Skip to content

Commit a80b7eb

Browse files
mcc0612mcc0612chencheng maoclaude
authored
Fix crash with NUL character in path given to --file-list (#8902)
**Description** If a path in the --file-list file contains a NUL character, cppcheck keeps opening the same folder over and over until it crashes **Crash Replication** ```shell mkdir -p d/s; printf 'd\0\n' > list.txt && /path/to/cppcheck --file-list=list.txt ``` seg fault is expected **Proposed Patch** If a path in --file-list file contains NUL character, reject it. --------- Co-authored-by: chencheng mao <u1520758@utah.edu> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
1 parent 1349826 commit a80b7eb

2 files changed

Lines changed: 16 additions & 0 deletions

File tree

‎cli/filelister.cpp‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -168,6 +168,10 @@ std::string FileLister::addFiles(std::list<FileWithDetails> &files, const std::s
168168
if (path.empty())
169169
return "no path specified";
170170

171+
const std::string::size_type nulPos = path.find('\0');
172+
if (nulPos != std::string::npos)
173+
return "path '" + path.substr(0, nulPos) + "' contains a NUL character";
174+
171175
std::list<FileWithDetails> filesSorted;
172176

173177
std::string err = addFiles2(filesSorted, path, extra, recursive, ignored, debug);
@@ -285,6 +289,10 @@ std::string FileLister::addFiles(std::list<FileWithDetails> &files, const std::s
285289
if (path.empty())
286290
return "no path specified";
287291

292+
const std::string::size_type nulPos = path.find('\0');
293+
if (nulPos != std::string::npos)
294+
return "path '" + path.substr(0, nulPos) + "' contains a NUL character";
295+
288296
std::string corrected_path = path;
289297
if (endsWith(corrected_path, '/'))
290298
corrected_path.erase(corrected_path.end() - 1);

‎test/testfilelister.cpp‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,7 @@ class TestFileLister : public TestFixture {
3636
void run() override {
3737
TEST_CASE(recursiveAddFiles);
3838
TEST_CASE(recursiveAddFilesEmptyPath);
39+
TEST_CASE(recursiveAddFilesNulInPath);
3940
TEST_CASE(excludeFile1);
4041
TEST_CASE(excludeFile2);
4142
TEST_CASE(excludeDir);
@@ -110,6 +111,13 @@ class TestFileLister : public TestFixture {
110111
ASSERT_EQUALS("no path specified", err);
111112
}
112113

114+
void recursiveAddFilesNulInPath() const {
115+
std::list<FileWithDetails> files;
116+
const std::string err = FileLister::recursiveAddFiles(files, std::string("lib\0", 4), {}, PathMatch());
117+
ASSERT_EQUALS("path 'lib' contains a NUL character", err);
118+
ASSERT(files.empty());
119+
}
120+
113121
void excludeFile1() const {
114122
const std::string basedir = findBaseDir();
115123

0 commit comments

Comments
 (0)