Resolve potential access beyond a metric buffer (from covscan report)#1907
Merged
natoscott merged 2 commits intohtop-dev:mainfrom Feb 19, 2026
Merged
Resolve potential access beyond a metric buffer (from covscan report)#1907natoscott merged 2 commits intohtop-dev:mainfrom
natoscott merged 2 commits intohtop-dev:mainfrom
Conversation
BenBE
reviewed
Feb 19, 2026
Comment on lines
396
to
397
| buffer[CLAMP(bytes, 0u, size - 1)] = '\0'; | ||
|
|
Member
There was a problem hiding this comment.
This is still needed, if the last thing is a delimiter and the subsequent metric evaluation failed.
Member
Author
There was a problem hiding this comment.
Spot on - will fix up, thanks!
The PCP library provides a string safe routine to guarantee string termination when sprintf-ing into a buffer. Switch to this as xSnprintf is designed to fail() rather than to tolerate, which is more desirable behaviour when dealing with user-supplied configuration files. In order to prevent accidental use of xSnprintf in these files in future, all snprintf-alike calls are switched to the libpcp interface here.
If there is no space remaining in the meter buffer for a suffix, just ignore it and continue on - it's better to be safe in this rare corner case than risk a crash.
975db66 to
a8e0ce7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.