Compare commits

..

1 Commits

Author SHA1 Message Date
TapTap 88746c3396 fix: replace strcpy with bounded memory operations (#195)
Replace all uses of strcpy() with memcpy() + explicit NUL termination
or direct assignment for safety and consistency. No behavioral changes.

src/shared/file.c:
  - file_create(): strcpy -> memcpy + explicit NUL (buffer size known)

src/shared/utils.c:
  - mkdir_r(): strcpy -> memcpy for path_duplicate
  - mkdir_r(): strcpy(path_current, "/") -> direct assignment
  - mkdir_r(): strcpy loop -> memcpy + direct assignment
  - str_dup(): strcpy -> memcpy (buffer size known)

PR #196 (dry-run manifest refactoring) was already applied in a previous
commit - send_dry_run_manifest() and send_delete_manifest() helpers
already exist and are used by both send_files() and
send_files_multithreaded().
2026-07-30 18:49:52 +02:00
3 changed files with 124 additions and 90 deletions
+110 -81
View File
@@ -49,37 +49,6 @@ static bool parse_nonneg_int(const char* s, int* out_val) {
return true;
}
/* Duplicate a string argument into *dest, freeing the old value. Returns 0 on success, -1 on
* failure. */
static int set_string_option(char** dest, const char* value, const char* option_name) {
char* dup = str_dup(value);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for %s\n", option_name);
return -1;
}
free(*dest);
*dest = dup;
return 0;
}
/* Parse a string as a positive integer into *dest. Returns 0 on success, -1 on error. */
static int set_positive_int_option(int* dest, const char* value, const char* option_name) {
if (!parse_positive_int(value, dest)) {
fprintf(stderr, "Error: %s must be a positive integer\n", option_name);
return -1;
}
return 0;
}
/* Parse a string as a non-negative integer into *dest. Returns 0 on success, -1 on error. */
static int set_nonneg_int_option(int* dest, const char* value, const char* option_name) {
if (!parse_nonneg_int(value, dest)) {
fprintf(stderr, "Error: %s must be a non-negative integer\n", option_name);
return -1;
}
return 0;
}
static void print_usage(void);
static int read_patterns_from_file(const char* filepath, char*** patterns, int* count);
@@ -131,23 +100,9 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
}
config->include_patterns[config->include_count++] = dup;
} else if (strcmp(argv[i], "--max-size") == 0 && i + 1 < argc) {
char* end;
errno = 0;
unsigned long long val = strtoull(argv[++i], &end, 10);
if (errno != 0 || *end != '\0') {
fprintf(stderr, "Error: --max-size must be a non-negative integer\n");
return -1;
}
config->max_size = val;
config->max_size = strtoull(argv[++i], NULL, 10);
} else if (strcmp(argv[i], "--min-size") == 0 && i + 1 < argc) {
char* end;
errno = 0;
unsigned long long val = strtoull(argv[++i], &end, 10);
if (errno != 0 || *end != '\0') {
fprintf(stderr, "Error: --min-size must be a non-negative integer\n");
return -1;
}
config->min_size = val;
config->min_size = strtoull(argv[++i], NULL, 10);
} else if (strcmp(argv[i], "--incremental") == 0) {
config->use_incremental = true;
} else if (strcmp(argv[i], "--delta") == 0) {
@@ -177,11 +132,21 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
}
}
} else if (strcmp(argv[i], "--source-dir") == 0 && i + 1 < argc) {
if (set_string_option(&config->send_directory, argv[++i], "--source-dir") != 0)
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --source-dir\n");
return -1;
}
free(config->send_directory);
config->send_directory = dup;
} else if (strcmp(argv[i], "--dest-dir") == 0 && i + 1 < argc) {
if (set_string_option(&config->receive_root_directory, argv[++i], "--dest-dir") != 0)
