curlx: curlx_strcopy() instead of strcpy()

This function REQUIRES the size of the target buffer as well as the
length of the source string. Meant to make it harder to do a bad
strcpy().

Removes 23 calls to strcpy().

Closes #20067
This commit is contained in:
Daniel Stenberg 2025-12-21 23:40:24 +01:00
parent f099c2ca55
commit a535be4ea0
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
30 changed files with 195 additions and 97 deletions

View file

@ -40,7 +40,7 @@
#include "curl_ntlm_core.h"
#include "escape.h"
#include "curl_endian.h"
#include "curlx/strcopy.h"
/* meta key for storing protocol meta at easy handle */
#define CURL_META_SMB_EASY "meta:proto:smb:easy"
@ -790,7 +790,7 @@ static CURLcode smb_send_open(struct Curl_easy *data,
msg.create_disposition = smb_swap32(SMB_FILE_OPEN);
}
msg.byte_count = smb_swap16((unsigned short)byte_count);
strcpy(msg.bytes, req->path);
curlx_strcopy(msg.bytes, sizeof(msg.bytes), req->path, byte_count - 1);
return smb_send_message(data, smbc, req, SMB_COM_NT_CREATE_ANDX, &msg,
sizeof(msg) - sizeof(msg.bytes) + byte_count);