Harden compiler flags, simplify CWE-134 script, fix bugs found by new warnings
configure.ac: - Replace basic -Wformat/-Wformat-nonliteral with -Wformat=2 - Add -Wextra, -Wnull-dereference, -Wpointer-arith, -Wimplicit-function-declaration - Add -fstack-protector-strong, -fno-common, -D_FORTIFY_SOURCE=2 - Add GCC-specific flags via AC_COMPILE_IFELSE: -Wlogical-op, -Wduplicated-cond, -Wduplicated-branches, -Wstringop-overflow - Add linker hardening via AC_LINK_IFELSE: -Wl,-z,relro -Wl,-z,now - Suppress noisy -Wextra sub-warnings: -Wno-unused-parameter, -Wno-missing-field-initializers, -Wno-sign-compare, -Wno-cast-function-type - Remove AM_CFLAGS/CFLAGS duplication line check-cwe134.sh: - Reduce from 5 checks to 2 (checks 1-3 are now redundant with -Wformat=2) - Check 1: verify known wrappers have G_GNUC_PRINTF attribute - Check 2: auto-detect unannotated variadic printf-like functions Bug fixes found by -Wduplicated-branches: - chatlog.c: non-MUCPM redact path passed resourcepart instead of NULL - rosterwin.c: two instances of if/else with identical branches in roster count - omemo.c: redundant else-if branch in omemo_automatic_start Other fixes for new warnings: - console.c: pointer compared to integer 0 instead of NULL (2 instances) - vcard.c: NULL guard for filename before g_file_set_contents - files.c: refactor to early return, eliminating NULL logfile path - database.c: const-correctness for type, query, sort variables - form.c/xmpp.h: const-correctness for form_set_value parameter - muc.c/muc.h: remove meaningless top-level const on return type - common.c: const-correctness for URL string literal - xmpp/omemo.c: scope block for declarations after goto, move from decl before goto, replace goto with direct return - http_common.h: add G_GNUC_PRINTF attributes for http_print_transfer* - test_common.c: add currb NULL check to silence -Wnull-dereference
This commit is contained in:
@@ -353,6 +353,7 @@ omemo_receive_message(xmpp_stanza_t* const stanza, gboolean* trusted)
|
||||
{
|
||||
char* plaintext = NULL;
|
||||
const char* type = xmpp_stanza_get_type(stanza);
|
||||
const char* from = xmpp_stanza_get_from(stanza);
|
||||
GList* keys = NULL;
|
||||
unsigned char* iv_raw = NULL;
|
||||
unsigned char* payload_raw = NULL;
|
||||
@@ -434,8 +435,6 @@ omemo_receive_message(xmpp_stanza_t* const stanza, gboolean* trusted)
|
||||
keys = g_list_append(keys, key);
|
||||
}
|
||||
|
||||
const char* from = xmpp_stanza_get_from(stanza);
|
||||
|
||||
plaintext = omemo_on_message_recv(from, sid, iv_raw, iv_len,
|
||||
keys, payload_raw, payload_len,
|
||||
g_strcmp0(type, STANZA_TYPE_GROUPCHAT) == 0, trusted);
|
||||
@@ -471,7 +470,8 @@ _omemo_receive_devicelist(xmpp_stanza_t* const stanza, void* const userdata)
|
||||
|
||||
const char* code = xmpp_stanza_get_attribute(error, "code");
|
||||
if (g_strcmp0(code, "404") == 0) {
|
||||
goto out;
|
||||
omemo_set_device_list(from, NULL);
|
||||
return 1;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -520,22 +520,25 @@ _omemo_receive_devicelist(xmpp_stanza_t* const stanza, void* const userdata)
|
||||
goto out;
|
||||
}
|
||||
|
||||
xmpp_stanza_t* list = xmpp_stanza_get_child_by_ns(item, STANZA_NS_OMEMO);
|
||||
if (!list) {
|
||||
return 1;
|
||||
}
|
||||
|
||||
xmpp_stanza_t* device;
|
||||
for (device = xmpp_stanza_get_children(list); device != NULL; device = xmpp_stanza_get_next(device)) {
|
||||
if (g_strcmp0(xmpp_stanza_get_name(device), "device") != 0) {
|
||||
continue;
|
||||
/* New scope to keep declarations after goto out above */
|
||||
{
|
||||
xmpp_stanza_t* list = xmpp_stanza_get_child_by_ns(item, STANZA_NS_OMEMO);
|
||||
if (!list) {
|
||||
return 1;
|
||||
}
|
||||
|
||||
const char* id = xmpp_stanza_get_id(device);
|
||||
if (id != NULL) {
|
||||
device_list = g_list_append(device_list, GINT_TO_POINTER(strtoul(id, NULL, 10)));
|
||||
} else {
|
||||
log_error("[OMEMO] received device without ID");
|
||||
xmpp_stanza_t* device;
|
||||
for (device = xmpp_stanza_get_children(list); device != NULL; device = xmpp_stanza_get_next(device)) {
|
||||
if (g_strcmp0(xmpp_stanza_get_name(device), "device") != 0) {
|
||||
continue;
|
||||
}
|
||||
|
||||
const char* id = xmpp_stanza_get_id(device);
|
||||
if (id != NULL) {
|
||||
device_list = g_list_append(device_list, GINT_TO_POINTER(strtoul(id, NULL, 10)));
|
||||
} else {
|
||||
log_error("[OMEMO] received device without ID");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user