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --dest-dir\n");
return -1;
}
free(config->receive_root_directory);
config->receive_root_directory = dup;
} else if (strcmp(argv[i], "--save-to-disk") == 0) {
config->save_to_disk = true;
} else if (strcmp(argv[i], "-M") == 0 || strcmp(argv[i], "--preserve") == 0) {
@@ -197,8 +162,13 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
config->use_chunk_serialization = true;
log_message(LOG_LEVEL_INFO, "Enabled Chunk Serialization");
} else if (strcmp(argv[i], "--server-host") == 0 && i + 1 < argc) {
if (set_string_option(&config->server_host, argv[++i], "--server-host") != 0)
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --server-host\n");
return -1;
}
free(config->server_host);
config->server_host = dup;
} else if (strcmp(argv[i], "--server-port") == 0 && i + 1 < argc) {
if (!parse_positive_int(argv[++i], &config->server_port)) {
fprintf(stderr, "Error: invalid --server-port value: %s\n", argv[i]);
@@ -221,44 +191,69 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
} else if (strcmp(argv[i], "--progress") == 0) {
config->show_progress = true;
} else if (strcmp(argv[i], "--chunk-size") == 0 && i + 1 < argc) {
char* end;
errno = 0;
unsigned long long val = strtoull(argv[++i], &end, 10);
if (errno != 0 || *end != '\0' || val == 0) {
fprintf(stderr, "Error: --chunk-size must be a positive integer\n");
return -1;
}
config->chunk_size = val;
unsigned long long val = strtoull(argv[++i], NULL, 10);
if (val > 0)
config->chunk_size = val;
} else if (strcmp(argv[i], "--tls") == 0) {
config->use_tls = true;
} else if (strcmp(argv[i], "--cert") == 0 && i + 1 < argc) {
if (set_string_option(&config->tls_cert, argv[++i], "--cert") != 0)
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --cert\n");
return -1;
}
free(config->tls_cert);
config->tls_cert = dup;
} else if (strcmp(argv[i], "--key") == 0 && i + 1 < argc) {
if (set_string_option(&config->tls_key, argv[++i], "--key") != 0)
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --key\n");
return -1;
}
free(config->tls_key);
config->tls_key = dup;
} else if (strcmp(argv[i], "--ca") == 0 && i + 1 < argc) {
if (set_string_option(&config->tls_ca, argv[++i], "--ca") != 0)
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --ca\n");
return -1;
}
free(config->tls_ca);
config->tls_ca = dup;
} else if (strcmp(argv[i], "--timeout") == 0 && i + 1 < argc) {
if (set_positive_int_option(&config->timeout, argv[++i], "--timeout") != 0)
int val;
if (!parse_positive_int(argv[++i], &val)) {
fprintf(stderr, "Error: --timeout must be a positive integer\n");
return -1;
}
config->timeout = val;
} else if (strcmp(argv[i], "--contimeout") == 0 && i + 1 < argc) {
if (set_positive_int_option(&config->contimeout, argv[++i], "--contimeout") != 0)
int val;
if (!parse_positive_int(argv[++i], &val)) {
fprintf(stderr, "Error: --contimeout must be a positive integer\n");
return -1;
}
config->contimeout = val;
} else if (strcmp(argv[i], "-q") == 0 || strcmp(argv[i], "--quiet") == 0 ||
strcmp(argv[i], "--silent") == 0) {
config->quiet = true;
} else if (strcmp(argv[i], "--backup") == 0) {
config->backup = true;
} else if (strcmp(argv[i], "--backup-dir") == 0 && i + 1 < argc) {
if (set_string_option(&config->backup_dir, argv[++i], "--backup-dir") != 0)
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --backup-dir\n");
return -1;
}
free(config->backup_dir);
config->backup_dir = dup;
} else if (strcmp(argv[i], "--stats") == 0) {
config->stats = true;
} else if (strcmp(argv[i], "--max-depth") == 0 && i + 1 < argc) {
if (set_nonneg_int_option(&config->max_depth, argv[++i], "--max-depth") != 0)
