Description:
Several code paths use strcpy() and strcat() instead of bounded string functions. Although the current inputs are mostly from local CLI or small fixed strings, this is unsafe and blocks strict static analysis:
file_create() in src/shared/file.c:37 copies path into a buffer allocated from strlen(path)+1. If the length calculation is ever wrong, this is a buffer overflow risk.
str_dup() in src/shared/utils.c:55 uses strcpy() and could be replaced with strdup() or memcpy.
mkdir_r() in src/shared/utils.c:15,23,32,34 uses strcpy() and strcat() on stack buffers.
Suggested fix:
Replace strcpy with memcpy + explicit null termination or snprintf(buf, size, "%s", src).
Use strdup() where available (POSIX.1-2008) or add a bounded str_dup helper.
Audit mkdir_r for path-length overflow and simplify it with snprintf/strncat.
Labels: quality, security
**Severity:** low
**Category:** quality / security
**Location:** `src/shared/file.c:37`, `src/shared/utils.c:15,23,32,34,55`
**Description:**
Several code paths use `strcpy()` and `strcat()` instead of bounded string functions. Although the current inputs are mostly from local CLI or small fixed strings, this is unsafe and blocks strict static analysis:
- `file_create()` in `src/shared/file.c:37` copies `path` into a buffer allocated from `strlen(path)+1`. If the length calculation is ever wrong, this is a buffer overflow risk.
- `str_dup()` in `src/shared/utils.c:55` uses `strcpy()` and could be replaced with `strdup()` or `memcpy`.
- `mkdir_r()` in `src/shared/utils.c:15,23,32,34` uses `strcpy()` and `strcat()` on stack buffers.
**Suggested fix:**
- Replace `strcpy` with `memcpy` + explicit null termination or `snprintf(buf, size, "%s", src)`.
- Use `strdup()` where available (POSIX.1-2008) or add a bounded `str_dup` helper.
- Audit `mkdir_r` for path-length overflow and simplify it with `snprintf`/`strncat`.
**Labels:** quality, security
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity: low
Category: quality / security
Location:
src/shared/file.c:37,src/shared/utils.c:15,23,32,34,55Description:
Several code paths use
strcpy()andstrcat()instead of bounded string functions. Although the current inputs are mostly from local CLI or small fixed strings, this is unsafe and blocks strict static analysis:file_create()insrc/shared/file.c:37copiespathinto a buffer allocated fromstrlen(path)+1. If the length calculation is ever wrong, this is a buffer overflow risk.str_dup()insrc/shared/utils.c:55usesstrcpy()and could be replaced withstrdup()ormemcpy.mkdir_r()insrc/shared/utils.c:15,23,32,34usesstrcpy()andstrcat()on stack buffers.Suggested fix:
strcpywithmemcpy+ explicit null termination orsnprintf(buf, size, "%s", src).strdup()where available (POSIX.1-2008) or add a boundedstr_duphelper.mkdir_rfor path-length overflow and simplify it withsnprintf/strncat.Labels: quality, security