Suppress Coverity Scan false positives

** CID 646509:       Insecure data handling  (INTEGER_OVERFLOW)
/src/tlslib.c: 156           in cstp_send_file()

** CID 646510:       Insecure data handling  (INTEGER_OVERFLOW)
/src/auth/pam-stack.h: 73           in pam_stack_alloc()

Make sure the suppression annotation:
* appears at the beginning of a C or C++ comment,
* is placed immediately before the line of code where the defect occurs.

Signed-off-by: Dimitri Papadopoulos <3350651-DimitriPapadopoulos@users.noreply.gitlab.com>
This commit is contained in:
Dimitri Papadopoulos
2026-06-24 11:24:14 +02:00
parent f3f74de305
commit 5953319ef4
4 changed files with 10 additions and 4 deletions
+3
View File
@@ -70,6 +70,9 @@ static inline void *pam_stack_alloc(struct pam_stack_st *st, size_t size)
return NULL;
/* Guard page below the stack: overflow → SIGSEGV, not silent heap corruption. */
if (mprotect(map, (size_t)pgsz, PROT_NONE) != 0) {
/* No way `size` can be even close to SIZE_MAX (4 GB on 32-bit systems
* and 16 EB on 64-bit systems) */
// coverity[overflow_sink : FALSE]
munmap(map, total);
return NULL;
}
+2 -3
View File
@@ -61,9 +61,8 @@ static rlim_t compute_worker_data_limit(unsigned headroom_kb)
if (pagesize < 0)
return 0;
/* A process where data * pagesize overflows unsigned long (64-bit)
* would use more than 16 million TB of data pages!
*
* coverity[INTEGER_OVERFLOW] */
* would use more than 16 million TB of data pages! */
// coverity[return_overflow : FALSE]
return (rlim_t)data * (rlim_t)pagesize + (rlim_t)headroom_kb * 1024;
}
+4 -1
View File
@@ -153,6 +153,9 @@ ssize_t cstp_send_file(worker_st *ws, const char *file)
close(fd);
/* No way we can read SSIZE_MAX (2 GB on 32-bit systems and 8 EB
* on 64-bit systems) from a profile */
// coverity[return_overflow : FALSE]
return total;
}
@@ -237,7 +240,7 @@ ssize_t cstp_recv_packet(worker_st *ws, gnutls_datum_t *data, void **p)
gnutls_packet_get(packet, data, NULL);
}
} else {
ret = _cstp_recv_packet(ws, ws->buffer, ws->buffer_size);
ret = (int)_cstp_recv_packet(ws, ws->buffer, ws->buffer_size);
data->data = ws->buffer;
data->size = ret;
}
+1
View File
@@ -223,6 +223,7 @@ int complete_vpn_info(worker_st *ws, struct vpn_st *vinfo)
return 0;
}
// coverity[leaked_storage : FALSE]
void ocsigaltstack(struct worker_st *ws)
{
#if defined(HAVE_SIGALTSTACK) && defined(HAVE_POSIX_MEMALIGN)