Skip to content

Various unsafe code in nlp_engine.cpp #486

Description

@dhdaines

Widespread use of fixed-size buffers on the stack as strings is quite unsafe (too many examples to list but everywhere MAXPATH or MAXSTR is used).

Consider using _stprintf_s on Windows or snprintf on Unix, or using std::string (since it is being used elsewhere).

Also the ownership of _TCHAR * arguments pased to the API functions is unclear, it appears that they take ownership (and so these strings should not ever be deallocated by the caller).

Again consider using std::string since this is a C++ API. Otherwise mark them as const and copy the contents.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions