github / github/codeql

False positives - cpp/unbounded-write

Đang mở
#11,557 3 bình luận 0 reaction 0 người được giao Xem trên GitHub
acknowledged C++ false-positive
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

**Description of the false positive**

CodeQL reports false positives from `cpp/unbounded-write` when the destination buffer passed to `strcpy()` has been allocated to be big enough to fit the string according to `strlen()`.

**Code samples or links to source code**

Here is an example from the OpenZFS source code:

```
int len = strlen(drrb->drr_toname);
cp = umem_alloc(len + 2, UMEM_NOFAIL);
cp[0] = '/';
(void) strcpy(&cp[1], drrb->drr_toname);
```

We allocate `cp` to be 2 larger than the length of `drrb->drr_toname`. Then we do a `strcpy()` command that is guaranteed to be safe.

That is from report 783 below.

**URL to the alert on GitHub code scanning (optional)**

https://github.com/ryao/zfs/security/code-scanning/782
https://github.com/ryao/zfs/security/code-scanning/783
https://github.com/ryao/zfs/security/code-scanning/784

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.