String safety (#1548)

* Array size UB fixes

* Fix ShieldD

* Remove (almost) all unsafe strcpy calls

Bunch of macros. C arrays are easy enough and just need a different call. For various cases where a char* is passed around bare, I've made a TEXT_SPAN macro that can store a length too for bounds checking.

* Move crash handling in safe string operations to separate TU

* strcat safe version

* sprintf made safe too

* Fix compile
This commit is contained in:
Pieter-Jan Briers
2026-05-24 18:43:00 +02:00
committed by GitHub
parent af162bbd0a
commit a6376368ee
100 changed files with 781 additions and 546 deletions
+2 -2
View File
@@ -508,12 +508,12 @@ void dMenu_ItemExplain_c::move_select_init() {
"\x1B"
"CR[%d]",
(int)(0.5f * (length - stringLength1)));
strcat(local_64, local_88);
SAFE_STRCAT(local_64, local_88);
snprintf(cStack78, 20,
"\x1B"
"CR[%d]",
(int)(0.5f * (length - stringLength2)));
strcat(cStack78, local_80);
SAFE_STRCAT(cStack78, local_80);
mpSelect_c->setString("", local_64, cStack78);
mpSelect_c->setRubyString("", "", "");
mpSelect_c->selAnimeInit(2, field_0xe2 + 1, 0, length, 0);