github / github/codeql

False positives - cpp/unbounded-write

未關閉
#11,557 3 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
acknowledged C++ false-positive
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the false positive**

CodeQL reports false positives from `cpp/unbounded-write` when the destination buffer passed to `strcpy()` has been allocated to be big enough to fit the string according to `strlen()`.

**Code samples or links to source code**

Here is an example from the OpenZFS source code:

```
int len = strlen(drrb->drr_toname);
cp = umem_alloc(len + 2, UMEM_NOFAIL);
cp[0] = '/';
(void) strcpy(&cp[1], drrb->drr_toname);
```

We allocate `cp` to be 2 larger than the length of `drrb->drr_toname`. Then we do a `strcpy()` command that is guaranteed to be safe.

That is from report 783 below.

**URL to the alert on GitHub code scanning (optional)**

https://github.com/ryao/zfs/security/code-scanning/782
https://github.com/ryao/zfs/security/code-scanning/783
https://github.com/ryao/zfs/security/code-scanning/784

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。