String safety (#1548)

* Array size UB fixes

* Fix ShieldD

* Remove (almost) all unsafe strcpy calls

Bunch of macros. C arrays are easy enough and just need a different call. For various cases where a char* is passed around bare, I've made a TEXT_SPAN macro that can store a length too for bounds checking.

* Move crash handling in safe string operations to separate TU

* strcat safe version

* sprintf made safe too

* Fix compile
This commit is contained in:
Pieter-Jan Briers
2026-05-24 18:43:00 +02:00
committed by GitHub
parent af162bbd0a
commit a6376368ee
100 changed files with 781 additions and 546 deletions
+4 -2
View File
@@ -9,6 +9,8 @@
#include <cmath>
#include <cstdio>
#include <cstdlib>
#include "dusk/string.hpp"
#ifdef __REVOLUTION_SDK__
#include <revolution.h>
#else
@@ -845,8 +847,8 @@ bool JUTException::queryMapAddress(char* mapPath, u32 address, s32 section_id, u
bool begin_with_newline) {
if (mapPath) {
char buffer[80];
strcpy(buffer, mapPath);
strcat(buffer, ".map");
SAFE_STRCPY(buffer, mapPath);
SAFE_STRCAT(buffer, ".map");
if (queryMapAddress_single(buffer, address, section_id, out_addr, out_size, out_line,
line_length, print, begin_with_newline) == true)
{