fix: replace strcpy with bounded memory operations (#195)

Replace all uses of strcpy() with memcpy() + explicit NUL termination
or direct assignment for safety and consistency. No behavioral changes.

src/shared/file.c:
  - file_create(): strcpy -> memcpy + explicit NUL (buffer size known)

src/shared/utils.c:
  - mkdir_r(): strcpy -> memcpy for path_duplicate
  - mkdir_r(): strcpy(path_current, "/") -> direct assignment
  - mkdir_r(): strcpy loop -> memcpy + direct assignment
  - str_dup(): strcpy -> memcpy (buffer size known)

PR #196 (dry-run manifest refactoring) was already applied in a previous
commit - send_dry_run_manifest() and send_delete_manifest() helpers
already exist and are used by both send_files() and
send_files_multithreaded().
This commit is contained in:
2026-07-30 18:49:31 +02:00
parent e876055167
commit 88746c3396
2 changed files with 14 additions and 9 deletions
+2 -1
View File
@@ -35,7 +35,8 @@ File* file_create(const char* path) {
return NULL;
}
strcpy(file->path, path);
memcpy(file->path, path, path_len);
file->path[path_len] = '\0';
file->data = data_create_reserve(0);
if (file->data == NULL) {
free(file->path);