mirror of
https://github.com/github/codeql.git
synced 2026-05-05 13:45:19 +02:00
C++: Use range analysis in 'cpp/overrun-write' and accept test changes.
This commit is contained in:
@@ -1,52 +1,18 @@
|
||||
edges
|
||||
| test.cpp:16:11:16:21 | VariableAddress indirection [string] | test.cpp:24:21:24:31 | Call indirection [string] |
|
||||
| test.cpp:16:11:16:21 | VariableAddress indirection [string] | test.cpp:34:21:34:31 | Call indirection [string] |
|
||||
| test.cpp:16:11:16:21 | VariableAddress indirection [string] | test.cpp:39:21:39:31 | Call indirection [string] |
|
||||
| test.cpp:18:5:18:30 | Store | test.cpp:18:10:18:15 | Load indirection [post update] [string] |
|
||||
| test.cpp:18:10:18:15 | Load indirection [post update] [string] | test.cpp:16:11:16:21 | VariableAddress indirection [string] |
|
||||
| test.cpp:18:19:18:24 | call to malloc | test.cpp:18:5:18:30 | Store |
|
||||
| test.cpp:24:21:24:31 | Call indirection [string] | test.cpp:26:13:26:15 | Load indirection [string] |
|
||||
| test.cpp:26:13:26:15 | Load indirection [string] | test.cpp:26:18:26:23 | FieldAddress indirection |
|
||||
| test.cpp:26:18:26:23 | FieldAddress indirection | test.cpp:26:18:26:23 | Load |
|
||||
| test.cpp:29:32:29:34 | str indirection [string] | test.cpp:30:13:30:15 | Load indirection [string] |
|
||||
| test.cpp:30:13:30:15 | Load indirection [string] | test.cpp:30:18:30:23 | FieldAddress indirection |
|
||||
| test.cpp:30:18:30:23 | FieldAddress indirection | test.cpp:30:18:30:23 | Load |
|
||||
| test.cpp:34:21:34:31 | Call indirection [string] | test.cpp:35:21:35:23 | str indirection [string] |
|
||||
| test.cpp:35:21:35:23 | str indirection [string] | test.cpp:29:32:29:34 | str indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:41:13:41:15 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:42:13:42:15 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:44:13:44:15 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:45:13:45:15 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:48:17:48:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:52:17:52:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:56:17:56:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:60:17:60:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:64:17:64:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:68:17:68:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:72:17:72:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:76:17:76:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:80:17:80:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:84:17:84:19 | Load indirection [string] |
|
||||
| test.cpp:41:13:41:15 | Load indirection [string] | test.cpp:41:18:41:23 | FieldAddress indirection |
|
||||
| test.cpp:41:18:41:23 | FieldAddress indirection | test.cpp:41:18:41:23 | Load |
|
||||
| test.cpp:42:13:42:15 | Load indirection [string] | test.cpp:42:18:42:23 | FieldAddress indirection |
|
||||
| test.cpp:42:18:42:23 | FieldAddress indirection | test.cpp:42:18:42:23 | Load |
|
||||
| test.cpp:44:13:44:15 | Load indirection [string] | test.cpp:44:18:44:23 | FieldAddress indirection |
|
||||
| test.cpp:44:18:44:23 | FieldAddress indirection | test.cpp:44:18:44:23 | Load |
|
||||
| test.cpp:45:13:45:15 | Load indirection [string] | test.cpp:45:18:45:23 | FieldAddress indirection |
|
||||
| test.cpp:45:18:45:23 | FieldAddress indirection | test.cpp:45:18:45:23 | Load |
|
||||
| test.cpp:48:17:48:19 | Load indirection [string] | test.cpp:48:22:48:27 | FieldAddress indirection |
|
||||
| test.cpp:48:22:48:27 | FieldAddress indirection | test.cpp:48:22:48:27 | Load |
|
||||
| test.cpp:52:17:52:19 | Load indirection [string] | test.cpp:52:22:52:27 | FieldAddress indirection |
|
||||
| test.cpp:52:22:52:27 | FieldAddress indirection | test.cpp:52:22:52:27 | Load |
|
||||
| test.cpp:56:17:56:19 | Load indirection [string] | test.cpp:56:22:56:27 | FieldAddress indirection |
|
||||
| test.cpp:56:22:56:27 | FieldAddress indirection | test.cpp:56:22:56:27 | Load |
|
||||
| test.cpp:60:17:60:19 | Load indirection [string] | test.cpp:60:22:60:27 | FieldAddress indirection |
|
||||
| test.cpp:60:22:60:27 | FieldAddress indirection | test.cpp:60:22:60:27 | Load |
|
||||
| test.cpp:64:17:64:19 | Load indirection [string] | test.cpp:64:22:64:27 | FieldAddress indirection |
|
||||
