prefer memcpy to strcpy
When we already know the length of a string (e.g., because we just malloc'd to fit it), it's nicer to use memcpy than strcpy, as it makes it more obvious that we are not going to overflow the buffer (because the size we pass matches the size in the allocation). This also eliminates calls to strcpy, which make auditing the code base harder. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Jeff King committed
Sep 24, 2015 at 17:08 UTC
34fa79a6cde56d6d428ab0d3160cb094ebad3305
3 files changed
+7
-5
compat/nedmalloc/nedmalloc.c
+3
-2
@@ -957,8 +957,9 @@ char *strdup(const char *s1)
957
{
958
char *s2 = 0;
959
if (s1) {
960
- s2 = malloc(strlen(s1) + 1);
961
- strcpy(s2, s1);
960
+ size_t len = strlen(s1) + 1;
961
+ s2 = malloc(len);
962
+ memcpy(s2, s1, len);
963
}
964
return s2;
965
}
fast-import.c
+3
-2
@@ -644,8 +644,9 @@ static void *pool_calloc(size_t count, size_t size)
644
645
static char *pool_strdup(const char *s)
646
{
647
- char *r = pool_alloc(strlen(s) + 1);
648
- strcpy(r, s);
647
+ size_t len = strlen(s) + 1;
648
+ char *r = pool_alloc(len);
649
+ memcpy(r, s, len);
650
return r;
651
}
652
revision.c
+1
-1
@@ -38,7 +38,7 @@ char *path_name(const struct name_path *path, const char *name)
38
}
39
n = xmalloc(len);
40
m = n + len - (nlen + 1);
41
- strcpy(m, name);
41
+ memcpy(m, name, nlen + 1);
42
for (p = path; p; p = p->up) {
43
if (p->elem_len) {
44
m -= p->elem_len + 1;