented Oct 3, 2026

Copy link
Copy Markdown

@manugarg
manugarg merged commit 18287a6 into main Oct 3, 2026
30 checks passed
@manugarg
manugarg deleted the fix-sonar-tainted-index branch October 3, 2026 08:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant