Fix #2738, use bounded string comparisons - #2791
Open
sylvesterkaczmarek wants to merge 1 commit into
Open
Conversation
sylvesterkaczmarek
marked this pull request as ready for review
August 16, 2026 09:36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Checklist (Please check before submitting)
Describe the contribution
Fix #2738.
Replace the remaining unbounded
strcmp()uses undermodules/with bounded comparisons while preserving exact-match behavior.The change uses bounds derived from the relevant fixed-size field, API-name limit, string literal, or generated configuration-name entry. The configuration name table now records each generated name size so
CFE_Config_GetIdByName()can distinguish an exact name from a longer string sharing the same prefix.Regression coverage includes a prefix-plus-suffix configuration name to verify that bounded comparison does not introduce prefix matching.
Testing performed
startup_failurebefore any CodeQL job executed.action_requiredwith no jobs created. No upstream CI success is being claimed yet.Expected behavior changes
CFE_Config_IdNameEntry_trecords the generated configuration-name size.System(s) tested on
dev.Additional context
On the current
devbaseline, this patch addresses the remaining unboundedstrcmp()uses undermodules/covered by #2738.Third party code
None.
Contributor Info - All information REQUIRED for consideration of pull request
Sylvester Kaczmarek, Personal