curlx: curlx_strcopy() instead of strcpy()

This function REQUIRES the size of the target buffer as well as the
length of the source string. Meant to make it harder to do a bad
strcpy().

Removes 23 calls to strcpy().

Closes #20067
This commit is contained in:
Daniel Stenberg 2025-12-21 23:40:24 +01:00
parent f099c2ca55
commit a535be4ea0
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
30 changed files with 195 additions and 97 deletions

View file

@ -28,6 +28,7 @@
#include "curl_gssapi.h"
#include "curl_trc.h"
#include "curlx/strcopy.h"
#ifdef DEBUGBUILD
#if defined(HAVE_GSSGNU) || !defined(_WIN32)
@ -224,7 +225,7 @@ stub_gss_init_sec_context(OM_uint32 *min,
return GSS_S_FAILURE;
}
strcpy(ctx->creds, creds);
curlx_strcopy(ctx->creds, sizeof(ctx->creds), creds, strlen(creds));
ctx->flags = req_flags;
}