From 0a7f5faea6e4739ce88ac7fb119e199c9fdca0aa Mon Sep 17 00:00:00 2001 From: TapTap Date: Sun, 13 Sep 2026 10:51:01 +0200 Subject: [PATCH] test: replace strcat with a bounds-checked append in daemon-conf test --- tests/test_daemon_conf.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/tests/test_daemon_conf.c b/tests/test_daemon_conf.c index a9113a5..b6f54bc 100644 --- a/tests/test_daemon_conf.c +++ b/tests/test_daemon_conf.c @@ -543,11 +543,19 @@ static void test_daemon_conf_module_count_capped() { size_t len = (cap + 8) * 32; char* body = malloc(len); EXPECT_NOT_NULL(body); + size_t used = 0; body[0] = '\0'; for (size_t i = 0; i < cap + 1; i++) { char line[48]; - snprintf(line, sizeof(line), "[m%zu]\npath = /x\n", i); - strcat(body, line); + int n = snprintf(line, sizeof(line), "[m%zu]\npath = /x\n", i); + if (n < 0 || (size_t)n >= sizeof(line) || used + (size_t)n >= len) { + free(body); + EXPECT_TRUE(0 && "module-count test buffer overflow"); + return; + } + memcpy(body + used, line, (size_t)n); + used += (size_t)n; + body[used] = '\0'; } char* path; EXPECT_EQ_INT(write_conf(body, &path), 0);