False positives - cpp/unbounded-write
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the false positive**
CodeQL reports false positives from `cpp/unbounded-write` when the destination buffer passed to `strcpy()` has been allocated to be big enough to fit the string according to `strlen()`.
**Code samples or links to source code**
Here is an example from the OpenZFS source code:
```
int len = strlen(drrb->drr_toname);
cp = umem_alloc(len + 2, UMEM_NOFAIL);
cp[0] = '/';
(void) strcpy(&cp[1], drrb->drr_toname);
```
We allocate `cp` to be 2 larger than the length of `drrb->drr_toname`. Then we do a `strcpy()` command that is guaranteed to be safe.
That is from report 783 below.
**URL to the alert on GitHub code scanning (optional)**
https://github.com/ryao/zfs/security/code-scanning/782
https://github.com/ryao/zfs/security/code-scanning/783
https://github.com/ryao/zfs/security/code-scanning/784
貢獻指南
評估
這個 Issue 還沒有評估資料。