| test.cpp:64:22:64:27 | FieldAddress indirection | test.cpp:64:22:64:27 | Load |
|
||||
| test.cpp:68:17:68:19 | Load indirection [string] | test.cpp:68:22:68:27 | FieldAddress indirection |
|
||||
| test.cpp:68:22:68:27 | FieldAddress indirection | test.cpp:68:22:68:27 | Load |
|
||||
| test.cpp:72:17:72:19 | Load indirection [string] | test.cpp:72:22:72:27 | FieldAddress indirection |
|
||||
| test.cpp:72:22:72:27 | FieldAddress indirection | test.cpp:72:22:72:27 | Load |
|
||||
| test.cpp:76:17:76:19 | Load indirection [string] | test.cpp:76:22:76:27 | FieldAddress indirection |
|
||||
@@ -59,40 +25,16 @@ edges
|
||||
| test.cpp:90:5:90:34 | Store | test.cpp:90:10:90:15 | Load indirection [post update] [string] |
|
||||
| test.cpp:90:10:90:15 | Load indirection [post update] [string] | test.cpp:88:11:88:30 | VariableAddress indirection [string] |
|
||||
| test.cpp:90:19:90:24 | call to malloc | test.cpp:90:5:90:34 | Store |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:98:13:98:15 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:99:13:99:15 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:101:13:101:15 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:102:13:102:15 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:105:17:105:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:109:17:109:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:113:17:113:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:117:17:117:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:121:17:121:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:125:17:125:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:129:17:129:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:133:17:133:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:137:17:137:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:141:17:141:19 | Load indirection [string] |
|
||||
| test.cpp:98:13:98:15 | Load indirection [string] | test.cpp:98:18:98:23 | FieldAddress indirection |
|
||||
| test.cpp:98:18:98:23 | FieldAddress indirection | test.cpp:98:18:98:23 | Load |
|
||||
| test.cpp:99:13:99:15 | Load indirection [string] | test.cpp:99:18:99:23 | FieldAddress indirection |
|
||||
| test.cpp:99:18:99:23 | FieldAddress indirection | test.cpp:99:18:99:23 | Load |
|
||||
| test.cpp:101:13:101:15 | Load indirection [string] | test.cpp:101:18:101:23 | FieldAddress indirection |
|
||||
| test.cpp:101:18:101:23 | FieldAddress indirection | test.cpp:101:18:101:23 | Load |
|
||||
| test.cpp:102:13:102:15 | Load indirection [string] | test.cpp:102:18:102:23 | FieldAddress indirection |
|
||||
| test.cpp:102:18:102:23 | FieldAddress indirection | test.cpp:102:18:102:23 | Load |
|
||||
| test.cpp:105:17:105:19 | Load indirection [string] | test.cpp:105:22:105:27 | FieldAddress indirection |
|
||||
| test.cpp:105:22:105:27 | FieldAddress indirection | test.cpp:105:22:105:27 | Load |
|
||||
| test.cpp:109:17:109:19 | Load indirection [string] | test.cpp:109:22:109:27 | FieldAddress indirection |
|
||||
| test.cpp:109:22:109:27 | FieldAddress indirection | test.cpp:109:22:109:27 | Load |
|
||||
| test.cpp:113:17:113:19 | Load indirection [string] | test.cpp:113:22:113:27 | FieldAddress indirection |
|
||||
| test.cpp:113:22:113:27 | FieldAddress indirection | test.cpp:113:22:113:27 | Load |
|
||||
| test.cpp:117:17:117:19 | Load indirection [string] | test.cpp:117:22:117:27 | FieldAddress indirection |
|
||||
| test.cpp:117:22:117:27 | FieldAddress indirection | test.cpp:117:22:117:27 | Load |
|
||||
| test.cpp:121:17:121:19 | Load indirection [string] | test.cpp:121:22:121:27 | FieldAddress indirection |
|
||||
| test.cpp:121:22:121:27 | FieldAddress indirection | test.cpp:121:22:121:27 | Load |
|
||||
| test.cpp:125:17:125:19 | Load indirection [string] | test.cpp:125:22:125:27 | FieldAddress indirection |
|
||||
| test.cpp:125:22:125:27 | FieldAddress indirection | test.cpp:125:22:125:27 | Load |
|
||||
| test.cpp:129:17:129:19 | Load indirection [string] | test.cpp:129:22:129:27 | FieldAddress indirection |
|
||||
| test.cpp:129:22:129:27 | FieldAddress indirection | test.cpp:129:22:129:27 | Load |
|
||||
| test.cpp:133:17:133:19 | Load indirection [string] | test.cpp:133:22:133:27 | FieldAddress indirection |
|
||||
@@ -106,47 +48,13 @@ nodes
|
||||
| test.cpp:18:5:18:30 | Store | semmle.label | Store |
|
||||
