• New Defects reported by Coverity Scan for Synchronet

    From scan-admin@coverity.com@VERT to cov-scan@synchro.net on Monday, August 10, 2026 13:31:15
    Hi,

    Please find the latest report on new defect(s) introduced to Synchronet found with Coverity Scan.

    1 new defect(s) introduced to Synchronet found with Coverity Scan.
    1 defect(s), reported by Coverity Scan earlier, were marked fixed in the recent build analyzed by Coverity Scan.

    New defect(s) Reported-by: Coverity Scan
    Showing 1 of 1 defect(s)


    ** CID 652885: Integer handling issues (INTEGER_OVERFLOW)
    /useredit.cpp: 167 in sbbs_t::useredit(int)()


    _____________________________________________________________________________________________
    *** CID 652885: Integer handling issues (INTEGER_OVERFLOW) /useredit.cpp: 167 in sbbs_t::useredit(int)()
    161 bprintf(text[UeditPrompt], user.number, l);
    162 SAFEPRINTF4(str, "QG[]?/{}()%c%c%c%c", TERM_KEY_LEFT, TERM_KEY_RIGHT, TERM_KEY_HOME, TERM_KEY_END);
    163 if (user.level <= useron.level)
    164 SAFECAT(str, "ABCDEFHIJKLMNOPRSTUVWXYZ+~*$#"); 165 l = getkeys(str, l, K_UPPER | K_NOCRLF);
    166 if (l & 0x80000000L) {
    CID 652885: Integer handling issues (INTEGER_OVERFLOW)
    Expression "user.number", where "l & 0xffffffff7fffffffL" is known to be equal to -2147483649, overflows the type of "user.number", which is type "int".
    167 user.number = l & ~0x80000000L;
    168 continue;
    169 }
    170 if (IS_ALPHA(l) || strchr("~+*$/", l) != NULL) // non-alpha commands that prompt
    171 term->newline();
    172 switch (l) {


    ________________________________________________________________________________________________________
    To view the defects in Coverity Scan visit, https://scan.coverity.com/projects/synchronet?tab=overview



    ---
    * Synchronet * Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net
  • From scan-admin@coverity.com@VERT to All on Thursday, August 20, 2026 12:49:16
    Hi,

    Please find the latest report on new defect(s) introduced to Synchronet found with Coverity Scan.

    1 new defect(s) introduced to Synchronet found with Coverity Scan.
    2 defect(s), reported by Coverity Scan earlier, were marked fixed in the recent build analyzed by Coverity Scan.

    New defect(s) Reported-by: Coverity Scan
    Showing 1 of 1 defect(s)


    ** CID 653403: Insecure data handling (INTEGER_OVERFLOW)
    /userdat.c: 214 in total_users()


    _____________________________________________________________________________________________
    *** CID 653403: Insecure data handling (INTEGER_OVERFLOW)
    /userdat.c: 214 in total_users()
    208 lock is a synchronous round-trip that dominates the cost of this scan
    209 when the data directory is network-mounted, and no amount of locking
    210 makes the result more current than the snapshot it already is. */
    211 do {
    212 got = 0;
    213 while (got < bufsize) {
    CID 653403: Insecure data handling (INTEGER_OVERFLOW)
    "64000UL - got", which might have underflowed, is passed to "read(file, buf + got, 64000UL - got)".
    214 ssize_t rd = read(file, buf + got, bufsize - got);
    215 if (rd <= 0)
    216 break;
    217 got += (size_t)rd;
    218 }
    219 for (size_t offset = 0; offset + USER_RECORD_LINE_LEN <= got; offset += USER_RECORD_LINE_LEN) {


    ________________________________________________________________________________________________________
    To view the defects in Coverity Scan visit, https://scan.coverity.com/projects/synchronet?tab=overview



    ---
    * Synchronet * Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net
  • From scan-admin@coverity.com@VERT to All on Sunday, August 30, 2026 12:51:09
    Hi,

    Please find the latest report on new defect(s) introduced to Synchronet found with Coverity Scan.

    3 new defect(s) introduced to Synchronet found with Coverity Scan.
    1 defect(s), reported by Coverity Scan earlier, were marked fixed in the recent build analyzed by Coverity Scan.

    New defect(s) Reported-by: Coverity Scan
    Showing 3 of 3 defect(s)


    ** CID 654570: (CHECKED_RETURN)
    /xtrn_sec.cpp: 1223 in sbbs_t::xtrndat(const char *, const char *, unsigned char, unsigned int, unsigned int)()
    /xtrn_sec.cpp: 1213 in sbbs_t::xtrndat(const char *, const char *, unsigned char, unsigned int, unsigned int)()


    _____________________________________________________________________________________________
    *** CID 654570: (CHECKED_RETURN)
    /xtrn_sec.cpp: 1223 in sbbs_t::xtrndat(const char *, const char *, unsigned char, unsigned int, unsigned int)()
    1217 int chmod_result = CHMOD(str, _S_IREAD);
    1218 #else
    1219 int chmod_result = CHMOD(str, S_IRUSR);
    1220 #endif
    1221 if (chmod_result != 0) {
    1222 errormsg(WHERE, ERR_WRITE, str, errno);
    CID 654570: (CHECKED_RETURN)
    Calling "remove(str)" without checking return value. This library function may fail and return an error code.
    1223 remove(str);
    1224 return false;
    1225 }
    1226 }
    1227
    1228 else if (type)
    /xtrn_sec.cpp: 1213 in sbbs_t::xtrndat(const char *, const char *, unsigned char, unsigned int, unsigned int)()
    1207 }
    1208 bool write_ok = bbsdev_write(fp, lines, sizeof(lines) / sizeof(lines[0]));
    1209 if (fclose(fp) != 0)
    1210 write_ok = false;
    1211 if (!write_ok) {
    1212 errormsg(WHERE, ERR_WRITE, str, 0);
    CID 654570: (CHECKED_RETURN)
    Calling "remove(str)" without checking return value. This library function may fail and return an error code.
    1213 remove(str);
    1214 return false;
    1215 }
    1216 #if defined(_WIN32)
    1217 int chmod_result = CHMOD(str, _S_IREAD);
    1218 #else

