String safety (#1548)

* Array size UB fixes

* Fix ShieldD

* Remove (almost) all unsafe strcpy calls

Bunch of macros. C arrays are easy enough and just need a different call. For various cases where a char* is passed around bare, I've made a TEXT_SPAN macro that can store a length too for bounds checking.

* Move crash handling in safe string operations to separate TU

* strcat safe version

* sprintf made safe too

* Fix compile
This commit is contained in:
Pieter-Jan Briers
2026-05-24 18:43:00 +02:00
committed by GitHub
parent af162bbd0a
commit a6376368ee
100 changed files with 781 additions and 546 deletions
+1 -1
View File
@@ -1263,7 +1263,7 @@ bool dPa_control_c::readScene(u8 param_0, mDoDvdThd_toMainRam_c** param_1) {
JUT_ASSERT(2647, !mSceneCount++);
field_0x18 = param_0;
static char jpcName[32];
sprintf(jpcName, "/res/Particle/Pscene%03d.jpc", param_0);
SAFE_SPRINTF(jpcName, "/res/Particle/Pscene%03d.jpc", param_0);
*param_1 = mDoDvdThd_toMainRam_c::create(jpcName, 0, m_resHeap);
return 1;
}