| test.cpp:18:10:18:15 | Load indirection [post update] [string] | semmle.label | Load indirection [post update] [string] |
|
||||
| test.cpp:18:19:18:24 | call to malloc | semmle.label | call to malloc |
|
||||
| test.cpp:24:21:24:31 | Call indirection [string] | semmle.label | Call indirection [string] |
|
||||
| test.cpp:26:13:26:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:26:18:26:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:26:18:26:23 | Load | semmle.label | Load |
|
||||
| test.cpp:29:32:29:34 | str indirection [string] | semmle.label | str indirection [string] |
|
||||
| test.cpp:30:13:30:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:30:18:30:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:30:18:30:23 | Load | semmle.label | Load |
|
||||
| test.cpp:34:21:34:31 | Call indirection [string] | semmle.label | Call indirection [string] |
|
||||
| test.cpp:35:21:35:23 | str indirection [string] | semmle.label | str indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | semmle.label | Call indirection [string] |
|
||||
| test.cpp:41:13:41:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:41:18:41:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:41:18:41:23 | Load | semmle.label | Load |
|
||||
| test.cpp:42:13:42:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:42:18:42:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:42:18:42:23 | Load | semmle.label | Load |
|
||||
| test.cpp:44:13:44:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:44:18:44:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:44:18:44:23 | Load | semmle.label | Load |
|
||||
| test.cpp:45:13:45:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:45:18:45:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:45:18:45:23 | Load | semmle.label | Load |
|
||||
| test.cpp:48:17:48:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:48:22:48:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:48:22:48:27 | Load | semmle.label | Load |
|
||||
| test.cpp:52:17:52:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:52:22:52:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:52:22:52:27 | Load | semmle.label | Load |
|
||||
| test.cpp:56:17:56:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:56:22:56:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:56:22:56:27 | Load | semmle.label | Load |
|
||||
| test.cpp:60:17:60:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:60:22:60:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:60:22:60:27 | Load | semmle.label | Load |
|
||||
| test.cpp:64:17:64:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:64:22:64:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:64:22:64:27 | Load | semmle.label | Load |
|
||||
| test.cpp:68:17:68:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:68:22:68:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:68:22:68:27 | Load | semmle.label | Load |
|
||||
| test.cpp:72:17:72:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:72:22:72:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:72:22:72:27 | Load | semmle.label | Load |
|
||||
@@ -164,36 +72,12 @@ nodes
|
||||
| test.cpp:90:10:90:15 | Load indirection [post update] [string] | semmle.label | Load indirection [post update] [string] |
|
||||
| test.cpp:90:19:90:24 | call to malloc | semmle.label | call to malloc |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | semmle.label | Call indirection [string] |
|
||||
| test.cpp:98:13:98:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:98:18:98:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:98:18:98:23 | Load | semmle.label | Load |
|
||||
| test.cpp:99:13:99:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:99:18:99:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:99:18:99:23 | Load | semmle.label | Load |
|
||||
| test.cpp:101:13:101:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:101:18:101:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:101:18:101:23 | Load | semmle.label | Load |
|
||||
| test.cpp:102:13:102:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:102:18:102:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:102:18:102:23 | Load | semmle.label | Load |
|
||||
| test.cpp:105:17:105:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:105:22:105:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:105:22:105:27 | Load | semmle.label | Load |
|
||||