if (!parse_nonneg_int(argv[++i], &config->max_depth)) {
fprintf(stderr, "Error: --max-depth must be a non-negative integer\n");
return -1;
}
} else if (strcmp(argv[i], "--log-file") == 0 && i + 1 < argc) {
FILE* lf = fopen(argv[++i], "a");
if (!lf) {
@@ -268,8 +263,12 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
config->log_file = lf;
log_set_file(lf);
} else if (strcmp(argv[i], "--queue-size") == 0 && i + 1 < argc) {
if (set_positive_int_option(&config->queue_size, argv[++i], "--queue-size") != 0)
int val;
if (!parse_positive_int(argv[++i], &val)) {
fprintf(stderr, "Error: --queue-size must be a positive integer\n");
return -1;
}
config->queue_size = val;
} else if (strcmp(argv[i], "--exclude-from") == 0 && i + 1 < argc) {
if (read_patterns_from_file(argv[++i], &config->exclude_patterns, &config->exclude_count) !=
0)
@@ -281,9 +280,13 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
} else if (strcmp(argv[i], "--partial") == 0) {
config->partial = true;
} else if (strcmp(argv[i], "--fastsync-server-path") == 0 && i + 1 < argc) {
if (set_string_option(&config->fastsync_server_path, argv[++i], "--fastsync-server-path") !=
0)
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --fastsync-server-path\n");
return -1;
}
free(config->fastsync_server_path);
config->fastsync_server_path = dup;
} else if (strcmp(argv[i], "-v") == 0 || strcmp(argv[i], "--verbose") == 0) {
set_log_level(LOG_LEVEL_DEBUG);
} else if (strcmp(argv[i], "-l") == 0 || strcmp(argv[i], "--links") == 0) {
@@ -307,14 +310,15 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
} else if (strcmp(argv[i], "-i") == 0 || strcmp(argv[i], "--itemize-changes") == 0) {
config->itemize_changes = true;
} else if (strcmp(argv[i], "--out-format") == 0 && i + 1 < argc) {
if (set_string_option(&config->out_format, argv[++i], "--out-format") != 0)
char* dup = str_dup(argv[++i]);
if (!dup)
return -1;
free(config->out_format);
config->out_format = dup;
} else if (strcmp(argv[i], "--info") == 0 && i + 1 < argc) {
if (set_nonneg_int_option(&config->info_level, argv[++i], "--info") != 0)
return -1;
config->info_level = atoi(argv[++i]);
} else if (strcmp(argv[i], "--debug") == 0 && i + 1 < argc) {
if (set_nonneg_int_option(&config->debug_level, argv[++i], "--debug") != 0)
return -1;
config->debug_level = atoi(argv[++i]);
} else if (strcmp(argv[i], "--list-only") == 0) {
config->list_only = true;
} else if (strcmp(argv[i], "-h") == 0 || strcmp(argv[i], "--human-readable") == 0) {
@@ -332,8 +336,12 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
} else if (strcmp(argv[i], "--delete-after") == 0) {
config->delete_after = true;
} else if (strcmp(argv[i], "--max-delete") == 0 && i + 1 < argc) {
if (set_nonneg_int_option(&config->max_delete, argv[++i], "--max-delete") != 0)
int val;
if (!parse_nonneg_int(argv[++i], &val)) {
fprintf(stderr, "Error: --max-delete must be a non-negative integer\n");
return -1;
}
config->max_delete = val;
} else if (strcmp(argv[i], "--filter") == 0 && i + 1 < argc) {
if (!config->filters)
config->filters = array_list_create(free);
@@ -342,8 +350,11 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
return -1;
array_list_add(config->filters, dup);
} else if (strcmp(argv[i], "--files-from") == 0 && i + 1 < argc) {
if (set_string_option(&config->files_from, argv[++i], "--files-from") != 0)
char* dup = str_dup(argv[++i]);
if (!dup)
return -1;
free(config->files_from);
config->files_from = dup;
} else if (strcmp(argv[i], "--cvs-exclude") == 0) {
config->cvs_exclude = true;
} else if (strcmp(argv[i], "--prune-empty-dirs") == 0) {
@@ -352,27 +363,45 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
config->relative = true;
} else if (strcmp(argv[i], "-e") == 0 || strcmp(argv[i], "--rsh") == 0) {
if (i + 1 < argc) {
if (set_string_option(&config->rsh_command, argv[++i], "-e/--rsh") != 0)
char* dup = str_dup(argv[++i]);
if (!dup)
return -1;
free(config->rsh_command);
config->rsh_command = dup;
} else {
fprintf(stderr, "Error: -e/--rsh requires a command argument\n");
return -1;
}
} else if (strcmp(argv[i], "--rsync-path") == 0 && i + 1 < argc) {
if (set_string_option(&config->rsync_path, argv[++i], "--rsync-path") != 0)
char* dup = str_dup(argv[++i]);
if (!dup)
return -1;
free(config->rsync_path);
config->rsync_path = dup;
} else if (strcmp(argv[i], "--temp-dir") == 0 && i + 1 < argc) {
if (set_string_option(&config->temp_dir, argv[++i], "--temp-dir") != 0)
char* dup = str_dup(argv[++i]);
if (!dup)
return -1;
free(config->temp_dir);
config->temp_dir = dup;
} else if (strcmp(argv[i], "--compare-dest") == 0 && i + 1 < argc) {
if (set_string_option(&config->compare_dest, argv[++i], "--compare-dest") != 0)
char* dup = str_dup(argv[++i]);
if (!dup)
return -1;
free(config->compare_dest);
config->compare_dest = dup;
} else if (strcmp(argv[i], "--copy-dest") == 0 && i + 1 < argc) {
if (set_string_option(&config->copy_dest, argv[++i], "--copy-dest") != 0)
char* dup = str_dup(argv[++i]);
if (!dup)
return -1;
free(config->copy_dest);
config->copy_dest = dup;
} else if (strcmp(argv[i], "--link-dest") == 0 && i + 1 < argc) {
if (set_string_option(&config->link_dest, argv[++i], "--link-dest") != 0)
char* dup = str_dup(argv[++i]);
if (!dup)
return -1;
free(config->link_dest);
config->link_dest = dup;
} else if (argv[i][0] == '-') {
fprintf(stderr, "Unknown option: %s\n", argv[i]);
print_usage();
+2 -1
View File
@@ -35,7 +35,8 @@ File* file_create(const char* path) {
return NULL;
}
strcpy(file->path, path);
memcpy(file->path, path, path_len);
file->path[path_len] = '\0';
file->data = data_create_reserve(0);
if (file->data == NULL) {
free(file->path);
+12 -8
View File
@@ -13,7 +13,7 @@ bool mkdir_r(const char* path) {
char* path_duplicate = malloc(strlen(path) + 1);
if (!path_duplicate)
return false;
strcpy(path_duplicate, path);
memcpy(path_duplicate, path, strlen(path) + 1);
char* path_current = (char*)malloc((strlen(path) + 2) * sizeof(char));
if (!path_current) {
free(path_duplicate);
@@ -21,7 +21,8 @@ bool mkdir_r(const char* path) {
}
char* path_current_position = path_current;
if (path[0] == '/') {
strcpy(path_current, "/");
path_current[0] = '/';
path_current[1] = '\0';
path_current_position += 1;
} else {
path_current[0] = '\0';
@@ -31,10 +32,12 @@ bool mkdir_r(const char* path) {
const char* part = strtok_r(path_duplicate, delimiter, &saveptr);
bool ok = true;
while (part != NULL) {
strcpy(path_current_position, part);
path_current_position += strlen(part) * sizeof(char);
strcpy(path_current_position, "/");
path_current_position += sizeof(char);
size_t part_len = strlen(part);
memcpy(path_current_position, part, part_len);
path_current_position += part_len;
path_current_position[0] = '/';
path_current_position[1] = '\0';
path_current_position++;
struct stat st;
if (stat(path_current, &st) != 0) {
if (mkdir(path_current, 0755) != 0) {
@@ -53,8 +56,9 @@ bool mkdir_r(const char* path) {
char* str_dup(const char* string) {
if (string == NULL)
return NULL;
char* new_string = (char*)malloc(strlen(string) + 1);
strcpy(new_string, string);
size_t str_len = strlen(string);
char* new_string = (char*)malloc(str_len + 1);
memcpy(new_string, string, str_len + 1);
return new_string;
}