Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 25 additions & 0 deletions c_security_test.c
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 AI 代码审查发现问题

📋 问题概述

line 306 处将 ex_wundoex_rundo 声明为 static,但 line 8464 和 8474 处的函数定义缺少 static 关键字。C 语言标准规定,若函数先被声明为静态链接,后续定义也必须为静态,否则构成约束违规(constraint violation),将直接导致编译失败。

📍 问题详情

🟡 问题 1 | 严重程度: MEDIUM | 行号: 1-10

💬 详细说明:

  • line 1 处将 ex_wundoex_rundo 声明为 static,但 line 8464 和 8474 处的函数定义缺少 static 关键字。C 语言标准规定,若函数先被声明为静态链接,后续定义也必须为静态,否则构成约束违规(constraint violation),将直接导致编译失败。

📝 问题代码:

void

💡 修复建议:

在 line 1 和 1 的函数定义前添加 static 关键字,使其与 line 306-307 的声明保持一致。这符合 Vim 中命令处理函数通常为内部静态函数的惯例。

✅ 修复示例:

    #ifdef FEAT_PERSISTENT_UNDO
    static void
ex_wundo(eap)
    exarg_T *eap;
{
    char_u hash[UNDO_HASH_SIZE];

    u_compute_hash(hash);
    u_write_undo(eap->arg, eap->forceit, curbuf, hash);
}

🔗 参考链接

#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <limits.h>

#define MAX_BUFFER 10

void buffer_overflow_vuln(char* user_input) {
char buffer[MAX_BUFFER];
strcpy(buffer, user_input);
}
Comment on lines +9 to +12

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify that this file is isolated from production targets and uses sanitizer-based execution.
rg -n -C 3 'c_security_test\.c|buffer_overflow_vuln|integer_overflow_vuln|fsanitize|add_executable|target_sources' .

Repository: joyfaker/fock_c_json

Length of output: 27213


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf 'Tracked files:\n'
git ls-files | rg '(^|/)c_security_test\.c$|(^|/)CMakeLists\.txt$|(^|/)src/modules/CMakeLists\.txt$|(^|/)cmake/test\.cmake$' || true

printf '\nsrc/modules/c_security_test.c:\n'
cat -n src/modules/c_security_test.c

printf '\nTop-level CMakeLists relevant sections:\n'
sed -n '1,240p' CMakeLists.txt

printf '\ncmake/test.cmake relevant sections:\n'
sed -n '1,180p' cmake/test.cmake

printf '\nCMake references containing c_security_test:\n'
rg -n --hidden -C 3 'c_security_test|security_test|EXCLUDE_FROM_ALL|add_test' .

Repository: joyfaker/fock_c_json

Length of output: 31845


Isolate strcpy from normal test execution.

buffer has 10 bytes, but strcpy(buffer, user_input) copies all of argv[1]; a 10-byte or longer argument overwrites beyond buffer. If this fixture is intentional, keep it in a dedicated isolated EXCLUDE_FROM_ALL target and run it only with controlled short inputs. Otherwise, use a bounded-copy function and reject oversized input before copying.

🧰 Tools
🪛 ast-grep (0.45.0)

[error] 10-10: Use of an unbounded buffer function that can overflow the destination; use a size-bounded equivalent (fgets, strncpy/strlcpy, strncat/strlcat, snprintf).
Context: strcpy(buffer, user_input)
Note: [CWE-120] Buffer Copy without Checking Size of Input ('Classic Buffer Overflow').

(dangerous-buffer-functions-c)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@c_security_test.c` around lines 9 - 12, Update buffer_overflow_vuln so the
intentional strcpy vulnerability is excluded from normal test execution via a
dedicated EXCLUDE_FROM_ALL target and only exercised with controlled short
inputs; otherwise replace strcpy with bounded copying and reject inputs that do
not fit within buffer before copying.

Source: Linters/SAST tools



int integer_overflow_vuln(int count, int size) {
int total_bytes = count * size;
return total_bytes;
}


int main(int argc, char* argv[]) {
buffer_overflow_vuln(argv[1]);
int result = integer_overflow_vuln(INT_MAX, 2);
return 0;
}