mirror of
https://git.jabber.space/devs/cproof.git
synced 2026-07-25 03:16:20 +00:00
fix: CWE-134 format string audit and compiler hardening
Security: Fix CWE-134 in iq.c: user-controlled string passed as format argument Add G_GNUC_PRINTF annotations to all variadic printf-like wrappers in ui.h, log.h and http_common.h Compiler flags (configure.ac): Replace basic -Wformat/-Wformat-nonliteral with -Wformat=2 Add -Wextra, -Wnull-dereference, -Wpointer-arith, -Wimplicit-function-declaration, -Wundef, -Wfloat-equal, -Wredundant-decls, -Walloc-zero Add -fstack-protector-strong, -fno-common, -D_FORTIFY_SOURCE=2 Add GCC-specific flags via AC_COMPILE_IFELSE: -Wlogical-op, -Wduplicated-cond, -Wduplicated-branches, -Wstringop-overflow, -Warray-bounds=2 Suppress noisy -Wextra sub-warnings: -Wno-unused-parameter, -Wno-missing-field-initializers, -Wno-sign-compare, -Wno-cast-function-type Remove AM_CFLAGS/CFLAGS duplication Bug fixes found by new warnings: chatlog.c: non-MUCPM redact path passed resourcepart instead of NULL rosterwin.c: merge duplicated if/else branches into single condition omemo.c: redundant else-if in omemo_automatic_start; remove unnecessary scope block and goto, use early return console.c: pointer compared to integer 0 instead of NULL stanza.c: increase pri_str/idle_str buffers from 10 to 12 bytes (INT_MIN = -2147483648 needs 12 bytes including NUL) vcard.c: NULL guard for filename before g_file_set_contents api.c: broken log_warning() calls with extra format argument Format mismatch fixes: chatwin.c: Jid* → char* for %s connection.c: %x → %lx for long flags cmd_funcs.c: %d → %zu for size_t; cast gpointer to char* for %s cmd_defs.c: %d → %u for g_list_length() return (guint) iq.c: barejid → fulljid for from_jid console.c, mucwin.c, privwin.c, account.c, omemo.c, presence.c: gpointer → (char*) casts for %s Const-correctness and cleanup: database.c: const for type, query, sort variables form.c/xmpp.h: const for form_set_value parameter files.c: refactor to early return, eliminating NULL logfile path muc.c/muc.h: remove meaningless top-level const on return type common.c: const for URL string literal Remove stale declarations: cons_show_desktop_prefs (ui.h), connection_set_priority (connection.h), omemo_devicelist_configure_and_request (omemo.h) test_common.c: add currb NULL check to silence -Wnull-dereference Tooling (check-cwe134.sh): Reduce from 5 checks to 2 (checks 1-3 redundant with -Wformat=2) Check 1: verify known wrappers have G_GNUC_PRINTF attribute Check 2: auto-detect unannotated variadic printf-like functions Match both const char* and const gchar* in variadic patterns Author: jabber.developer2 <jabber.developer2@jabber.space>
This commit is contained in:
@@ -239,7 +239,7 @@ _conn_apply_settings(const char* const jid, const char* const passwd, const char
|
||||
}
|
||||
|
||||
if (xmpp_conn_set_flags(conn.xmpp_conn, flags)) {
|
||||
log_error("libstrophe doesn't accept this combination of flags: 0x%x", flags);
|
||||
log_error("libstrophe doesn't accept this combination of flags: 0x%lx", flags);
|
||||
conn.conn_status = JABBER_DISCONNECTED;
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
@@ -51,7 +51,6 @@ jabber_conn_status_t connection_register(const char* const altdomain, int port,
|
||||
void connection_set_disconnected(void);
|
||||
|
||||
void connection_set_priority(const int priority);
|
||||
void connection_set_priority(int priority);
|
||||
void connection_set_disco_items(GSList* items);
|
||||
|
||||
xmpp_conn_t* connection_get_conn(void);
|
||||
|
||||
@@ -458,7 +458,7 @@ form_get_field_type(DataForm* form, const char* const tag)
|
||||
}
|
||||
|
||||
void
|
||||
form_set_value(DataForm* form, const char* const tag, char* value)
|
||||
form_set_value(DataForm* form, const char* const tag, const char* value)
