If malloc fails inside str_dup, the code continues with NULL pointers. The subsequent NULL check at line 271 will catch this, but the error message will be misleading ("source and destination directories are required" rather than "out of memory").
2. str_dup() for --exclude / --include unchecked (lines 120, 130)
Add NULL checks after every str_dup call, with proper error message.
For --max-size, --min-size, and --chunk-size: pass an endptr and check *end != 0; also check errno for ERANGE.
Add a sensible upper bound for --chunk-size (e.g., 1 GB max).
Consider extracting a helper: static bool parse_u64(const char* str, unsigned long long* out, unsigned long long min, unsigned long long max).
Severity
High
Category
Bug / Reliability
## Description
Several CLI argument parsing paths in `client_cli.c` have inadequate input validation, risking crashes or silent misbehavior:
### 1. str_dup() results unchecked (lines 254-255)
```c
config->send_directory = str_dup(argv[positional_args[0]]);
config->receive_root_directory = str_dup(argv[positional_args[1]]);
```
If `malloc` fails inside `str_dup`, the code continues with NULL pointers. The subsequent NULL check at line 271 will catch this, but the error message will be misleading ("source and destination directories are required" rather than "out of memory").
### 2. str_dup() for --exclude / --include unchecked (lines 120, 130)
```c
config->exclude_patterns[config->exclude_count++] = str_dup(argv[++i]);
```
If `str_dup` returns NULL, the config stores a NULL pattern, and later calls to `glob_match` or `strcmp` may dereference it.
### 3. --max-size / --min-size no errno/endptr validation (lines 131-133)
```c
config->max_size = strtoull(argv[++i], NULL, 10);
```
Passes `NULL` for `endptr` — garbage like `--max-size abc` silently becomes 0. No `errno` check for overflow.
### 4. --chunk-size no lower bound validation (line 213-215)
```c
unsigned long long val = strtoull(argv[++i], NULL, 10);
if (val > 0)
config->chunk_size = val;
```
Passes `NULL` for `endptr`. No upper bound check — chunk_size of ULLONG_MAX would cause allocation failures later.
## Location
`src/client/client_cli.c:120, 130-133, 213-215, 254-255`
## Suggested Fix
1. Add NULL checks after every `str_dup` call, with proper error message.
2. For `--max-size`, `--min-size`, and `--chunk-size`: pass an `endptr` and check `*end != 0`; also check `errno` for `ERANGE`.
3. Add a sensible upper bound for `--chunk-size` (e.g., 1 GB max).
4. Consider extracting a helper: `static bool parse_u64(const char* str, unsigned long long* out, unsigned long long min, unsigned long long max)`.
## Severity
High
## Category
Bug / Reliability
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
Several CLI argument parsing paths in
client_cli.chave inadequate input validation, risking crashes or silent misbehavior:1. str_dup() results unchecked (lines 254-255)
If
mallocfails insidestr_dup, the code continues with NULL pointers. The subsequent NULL check at line 271 will catch this, but the error message will be misleading ("source and destination directories are required" rather than "out of memory").2. str_dup() for --exclude / --include unchecked (lines 120, 130)
If
str_dupreturns NULL, the config stores a NULL pattern, and later calls toglob_matchorstrcmpmay dereference it.3. --max-size / --min-size no errno/endptr validation (lines 131-133)
Passes
NULLforendptr— garbage like--max-size abcsilently becomes 0. Noerrnocheck for overflow.4. --chunk-size no lower bound validation (line 213-215)
Passes
NULLforendptr. No upper bound check — chunk_size of ULLONG_MAX would cause allocation failures later.Location
src/client/client_cli.c:120, 130-133, 213-215, 254-255Suggested Fix
str_dupcall, with proper error message.--max-size,--min-size, and--chunk-size: pass anendptrand check*end != 0; also checkerrnoforERANGE.--chunk-size(e.g., 1 GB max).static bool parse_u64(const char* str, unsigned long long* out, unsigned long long min, unsigned long long max).Severity
High
Category
Bug / Reliability