String safety (#1548)

* Array size UB fixes

* Fix ShieldD

* Remove (almost) all unsafe strcpy calls

Bunch of macros. C arrays are easy enough and just need a different call. For various cases where a char* is passed around bare, I've made a TEXT_SPAN macro that can store a length too for bounds checking.

* Move crash handling in safe string operations to separate TU

* strcat safe version

* sprintf made safe too

* Fix compile
This commit is contained in:
Pieter-Jan Briers
2026-05-24 18:43:00 +02:00
committed by GitHub
parent af162bbd0a
commit a6376368ee
100 changed files with 781 additions and 546 deletions
+4 -2
View File
@@ -26,6 +26,8 @@
#include <cstdio>
#include <cstring>
#include "dusk/string.hpp"
void dComIfG_play_c::ct() {
mWindowNum = 0;
mParticle = NULL;
@@ -2649,7 +2651,7 @@ static void dComIfGs_setWarpItemData(int param_0, char const* i_stage, cXyz i_po
void dComIfG_play_c::setWarpItemData(char const* i_stage, cXyz i_pos, s16 i_angle, s8 i_roomNo,
u8 param_4, u8 param_5) {
strcpy(mItemInfo.mWarpItemData.mWarpItemStage, i_stage);
SAFE_STRCPY(mItemInfo.mWarpItemData.mWarpItemStage, i_stage);
mItemInfo.mWarpItemData.mWarpItemPos.set(i_pos);
mItemInfo.mWarpItemData.mWarpItemAngle = i_angle;
mItemInfo.mWarpItemData.mWarpItemRoom = i_roomNo;
@@ -2736,7 +2738,7 @@ void* dComIfG_getOldStageRes(char const* i_resName) {
char* dComIfG_getRoomArcName(int i_roomNo) {
static char buf[32];
sprintf(buf, "R%02d_00", i_roomNo);
SAFE_SPRINTF(buf, "R%02d_00", i_roomNo);
return buf;
}