Use dynamic instead of fixed buffers #199
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
By submitting this pull request, I confirm the following (please check boxes, eg [X]) Failure to fill the template will close your PR:
Please submit all pull requests against the
development
branch. Failure to do so will delay or deny your requestHow familiar are you with the codebase?:
10
This is a security fix, cherry-picking
19c54b0
from branchnew/API
. Originally I thought this could go todevelopment
much earlier, but now thenew/API
branch is still in progress.Short summary of what this PR achieves: We currently use fixed buffers of length 1024 in the
request.c
results. It may happen that unexceptionally long result lines /which are not expected to happen, but may appear when e.g. the DNS resolver is malfunctioning (there are always many ways things can go wrong). So, theoretically, the present code can corrupt the stack frame and trigger the Stack Smashing Protector (SSP) I added toFTL
several months ago.This PR changes the behavior drastically in removing all fixed buffers and using only dynamic buffers everywhere.
This may fix #198 but further details are still needed there.
This template was created based on the work of
udemy-dl
.