rt-thread icon indicating copy to clipboard operation
rt-thread copied to clipboard

[AT_SOCKET]fix compile warnings

Open dongly opened this issue 3 years ago • 4 comments

拉取/合并请求描述:(PR description)

[ 编译器: GCC 10.2.1 硬件: stm32l475-atk-pandora 编译出警告了

CC build\kernel\components\net\at\at_socket\at_socket.o
rt-thread\components\net\at\at_socket\at_socket.c: In function 'at_gethostbyname':
rt-thread\components\net\at\at_socket\at_socket.c:1423:9: warning: 'strncpy' specified bound depends on the length of the source argument [-Wstringop-overflow=]
 1423 |         strncpy(ipstr, name, strlen(name));
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
rt-thread\components\net\at\at_socket\at_socket.c:1412:25: note: length computed here
 1412 |     for (idx = 0; idx < strlen(name) && !isalpha(name[idx]); idx++);
      |                         ^~~~~~~~~~~~
rt-thread\components\net\at\at_socket\at_socket.c: In function 'at_getaddrinfo':
rt-thread\components\net\at\at_socket\at_socket.c:1531:17: warning: 'strncpy' specified bound depends on the length of the source argument [-Wstringop-overflow=]
 1531 |                 strncpy(ip_str, nodename, strlen(nodename));
      |                 ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
rt-thread\components\net\at\at_socket\at_socket.c:1520:33: note: length computed here
 1520 |             for (idx = 0; idx < strlen(nodename) && !isalpha(nodename[idx]); idx++);
      |  

可能出现内存溢出

]

以下的内容不应该在提交PR时的message修改,修改下述message,PR会被直接关闭。请在提交PR后,浏览器查看PR并对以下检查项逐项check,没问题后逐条在页面上打钩。 The following content must not be changed in the submitted PR message. Otherwise, the PR will be closed immediately. After submitted PR, please use a web browser to visit PR, and check items one by one, and ticked them if no problem.

当前拉取/合并请求的状态 Intent for your PR

必须选择一项 Choose one (Mandatory):

  • [ ] 本拉取/合并请求是一个草稿版本 This PR is for a code-review and is intended to get feedback
  • [x] 本拉取/合并请求是一个成熟版本 This PR is mature, and ready to be integrated into the repo

代码质量 Code Quality:

我在这个拉取/合并请求中已经考虑了 As part of this pull request, I've considered the following:

  • [x] 已经仔细查看过代码改动的对比 Already check the difference between PR and old code
  • [x] 代码风格正确,包括缩进空格,命名及其他风格 Style guide is adhered to, including spacing, naming and other styles
  • [x] 没有垃圾代码,代码尽量精简,不包含#if 0代码,不包含已经被注释了的代码 All redundant code is removed and cleaned up
  • [x] 所有变更均有原因及合理的,并且不会影响到其他软件组件代码或BSP All modifications are justified and not affect other components or BSP
  • [x] 对难懂代码均提供对应的注释 I've commented appropriately where code is tricky
  • [x] 本拉取/合并请求代码是高质量的 Code in this PR is of high quality
  • [x] 本拉取/合并使用formatting等源码格式化工具确保格式符合RT-Thread代码规范 This PR complies with RT-Thread code specification

dongly avatar Aug 12 '22 03:08 dongly

https://stackoverflow.com/questions/56782248/gcc-specified-bound-depends-on-the-length-of-the-source-argument

感觉这个警告有些不合理诶 非得让人去用sizeof

mysterywolf avatar Aug 12 '22 04:08 mysterywolf

但具体到本pr,确有可能溢出

dongly avatar Aug 12 '22 07:08 dongly

https://stackoverflow.com/questions/56782248/gcc-specified-bound-depends-on-the-length-of-the-source-argument

感觉这个警告有些不合理诶 非得让人去用sizeof

并不是 sizeof原因。strncpy,第三个参数是防止写入一次。上面用法 strlen是计算的第二个源字符串长度,这种用法违反了 strncpy的本质目的。让strncpy退化为strcpy,不如直接使用 strcpy了。 同样的问题在 sfud 代码里面一样存在 #6668。建议使用strcpy, 或者strncpy第三个参数 用来指示 目的字符串的最大长度,而不是源字符串的长度

yuqingli05 avatar Dec 05 '22 01:12 yuqingli05

https://stackoverflow.com/questions/56782248/gcc-specified-bound-depends-on-the-length-of-the-source-argument

感觉这个警告有些不合理诶 非得让人去用sizeof

我认为,应该规范 strncpy的使用方式。类似的代码片段应该改成 strcpy,或者 重新正确使用strncpy的第三个参数。

yuqingli05 avatar Dec 05 '22 01:12 yuqingli05