Fix format-string use of __FILE__/__func__ and name_for_status lower bound
Two hardening fixes flagged by the earlier review: 1. FAIL passed __FILE__ and __func__ directly as the snprintf format string. __FILE__ expands to a string literal that could contain a '%' (a build path under a directory with a percent sign), and __func__ is not a literal at all; either way snprintf would read nonexistent varargs. Pass them as "%s" arguments instead. 2. akerr_name_for_status guarded the upper bound but not the lower one, so a negative status indexed __AKERR_ERROR_NAMES[negative] -- an out-of-bounds read, or an out-of-bounds write when a name was supplied. Reject status < 0. Regression tests err_format_string (uses #line to put a conversion specifier in __FILE__) and err_name_bounds fail against the old code (verified) and pass now. Full suite: 23/23, no warnings. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -190,8 +190,8 @@ void akerr_init_errno(void);
|
||||
#define FAIL(__err_context, __err, __message, ...) \
|
||||
ENSURE_ERROR_READY(__err_context); \
|
||||
__err_context->status = __err; \
|
||||
snprintf((char *)__err_context->fname, AKERR_MAX_ERROR_FNAME_LENGTH, __FILE__); \
|
||||
snprintf((char *)__err_context->function, AKERR_MAX_ERROR_FUNCTION_LENGTH, __func__); \
|
||||
snprintf((char *)__err_context->fname, AKERR_MAX_ERROR_FNAME_LENGTH, "%s", __FILE__); \
|
||||
snprintf((char *)__err_context->function, AKERR_MAX_ERROR_FUNCTION_LENGTH, "%s", __func__); \
|
||||
__err_context->lineno = __LINE__; \
|
||||
snprintf((char *)__err_context->message, AKERR_MAX_ERROR_CONTEXT_STRING_LENGTH, __message, ## __VA_ARGS__); \
|
||||
AKERR_STACKTRACE_APPEND(__err_context, "%s:%s:%d: %d (%s) : %s\n", (char *)__err_context->fname, (char *)__err_context->function, __err_context->lineno, __err_context->status, akerr_name_for_status(__err_context->status, NULL), (__err_context->message == NULL ? "" : __err_context->message));
|
||||
|
||||
Reference in New Issue
Block a user