3 ms·
Author here. I did aim to write the code carefully, for instance doing bounded reads like `fgets(cmd, CLIENT_BUFSZ, conn)` to prevent overflowing my buffer. Als
by begriffs 8y ago
Author here. I did aim to write the code carefully, for instance doing bounded reads like `fgets(cmd, CLIENT_BUFSZ, conn)` to prevent overflowing my buffer. Also ran the program in Valgrind and exercised different code paths to detect memory leaks and management errors such as use-after-free or double-freeing. Because libgit2 and its memory conventions were new to me, I did actually make mistakes and Valgrind helped me find them. The fix for those mistakes is in commit 59bb39b if you're curious to check it out.
Writing in C requires care, but the modern day "rewrite it in rust" crusade does feel overblown. C programs are nice -- small and fast.
Anyway, I don't mean to be cocky. A code review is welcome, I'd be curious if I did indeed overlook a security issue.