In src/shared/utils.c:29, mkdir_r() uses strtok() to split the path into components:
constchar*part=strtok(path_duplicate,delimiter);
strtok() uses a hidden static buffer and is not thread-safe. If two threads call mkdir_r() simultaneously (e.g., during multithreaded file writing on the server), the paths will be interleaved and corrupted.
Additionally, strtok() modifies the input string in-place (which is why it takes char* not const char*), but the code already makes a duplicate for this purpose.
Fix: Replace strtok() with strtok_r() (the reentrant version) or manually parse the string character-by-character.
Location:src/shared/utils.c:29
Severity: high
In `src/shared/utils.c:29`, `mkdir_r()` uses `strtok()` to split the path into components:
```c
const char* part = strtok(path_duplicate, delimiter);
```
`strtok()` uses a hidden static buffer and is **not thread-safe**. If two threads call `mkdir_r()` simultaneously (e.g., during multithreaded file writing on the server), the paths will be interleaved and corrupted.
Additionally, `strtok()` modifies the input string in-place (which is why it takes `char*` not `const char*`), but the code already makes a duplicate for this purpose.
**Fix:** Replace `strtok()` with `strtok_r()` (the reentrant version) or manually parse the string character-by-character.
**Location:** `src/shared/utils.c:29`
**Severity:** high
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
In
src/shared/utils.c:29,mkdir_r()usesstrtok()to split the path into components:strtok()uses a hidden static buffer and is not thread-safe. If two threads callmkdir_r()simultaneously (e.g., during multithreaded file writing on the server), the paths will be interleaved and corrupted.Additionally,
strtok()modifies the input string in-place (which is why it takeschar*notconst char*), but the code already makes a duplicate for this purpose.Fix: Replace
strtok()withstrtok_r()(the reentrant version) or manually parse the string character-by-character.Location:
src/shared/utils.c:29Severity: high