fix: CWE-134 format string audit and compiler hardening

Security:
Fix CWE-134 in iq.c: user-controlled string passed as format argument
Add G_GNUC_PRINTF annotations to all variadic printf-like wrappers
in ui.h, log.h and http_common.h
Compiler flags (configure.ac):

Replace basic -Wformat/-Wformat-nonliteral with -Wformat=2
Add -Wextra, -Wnull-dereference, -Wpointer-arith,
-Wimplicit-function-declaration, -Wundef, -Wfloat-equal,
-Wredundant-decls, -Walloc-zero
Add -fstack-protector-strong, -fno-common, -D_FORTIFY_SOURCE=2
Add GCC-specific flags via AC_COMPILE_IFELSE: -Wlogical-op,
-Wduplicated-cond, -Wduplicated-branches, -Wstringop-overflow,
-Warray-bounds=2
Suppress noisy -Wextra sub-warnings: -Wno-unused-parameter,
-Wno-missing-field-initializers, -Wno-sign-compare,
-Wno-cast-function-type
Remove AM_CFLAGS/CFLAGS duplication
Bug fixes found by new warnings:

chatlog.c: non-MUCPM redact path passed resourcepart instead of NULL
rosterwin.c: merge duplicated if/else branches into single condition
omemo.c: redundant else-if in omemo_automatic_start; remove
unnecessary scope block and goto, use early return
console.c: pointer compared to integer 0 instead of NULL
stanza.c: increase pri_str/idle_str buffers from 10 to 12 bytes
(INT_MIN = -2147483648 needs 12 bytes including NUL)
vcard.c: NULL guard for filename before g_file_set_contents
api.c: broken log_warning() calls with extra format argument
Format mismatch fixes:

chatwin.c: Jid* → char* for %s
connection.c: %x → %lx for long flags
cmd_funcs.c: %d → %zu for size_t; cast gpointer to char* for %s
cmd_defs.c: %d → %u for g_list_length() return (guint)
iq.c: barejid → fulljid for from_jid
console.c, mucwin.c, privwin.c, account.c, omemo.c, presence.c:
gpointer → (char*) casts for %s
Const-correctness and cleanup:

database.c: const for type, query, sort variables
form.c/xmpp.h: const for form_set_value parameter
files.c: refactor to early return, eliminating NULL logfile path
muc.c/muc.h: remove meaningless top-level const on return type
common.c: const for URL string literal
Remove stale declarations: cons_show_desktop_prefs (ui.h),
connection_set_priority (connection.h),
omemo_devicelist_configure_and_request (omemo.h)
test_common.c: add currb NULL check to silence -Wnull-dereference
Tooling (check-cwe134.sh):

Reduce from 5 checks to 2 (checks 1-3 redundant with -Wformat=2)
Check 1: verify known wrappers have G_GNUC_PRINTF attribute
Check 2: auto-detect unannotated variadic printf-like functions
Match both const char* and const gchar* in variadic patterns

Author: jabber.developer2 <jabber.developer2@jabber.space>
This commit is contained in:
2026-03-07 11:55:50 +01:00
parent 1508f27e73
commit 9ec01fa8cc
32 changed files with 255 additions and 169 deletions

View File

@@ -244,7 +244,9 @@ char* inp_readline(void);
void inp_nonblocking(gboolean reset);
// Console window
G_GNUC_PRINTF(1, 2)
void cons_show(const char* const msg, ...);
G_GNUC_PRINTF(2, 3)
void cons_show_padded(int pad, const char* const msg, ...);
void cons_about(void);
void cons_help(void);
@@ -263,7 +265,9 @@ void cons_show_pgp_prefs(void);
void cons_show_omemo_prefs(void);
void cons_show_ox_prefs(void);
void cons_show_account(ProfAccount* account);
G_GNUC_PRINTF(1, 2)
void cons_debug(const char* const msg, ...);
G_GNUC_PRINTF(1, 2)
void cons_show_error(const char* const cmd, ...);
void cons_show_contacts(GSList* list);
void cons_show_roster(GSList* list);
@@ -318,7 +322,6 @@ void cons_wrap_setting(void);
void cons_time_setting(void);
void cons_wintitle_setting(void);
void cons_notify_setting(void);
void cons_show_desktop_prefs(void);
void cons_states_setting(void);
void cons_outtype_setting(void);
void cons_intype_setting(void);
@@ -393,16 +396,24 @@ void win_show_subwin(ProfWin* window);
void win_refresh_without_subwin(ProfWin* window);
void win_refresh_with_subwin(ProfWin* window);
G_GNUC_PRINTF(4, 5)
void win_print(ProfWin* window, theme_item_t theme_item, const char* show_char, const char* const message, ...);
G_GNUC_PRINTF(4, 5)
void win_println(ProfWin* window, theme_item_t theme_item, const char* show_char, const char* const message, ...);
G_GNUC_PRINTF(3, 4)
void win_println_indent(ProfWin* window, int pad, const char* const message, ...);
G_GNUC_PRINTF(4, 0)
void win_println_va(ProfWin* window, theme_item_t theme_item, const char* show_char, const char* const message, va_list arg);
G_GNUC_PRINTF(3, 4)
void win_append(ProfWin* window, theme_item_t theme_item, const char* const message, ...);
G_GNUC_PRINTF(3, 4)
void win_appendln(ProfWin* window, theme_item_t theme_item, const char* const message, ...);
G_GNUC_PRINTF(3, 4)
void win_append_highlight(ProfWin* window, theme_item_t theme_item, const char* const message, ...);
G_GNUC_PRINTF(3, 4)
void win_appendln_highlight(ProfWin* window, theme_item_t theme_item, const char* const message, ...);
gchar* win_get_title(ProfWin* window);
@@ -416,6 +427,7 @@ void win_clear(ProfWin* window);
char* win_get_tab_identifier(ProfWin* window);
gchar* win_to_string(ProfWin* window);
void win_command_list_error(ProfWin* window, const char* const error);
G_GNUC_PRINTF(3, 4)
void win_command_exec_error(ProfWin* window, const char* const command, const char* const error, ...);
void win_handle_command_list(ProfWin* window, GSList* cmds);
void win_handle_command_exec_status(ProfWin* window, const char* const type, const char* const value);