| test.cpp:109:17:109:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:109:22:109:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:109:22:109:27 | Load | semmle.label | Load |
|
||||
| test.cpp:113:17:113:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:113:22:113:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:113:22:113:27 | Load | semmle.label | Load |
|
||||
| test.cpp:117:17:117:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:117:22:117:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:117:22:117:27 | Load | semmle.label | Load |
|
||||
| test.cpp:121:17:121:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:121:22:121:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:121:22:121:27 | Load | semmle.label | Load |
|
||||
| test.cpp:125:17:125:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:125:22:125:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:125:22:125:27 | Load | semmle.label | Load |
|
||||
| test.cpp:129:17:129:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:129:22:129:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:129:22:129:27 | Load | semmle.label | Load |
|
||||
@@ -208,6 +92,6 @@ nodes
|
||||
| test.cpp:141:22:141:27 | Load | semmle.label | Load |
|
||||
subpaths
|
||||
#select
|
||||
| test.cpp:26:18:26:23 | Load | test.cpp:18:19:18:24 | call to malloc | test.cpp:26:18:26:23 | Load | Overrunning write allocated at $@ bounded by $@. | test.cpp:18:19:18:24 | call to malloc | call to malloc | test.cpp:26:36:26:39 | Load | Load |
|
||||
| test.cpp:30:18:30:23 | Load | test.cpp:18:19:18:24 | call to malloc | test.cpp:30:18:30:23 | Load | Overrunning write allocated at $@ bounded by $@. | test.cpp:18:19:18:24 | call to malloc | call to malloc | test.cpp:30:36:30:39 | Load | Load |
|
||||
| test.cpp:41:18:41:23 | Load | test.cpp:18:19:18:24 | call to malloc | test.cpp:41:18:41:23 | Load | Overrunning write allocated at $@ bounded by $@. | test.cpp:18:19:18:24 | call to malloc | call to malloc | test.cpp:41:36:41:39 | Load | Load |
|
||||
| test.cpp:42:5:42:11 | call to strncpy | test.cpp:18:19:18:24 | call to malloc | test.cpp:42:18:42:23 | Load | This write may overflow $@ by 1 element. | test.cpp:42:18:42:23 | string | string |
|
||||
| test.cpp:72:9:72:15 | call to strncpy | test.cpp:18:19:18:24 | call to malloc | test.cpp:72:22:72:27 | Load | This write may overflow $@ by 1 element. | test.cpp:72:22:72:27 | string | string |
|
||||
| test.cpp:80:9:80:15 | call to strncpy | test.cpp:18:19:18:24 | call to malloc | test.cpp:80:22:80:27 | Load | This write may overflow $@ by 2 elements. | test.cpp:80:22:80:27 | string | string |
|
||||
|
||||
@@ -23,11 +23,11 @@ string_t *mk_string_t(int size) {
|
||||
void test1(int size, char *buf) {
|
||||
string_t *str = mk_string_t(size);
|
||||
|
||||
strncpy(str->string, buf, str->size); // GOOD [FALSE POSITIVE]
|
||||
strncpy(str->string, buf, str->size); // GOOD
|
||||
}
|
||||
|
||||
void strncpy_wrapper(string_t *str, char *buf) {
|
||||
strncpy(str->string, buf, str->size); // GOOD [FALSE POSITIVE]
|
||||
strncpy(str->string, buf, str->size); // GOOD
|
||||
}
|
||||
|
||||
void test2(int size, char *buf) {
|
||||
@@ -38,8 +38,8 @@ void test2(int size, char *buf) {
|
||||
void test3(unsigned size, char *buf, unsigned anotherSize) {
|
||||
string_t *str = mk_string_t(size);
|
||||
|
||||
strncpy(str->string, buf, str->size); // GOOD [FALSE POSITIVE]
|
||||
strncpy(str->string, buf, str->size + 1); // BAD [NOT DETECTED]
|
||||
strncpy(str->string, buf, str->size); // GOOD
|
||||
strncpy(str->string, buf, str->size + 1); // BAD
|
||||
|
||||
strncpy(str->string, buf, size); // GOOD
|
||||
strncpy(str->string, buf, size + 1); // BAD [NOT DETECTED]
|
||||
@@ -69,7 +69,7 @@ void test3(unsigned size, char *buf, unsigned anotherSize) {
|
||||
}
|
||||
|
||||
if(anotherSize <= str->size + 1) {
|
||||
strncpy(str->string, buf, anotherSize); // BAD [NOT DETECTED]
|
||||
strncpy(str->string, buf, anotherSize); // BAD
|
||||
}
|
||||
|
||||
if(anotherSize <= size + 1) {
|
||||
@@ -77,7 +77,7 @@ void test3(unsigned size, char *buf, unsigned anotherSize) {
|
||||
}
|
||||
|
||||
if(anotherSize <= str->size + 2) {
|
||||
strncpy(str->string, buf, anotherSize); // BAD [NOT DETECTED]
|
||||
strncpy(str->string, buf, anotherSize); // BAD
|
||||
}
|
||||
|
||||
if(anotherSize <= size + 2) {
|
||||
|
||||
Reference in New Issue
Block a user