client_cli.c declares char* server_host = "127.0.0.1"; at file scope. When the user provides --server-host, the code does free(server_host); and assigns a newly allocated string. If server_host is never reassigned (the common case), no free() is called, so the literal is safe. However, the pattern is fragile: any future change that frees the default value would invoke undefined behavior.
Location
src/client/client_cli.c:14 — server_host initialized to a string literal.
src/client/client_cli.c:160 — free(server_host); before reassignment.
Suggested fix
Initialize server_host with str_dup("127.0.0.1") so it is always heap-allocated.
Ensure server_host is freed during cleanup.
Severity
Low
Category
bug, quality
This issue was automatically generated by the issue-creator agent.
## Description
`client_cli.c` declares `char* server_host = "127.0.0.1";` at file scope. When the user provides `--server-host`, the code does `free(server_host);` and assigns a newly allocated string. If `server_host` is never reassigned (the common case), no `free()` is called, so the literal is safe. However, the pattern is fragile: any future change that frees the default value would invoke undefined behavior.
## Location
- `src/client/client_cli.c:14` — `server_host` initialized to a string literal.
- `src/client/client_cli.c:160` — `free(server_host);` before reassignment.
## Suggested fix
1. Initialize `server_host` with `str_dup("127.0.0.1")` so it is always heap-allocated.
2. Ensure `server_host` is freed during cleanup.
## Severity
Low
## Category
bug, quality
---
_This issue was automatically generated by the issue-creator agent._
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
client_cli.cdeclareschar* server_host = "127.0.0.1";at file scope. When the user provides--server-host, the code doesfree(server_host);and assigns a newly allocated string. Ifserver_hostis never reassigned (the common case), nofree()is called, so the literal is safe. However, the pattern is fragile: any future change that frees the default value would invoke undefined behavior.Location
src/client/client_cli.c:14—server_hostinitialized to a string literal.src/client/client_cli.c:160—free(server_host);before reassignment.Suggested fix
server_hostwithstr_dup("127.0.0.1")so it is always heap-allocated.server_hostis freed during cleanup.Severity
Low
Category
bug, quality
This issue was automatically generated by the issue-creator agent.