cf-https-connect: silence clang-tidy v21 false positive

content_encoding: another one

```
/Users/runner/work/curl/curl/lib/content_encoding.c:657:5: error: Out of bound access to memory preceding 'all' [clang-analyzer-security.ArrayBound,-warnings-as-errors]
  657 |     p[-2] = '\0';
      |     ^
```
Ref: https://github.com/curl/curl/actions/runs/17295803554/job/49093573741?pr=18422#step:11:40

mime.c

/Users/runner/work/curl/curl/lib/mime.c:1756:12: error: Out of bound access to memory after the end of the string literal [clang-analyzer-security.ArrayBound,-warnings-as-errors]
 1756 |     switch(contenttype[len]) {
      |            ^
https://github.com/curl/curl/actions/runs/17295955998/job/49094149140?pr=18422#step:11:127

ntlm.c

```
/Users/runner/work/curl/curl/lib/vauth/ntlm.c:414:5: error: Out of bound access to memory after the end of 'ntlmbuf' [clang-analyzer-security.ArrayBound,-warnings-as-errors]
  414 |     dest[2 * i] = (unsigned char)src[i];
      |     ^
```
https://github.com/curl/curl/actions/runs/17296813157/job/49097003881?pr=18422#step:11:157

ntlm.c more

/Users/runner/work/curl/curl/lib/vauth/ntlm.c:836:17: error: Out of bound access to memory after the end of 'ntlmbuf' [clang-analyzer-security.ArrayBound,-warnings-as-errors]
  836 |     unicodecpy(&ntlmbuf[size], host, hostlen / 2);
      |                 ^~~~~~~~~~~~~
https://github.com/curl/curl/actions/runs/17296961941/job/49097574789?pr=18422#step:11:157

silence bunch more

https://github.com/curl/curl/actions/runs/17297304862/job/49098795447?pr=18422

silence bunch more 2

more odd cases in vtls.c
This commit is contained in:
Viktor Szakats 2025-08-28 14:26:43 +02:00
parent f08ecdc586
commit 36e08e5e62
No known key found for this signature in database
GPG key ID: B5ABD165E2AEF201
12 changed files with 21 additions and 0 deletions

View file

@ -75,6 +75,7 @@ static void cf_hc_baller_reset(struct cf_hc_baller *b,
static bool cf_hc_baller_is_active(struct cf_hc_baller *b)
{
/* NOLINTNEXTLINE(clang-analyzer-security.ArrayBound) */
return b->cf && !b->result;
}

View file

@ -654,6 +654,7 @@ void Curl_all_content_encodings(char *buf, size_t blen)
*p++ = ' ';
}
}
/* NOLINTNEXTLINE(clang-analyzer-security.ArrayBound) */
p[-2] = '\0';
}
}

View file

@ -1753,6 +1753,7 @@ static bool content_type_match(const char *contenttype,
const char *target, size_t len)
{
if(contenttype && curl_strnequal(contenttype, target, len))
/* NOLINTNEXTLINE(clang-analyzer-security.ArrayBound) */
switch(contenttype[len]) {
case '\0':
case '\t':

View file

@ -411,6 +411,7 @@ static void unicodecpy(unsigned char *dest, const char *src, size_t length)
{
size_t i;
for(i = 0; i < length; i++) {
/* NOLINTNEXTLINE(clang-analyzer-security.ArrayBound) */
dest[2 * i] = (unsigned char)src[i];
dest[2 * i + 1] = '\0';
}
@ -832,6 +833,7 @@ CURLcode Curl_auth_create_ntlm_type3_message(struct Curl_easy *data,
DEBUGASSERT(size == hostoff);
if(unicode)
/* NOLINTNEXTLINE(clang-analyzer-security.ArrayBound) */
unicodecpy(&ntlmbuf[size], host, hostlen / 2);
else
memcpy(&ntlmbuf[size], host, hostlen);

View file

@ -1048,6 +1048,7 @@ static size_t multissl_version(char *buffer, size_t size)
backends[0] = '\0';
/* NOLINTNEXTLINE(clang-analyzer-security.ArrayBound) */
for(i = 0; available_backends[i]; ++i) {
char vb[200];
bool paren = (selected != available_backends[i]);
@ -1088,6 +1089,7 @@ static int multissl_setup(const struct Curl_ssl *backend)
env = curl_getenv("CURL_SSL_BACKEND");
if(env) {
/* NOLINTNEXTLINE(clang-analyzer-security.ArrayBound) */
for(i = 0; available_backends[i]; i++) {
if(curl_strequal(env, available_backends[i]->info.name)) {
Curl_ssl = available_backends[i];
@ -1134,6 +1136,7 @@ CURLsslset Curl_init_sslset_nolock(curl_sslbackend id, const char *name,
CURLSSLSET_UNKNOWN_BACKEND;
#endif
/* NOLINTNEXTLINE(clang-analyzer-security.ArrayBound) */
for(i = 0; available_backends[i]; i++) {
if(available_backends[i]->info.id == id ||
(name && curl_strequal(available_backends[i]->info.name, name))) {