mirror of
https://github.com/acidanthera/audk.git
synced 2025-07-27 23:54:02 +02:00
BaseTools/C/Common: Refine using sprintf() with '%s' in format string
The commit removes the usages of sprintf() function calls with '%s' in the format string. And uses strncpy/strncat instead to ensure the destination string buffers will not be accessed beyond their boundary. Cc: Yonghong Zhu <yonghong.zhu@intel.com> Contributed-under: TianoCore Contribution Agreement 1.1 Signed-off-by: Hao Wu <hao.a.wu@intel.com> Reviewed-by: Liming Gao <liming.gao@intel.com>
This commit is contained in:
parent
938cf4b9bd
commit
3e1497334e
@ -462,10 +462,11 @@ Notes:
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
if (Cptr != NULL) {
|
if (Cptr != NULL) {
|
||||||
sprintf (Line, ": %s", Cptr);
|
strcpy (Line, ": ");
|
||||||
|
strncat (Line, Cptr, MAX_LINE_LEN - strlen (Line) - 1);
|
||||||
if (LineNumber != 0) {
|
if (LineNumber != 0) {
|
||||||
sprintf (Line2, "(%u)", (unsigned) LineNumber);
|
sprintf (Line2, "(%u)", (unsigned) LineNumber);
|
||||||
strcat (Line, Line2);
|
strncat (Line, Line2, MAX_LINE_LEN - strlen (Line) - 1);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
@ -476,14 +477,16 @@ Notes:
|
|||||||
if (mUtilityName[0] != '\0') {
|
if (mUtilityName[0] != '\0') {
|
||||||
fprintf (stdout, "%s...\n", mUtilityName);
|
fprintf (stdout, "%s...\n", mUtilityName);
|
||||||
}
|
}
|
||||||
sprintf (Line, "%s", Cptr);
|
strncpy (Line, Cptr, MAX_LINE_LEN - 1);
|
||||||
|
Line[MAX_LINE_LEN - 1] = 0;
|
||||||
if (LineNumber != 0) {
|
if (LineNumber != 0) {
|
||||||
sprintf (Line2, "(%u)", (unsigned) LineNumber);
|
sprintf (Line2, "(%u)", (unsigned) LineNumber);
|
||||||
strcat (Line, Line2);
|
strncat (Line, Line2, MAX_LINE_LEN - strlen (Line) - 1);
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
if (mUtilityName[0] != '\0') {
|
if (mUtilityName[0] != '\0') {
|
||||||
sprintf (Line, "%s", mUtilityName);
|
strncpy (Line, mUtilityName, MAX_LINE_LEN - 1);
|
||||||
|
Line[MAX_LINE_LEN - 1] = 0;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -501,12 +504,12 @@ Notes:
|
|||||||
// Have to print an error code or Visual Studio won't find the
|
// Have to print an error code or Visual Studio won't find the
|
||||||
// message for you. It has to be decimal digits too.
|
// message for you. It has to be decimal digits too.
|
||||||
//
|
//
|
||||||
|
strncat (Line, ": ", MAX_LINE_LEN - strlen (Line) - 1);
|
||||||
|
strncat (Line, Type, MAX_LINE_LEN - strlen (Line) - 1);
|
||||||
if (MessageCode != 0) {
|
if (MessageCode != 0) {
|
||||||
sprintf (Line2, ": %s %04u", Type, (unsigned) MessageCode);
|
sprintf (Line2, " %04u", (unsigned) MessageCode);
|
||||||
} else {
|
strncat (Line, Line2, MAX_LINE_LEN - strlen (Line) - 1);
|
||||||
sprintf (Line2, ": %s", Type);
|
|
||||||
}
|
}
|
||||||
strcat (Line, Line2);
|
|
||||||
fprintf (stdout, "%s", Line);
|
fprintf (stdout, "%s", Line);
|
||||||
//
|
//
|
||||||
// If offending text was provided, then print it
|
// If offending text was provided, then print it
|
||||||
|
Loading…
x
Reference in New Issue
Block a user