|
||||
{
|
||||
char* var = g_hash_table_lookup(form->tag_to_var, tag);
|
||||
if (var) {
|
||||
|
||||
@@ -921,7 +921,7 @@ _caps_response_id_handler(xmpp_stanza_t* const stanza, void* const userdata)
|
||||
// handle error responses
|
||||
if (g_strcmp0(type, STANZA_TYPE_ERROR) == 0) {
|
||||
auto_char char* error_message = stanza_get_error_message(stanza);
|
||||
log_warning("Error received for capabilities response from %s: ", from, error_message);
|
||||
log_warning("Error received for capabilities response from %s: %s", from, error_message);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -996,7 +996,7 @@ _caps_response_for_jid_id_handler(xmpp_stanza_t* const stanza, void* const userd
|
||||
// handle error responses
|
||||
if (g_strcmp0(type, STANZA_TYPE_ERROR) == 0) {
|
||||
auto_char char* error_message = stanza_get_error_message(stanza);
|
||||
log_warning("Error received for capabilities response from %s: ", from, error_message);
|
||||
log_warning("Error received for capabilities response from %s: %s", from, error_message);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -1054,7 +1054,7 @@ _caps_response_legacy_id_handler(xmpp_stanza_t* const stanza, void* const userda
|
||||
// handle error responses
|
||||
if (g_strcmp0(type, STANZA_TYPE_ERROR) == 0) {
|
||||
auto_char char* error_message = stanza_get_error_message(stanza);
|
||||
log_warning("Error received for capabilities response from %s: ", from, error_message);
|
||||
log_warning("Error received for capabilities response from %s: %s", from, error_message);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -1254,7 +1254,7 @@ _command_exec_response_handler(xmpp_stanza_t* const stanza, void* const userdata
|
||||
if (g_strcmp0(type, STANZA_TYPE_ERROR) == 0) {
|
||||
auto_char char* error_message = stanza_get_error_message(stanza);
|
||||
log_debug("Error executing command %s for %s: %s", command, from, error_message);
|
||||
win_command_exec_error(win, command, error_message);
|
||||
win_command_exec_error(win, command, "%s", error_message);
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
||||
@@ -427,7 +427,7 @@ muc_rooms(void)
|
||||
* Return current users nickname for the specified room
|
||||
* The nickname is owned by the chat room and should not be modified or freed
|
||||
*/
|
||||
const char* const
|
||||
const char*
|
||||
muc_nick(const char* const room)
|
||||
{
|
||||
ChatRoom* chat_room = g_hash_table_lookup(rooms, room);
|
||||
|
||||
@@ -93,7 +93,7 @@ GList* muc_rooms(void);
|
||||
|
||||
void muc_set_features(const char* const room, GSList* features);
|
||||
|
||||
const char* const muc_nick(const char* const room);
|
||||
const char* muc_nick(const char* const room);
|
||||
char* muc_password(const char* const room);
|
||||
|
||||
void muc_nick_change_start(const char* const room, const char* const new_nick);
|
||||
|
||||
@@ -353,6 +353,7 @@ omemo_receive_message(xmpp_stanza_t* const stanza, gboolean* trusted)
|
||||
{
|
||||
char* plaintext = NULL;
|
||||
const char* type = xmpp_stanza_get_type(stanza);
|
||||
const char* from = xmpp_stanza_get_from(stanza);
|
||||
GList* keys = NULL;
|
||||
unsigned char* iv_raw = NULL;
|
||||
unsigned char* payload_raw = NULL;
|
||||
@@ -434,8 +435,6 @@ omemo_receive_message(xmpp_stanza_t* const stanza, gboolean* trusted)
|
||||
keys = g_list_append(keys, key);
|
||||
}
|
||||
|
||||
const char* from = xmpp_stanza_get_from(stanza);
|
||||
|
||||
plaintext = omemo_on_message_recv(from, sid, iv_raw, iv_len,
|
||||
keys, payload_raw, payload_len,
|
||||
g_strcmp0(type, STANZA_TYPE_GROUPCHAT) == 0, trusted);
|
||||
@@ -471,7 +470,8 @@ _omemo_receive_devicelist(xmpp_stanza_t* const stanza, void* const userdata)
|
||||
|
||||
const char* code = xmpp_stanza_get_attribute(error, "code");
