String safety (#1548)

* Array size UB fixes

* Fix ShieldD

* Remove (almost) all unsafe strcpy calls

Bunch of macros. C arrays are easy enough and just need a different call. For various cases where a char* is passed around bare, I've made a TEXT_SPAN macro that can store a length too for bounds checking.

* Move crash handling in safe string operations to separate TU

* strcat safe version

* sprintf made safe too

* Fix compile
This commit is contained in:
Pieter-Jan Briers
2026-05-24 18:43:00 +02:00
committed by GitHub
parent af162bbd0a
commit a6376368ee
100 changed files with 781 additions and 546 deletions
+4 -4
View File
@@ -163,22 +163,22 @@ void dScnPly_reg_childHIO_c::genMessage(JORMContext* mctx) {
char textbuf[8];
for (int i = 0; i < 20; i++) {
sprintf(textbuf, " F(%02d)", i);
SAFE_SPRINTF(textbuf, " F(%02d)", i);
mctx->genSlider(textbuf, &mFloatReg[i], -100000.0f, 100000.0f);
}
for (int i = 20; i < 25; i++) {
sprintf(textbuf, " F(%02d)", i);
SAFE_SPRINTF(textbuf, " F(%02d)", i);
mctx->genSlider(textbuf, &mFloatReg[i], 0.0f, 1.0f);
}
for (int i = 25; i < 30; i++) {
sprintf(textbuf, " F(%02d)", i);
SAFE_SPRINTF(textbuf, " F(%02d)", i);
mctx->genSlider(textbuf, &mFloatReg[i], -1.0f, 1.0f);
}
for (int i = 0; i < 10; i++) {
sprintf(textbuf, " S(%02d)", i);
SAFE_SPRINTF(textbuf, " S(%02d)", i);
mctx->genSlider(textbuf, &mShortReg[i], -0x8000, 0x7FFF);
}
}