Skip to content

refactor(security): harden legacy C string functions and buffer bounds - #52

Merged
mcoliver merged 1 commit into
mainfrom
security/harden-legacy-c-strings
Sep 27, 2026
Merged

mcoliver merged 1 commit into
mainfrom
security/harden-legacy-c-strings

Conversation

@mcoliver

Copy link
Copy Markdown
Collaborator

Description

Audit and refactor unsafe legacy C string functions (sprintf, vsprintf, strcpy) and buffer boundaries across first-party core code in OpenUTV.

Summary of Hardening:

  1. Unbounded Formatted Printing (sprintf / vsprintf):

    • Converted all active occurrences in src/lib/ and src/bin/ to snprintf / vsnprintf with explicit buffer bounds:
      • src/lib/image/MovieFFMpeg/MovieFFMpeg.cpp: rotation string formatting and audio metadata attributes.
      • src/lib/image/IOdpx/IOdpx.cpp: timecode calculation and header descriptor attributes.
      • src/lib/image/IOpng/IOpng.cpp, IOjpeg/IOjpeg.cpp, IOtiff/IOtiff.cpp, IOz/IOz.cpp, IOmray/IOmray.cpp, TwkImg/TwkImgSgiIff.cpp.
      • src/lib/app/RvApp/RvSession.cpp, RvGraph.cpp, src/lib/ip/IPCore/IPGraph.cpp, Session.cpp, SourceGroupIPNode.cpp: unique node naming logic (eliminated thread-unsafe static buffers and unconstrained sprintf).
      • src/lib/base/TwkUtil/Notifier.cpp: object address formatting.
      • src/lib/files/Gto/Parser.y, Writer.cpp: reader/writer formatted error/warning reporting with vsnprintf and missing va_end cleanup.
      • src/lib/mu/Mu/ & MuLang/: compiler & assembler error reporting (NodeAssembler.cpp, Grammar.y), parameter naming (FunctionSpecializer.cpp, TupleType.cpp, PartialApplicator.cpp, FixedArrayType.cpp, DynamicArrayType.cpp, MuLangContext.cpp), and primitive string serialization (StringType.cpp).
  2. Unchecked String Copying (strcpy):

    • PanavisionLUT.cpp: Removed stack buffer and strcpy entirely when parsing entries header.
    • RvApplication.cpp:
      • Replaced dynamic char[] buffer and strcpy in baked URL decoding with safe std::string accumulation.
      • Protected hex URL encoding by casting to unsigned char (preventing negative-char expansion buffer overflow) and using snprintf.
      • Replaced vector<char> with QString::asprintf for the About dialog.
    • StringType.cpp: Replaced strcpy with memcpy in StringType::String::set and setn bounded by size (preventing out-of-bounds reads and overflows on non-null-terminated buffers).
    • MovieSideCar/Common.cpp: Replaced strcpy with strncpy bounded by Message::SizeInBytes().
    • TwkImgCineonIff.cpp: Replaced strcpy with strncpy bounded by header field sizes.
    • main.cpp across CLI executables (rv, utv, rvpkg, rvio): Replaced in-place strcpy(argv[i], "-help") with direct pointer reassignment.
    • Lexer.l & Grammar.y: Bounded operator token copying into _op[4] with strncpy.

Closes #51

Audit and refactor unsafe string and buffer handling in core application code:
- Replace unbounded `sprintf` and `vsprintf` with `snprintf` and `vsnprintf`
- Replace `strcpy` with `strncpy` or safe `memcpy` with explicit bounds
- In `RvApplication`: use `QString::asprintf` for about dialog, use `std::string` and `unsigned char` casts for URL decoding and hex encoding
- In `StringType::String::set` and `setn`: replace unconstrained `strcpy` with bounded `memcpy`
- In `PanavisionLUT.cpp`: remove fixed 64-byte stack buffer and parse integers directly from string offset
- In `MovieFFMpeg`: widen `charRotation` buffer and use `snprintf`
- In command-line entry points: avoid modifying `argv` via in-place `strcpy`
- In GTO and Mu parsers/lexers: guard error and warning format strings with bounds checking

Refs: #51
Signed-off-by: Michael Oliver <mcoliver@gmail.com>
@mcoliver
mcoliver merged commit 4510edf into main Sep 27, 2026
9 checks passed
@mcoliver
mcoliver deleted the security/harden-legacy-c-strings branch September 27, 2026 00:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: Audit and harden legacy C string functions (sprintf, strcpy) and potential buffer overflows

1 participant