    ** CID 654569: Memory - illegal accesses (OVERRUN)
    /xtrn_sec.cpp: 101 in bbsdev_language_tag_valid(const char *)()


    _____________________________________________________________________________________________
    *** CID 654569: Memory - illegal accesses (OVERRUN)
    /xtrn_sec.cpp: 101 in bbsdev_language_tag_valid(const char *)()
    95 || (lengths[at] == 4 && isdigit((unsigned char)parts[at][0])
    96 && bbsdev_subtag_chars(parts[at] + 1, 3, isalnum))))
    97 at++;
    98 while (at < count && lengths[at] == 1
    99 && tolower((unsigned char)parts[at][0]) != 'x') {
    100 at++;
    CID 654569: Memory - illegal accesses (OVERRUN)
    Overrunning array "lengths" of 32 8-byte elements at element index 32 (byte offset 263) using index "at" (which evaluates to 32).
    101 if (at == count || lengths[at] < 2)
    102 return false;
    103 while (at < count && lengths[at] >= 2)
    104 at++;
    105 }
    106 if (at < count && lengths[at] == 1 && tolower((unsigned char)parts[at][0]) == 'x')

    ** CID 654568: (RESOURCE_LEAK)
    /xtrn.cpp: 1925 in sbbs_t::external(const char *, int, const char *, const char *)()
    /xtrn.cpp: 1925 in sbbs_t::external(const char *, int, const char *, const char *)()


    _____________________________________________________________________________________________
    *** CID 654568: (RESOURCE_LEAK)
    /xtrn.cpp: 1925 in sbbs_t::external(const char *, int, const char *, const char *)()
    1919 dup2(fd, STDOUT_FILENO);
    1920 if (!(mode & EX_NOLOG))
    1921 dup2(fd, STDERR_FILENO);
    1922 if (fd > 2)
    1923 close(fd);
    1924 }
    CID 654568: (RESOURCE_LEAK)
    Handle variable "fd" going out of scope leaks the handle.
    1925 }
    1926
    1927 if (mode & EX_BG) /* background execution, detach child */
    1928 {
    1929 if (daemon(TRUE, FALSE) != 0)
    1930 lprintf(LOG_ERR, "!ERROR %d (%s) daemonizing: %s", errno, strerror(errno), argv[0]);
    /xtrn.cpp: 1925 in sbbs_t::external(const char *, int, const char *, const char *)()
    1919 dup2(fd, STDOUT_FILENO);
    1920 if (!(mode & EX_NOLOG))
    1921 dup2(fd, STDERR_FILENO);
    1922 if (fd > 2)
    1923 close(fd);
    1924 }
    CID 654568: (RESOURCE_LEAK)
    Handle variable "fd" going out of scope leaks the handle.
    1925 }
    1926
    1927 if (mode & EX_BG) /* background execution, detach child */
    1928 {
    1929 if (daemon(TRUE, FALSE) != 0)
    1930 lprintf(LOG_ERR, "!ERROR %d (%s) daemonizing: %s", errno, strerror(errno), argv[0]);


    ________________________________________________________________________________________________________
    To view the defects in Coverity Scan visit, https://scan.coverity.com/projects/synchronet?tab=overview



    ---
    * Synchronet * Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net
  • From scan-admin@coverity.com@VERT to cov-scan@synchro.net on Monday, September 14, 2026 13:45:35
    Hi,

    Please find the latest report on new defect(s) introduced to Synchronet found with Coverity Scan.

    1 new defect(s) introduced to Synchronet found with Coverity Scan.
    1 defect(s), reported by Coverity Scan earlier, were marked fixed in the recent build analyzed by Coverity Scan.

    New defect(s) Reported-by: Coverity Scan
    Showing 1 of 1 defect(s)


    ** CID 656168: High impact quality (Y2K38_SAFETY)
    /main.cpp: 4542 in update_client_ini(sbbs_t *, const long *)()


    _____________________________________________________________________________________________
    *** CID 656168: High impact quality (Y2K38_SAFETY)
    /main.cpp: 4542 in update_client_ini(sbbs_t *, const long *)()
    4536 iniCloseFile(fp);
    4537 return;
    4538 }
    4539 iniSetUInteger(&ini, ROOT_SECTION, "user", (uint)sbbs->useron.number, NULL);
    4540 iniSetString(&ini, ROOT_SECTION, "name", sbbs->useron.alias, NULL);
    4541 if (done != NULL)
    CID 656168: High impact quality (Y2K38_SAFETY)
    A "time_t" value is stored in an integer with too few bits to accommodate it. The expression "*done" is cast to "uint".
    4542 iniSetUInteger(&ini, ROOT_SECTION, "done", (uint)*done, NULL);
    4543 iniWriteFile(fp, ini);
    4544 iniCloseFile(fp);
    4545 iniFreeStringList(ini);
    4546 }
    4547


    ________________________________________________________________________________________________________
    To view the defects in Coverity Scan visit, https://scan.coverity.com/projects/synchronet?tab=overview



    ---
    * Synchronet * Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net