|
||||
if (g_strcmp0(code, "404") == 0) {
|
||||
goto out;
|
||||
omemo_set_device_list(from, NULL);
|
||||
return 1;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -517,7 +517,8 @@ _omemo_receive_devicelist(xmpp_stanza_t* const stanza, void* const userdata)
|
||||
log_warning("[OMEMO] User %s has a non 'current' device item list: %s.", from, xmpp_stanza_get_id(first));
|
||||
item = first;
|
||||
} else {
|
||||
goto out;
|
||||
omemo_set_device_list(from, device_list);
|
||||
return 1;
|
||||
}
|
||||
|
||||
xmpp_stanza_t* list = xmpp_stanza_get_child_by_ns(item, STANZA_NS_OMEMO);
|
||||
@@ -539,7 +540,6 @@ _omemo_receive_devicelist(xmpp_stanza_t* const stanza, void* const userdata)
|
||||
}
|
||||
}
|
||||
|
||||
out:
|
||||
omemo_set_device_list(from, device_list);
|
||||
|
||||
return 1;
|
||||
|
||||
@@ -38,7 +38,6 @@
|
||||
#include "xmpp/iq.h"
|
||||
|
||||
void omemo_devicelist_subscribe(void);
|
||||
void omemo_devicelist_configure_and_request(void);
|
||||
void omemo_devicelist_publish(GList* device_list);
|
||||
void omemo_devicelist_request(const char* const jid);
|
||||
void omemo_bundle_publish(gboolean first);
|
||||
|
||||
@@ -501,7 +501,7 @@ _subscribe_handler(xmpp_stanza_t* const stanza)
|
||||
{
|
||||
const char* from = xmpp_stanza_get_from(stanza);
|
||||
if (!from) {
|
||||
log_warning("Subscribe presence handler received with no from attribute", from);
|
||||
log_warning("Subscribe presence handler received with no from attribute");
|
||||
}
|
||||
log_debug("Subscribe presence handler fired for %s", from);
|
||||
|
||||
|
||||
@@ -1948,7 +1948,7 @@ stanza_attach_priority(xmpp_ctx_t* const ctx, xmpp_stanza_t* const presence, con
|
||||
return;
|
||||
}
|
||||
|
||||
char pri_str[10];
|
||||
char pri_str[12];
|
||||
snprintf(pri_str, sizeof(pri_str), "%d", pri);
|
||||
|
||||
xmpp_stanza_t* priority = xmpp_stanza_new(ctx);
|
||||
@@ -2007,7 +2007,7 @@ stanza_attach_last_activity(xmpp_ctx_t* const ctx,
|
||||
xmpp_stanza_t* query = xmpp_stanza_new(ctx);
|
||||
xmpp_stanza_set_name(query, STANZA_NAME_QUERY);
|
||||
xmpp_stanza_set_ns(query, STANZA_NS_LASTACTIVITY);
|
||||
char idle_str[10];
|
||||
char idle_str[12];
|
||||
snprintf(idle_str, sizeof(idle_str), "%d", idle);
|
||||
xmpp_stanza_set_attribute(query, STANZA_ATTR_SECONDS, idle_str);
|
||||
xmpp_stanza_add_child(presence, query);
|
||||
|
||||
@@ -1300,7 +1300,7 @@ _vcard_photo_result(xmpp_stanza_t* const stanza, void* userdata)
|
||||
return 1;
|
||||
}
|
||||
|
||||
GString* filename;
|
||||
GString* filename = NULL;
|
||||
|
||||
if (!data->filename) {
|
||||
auto_gchar gchar* path = files_get_data_path(DIR_PHOTOS);
|
||||
@@ -1340,6 +1340,11 @@ _vcard_photo_result(xmpp_stanza_t* const stanza, void* userdata)
|
||||
|
||||
GError* err = NULL;
|
||||
|
||||
if (!filename) {
|
||||
cons_show_error("Unable to determine filename for photo");
|
||||
return 1;
|
||||
}
|
||||
|
||||
if (g_file_set_contents(filename->str, (gchar*)photo->data, photo->length, &err) == FALSE) {
|
||||
cons_show_error("Unable to save photo: %s", err->message);
|
||||
g_error_free(err);
|
||||
|
||||
@@ -305,7 +305,7 @@ char* blocked_ac_find(const char* const search_str, gboolean previous, void* con
|
||||
void blocked_ac_reset(void);
|
||||
|
||||
void form_destroy(DataForm* form);
|
||||
void form_set_value(DataForm* form, const char* const tag, char* value);
|
||||
void form_set_value(DataForm* form, const char* const tag, const char* value);
|
||||
gboolean form_add_unique_value(DataForm* form, const char* const tag, char* value);
|
||||
void form_add_value(DataForm* form, const char* const tag, char* value);
|
||||
gboolean form_remove_value(DataForm* form, const char* const tag, char* value);
|
||||
|
||||
Reference in New Issue
Block a user