fix: Bounds-check read_from_file restores with snprintf - #64
VedantMadane wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Hi and welcome!
In secret_verification() and data_integrity_check(), snprintf and sizeof will work just fine.
However, in read_from_file(), sizeof will not work as you expect because here 'output' is a pointer to the char array, not the array itself. Calling sizeof(output) will return the size of the pointer which on a 32-bit system is just 4 bytes, causing snprintf to always copy at most 3 characters + a nul-terminator.
Instead, you've got to calculate the size to copy first and then pass it into read_from_file() e.g. like this:
read_from_file(const char* file_name, char* output, size_t output_size)
06ce7a2 to
4c1b446
Compare
|
Thank you for the review and explanation! I have updated |
4c1b446 to
01cfa96
Compare
read_from_file now takes an explicit size_t output_size so snprintf does not use sizeof(pointer). Call sites pass sizeof(rtc_g.Secret) and sizeof(rtc_g.chat_id) via restore_data_value. Fixes RomanAlexandroff#34 Signed-off-by: Vedant Madane <6527493+VedantMadane@users.noreply.github.com>
645d41c to
55b4d15
Compare
|
Ready for re-review. Maintainer feedback addressed
Cleanup
Please take another look when convenient. Thank you! |
|
Hi @RomanAlexandroff — gentle re-review bump.
|
|
Hi @RomanAlexandroff — gentle re-review bump when you have a moment. Thanks! |
|
Verified: |
Summary
Bounds-check read_from_file restores with snprintf
Changes
Fixes #34