Enhance code safety and readability in SSL_get_shared_ciphers()
authorSumitra Sharma <sumitraartsy@gmail.com>
Tue, 12 Sep 2023 06:30:21 +0000 (12:00 +0530)
committerTomas Mraz <tomas@openssl.org>
Mon, 18 Sep 2023 12:11:52 +0000 (14:11 +0200)
commit31584555aa5cc8a9fa7d4fc517f261cc4c17d7a9
treeeb6ddcb35857da8685f12502fab4c29bef94a6a8
parentcdc4f2b5072f908e88e3aae83d87a7d095d2b36a
Enhance code safety and readability in SSL_get_shared_ciphers()

This commit introduces two key improvements:

1. Improve code safety by replacing the conditional statement with
`if (n >= size)` and using OPENSSL_strnlen() instead of strlen().
This change ensures proper buffer size handling and adheres to
secure coding practices.

2. Enhance code readability by substituting `strcpy(p, c->name)` with
`memcpy(p, c->name, n)`. This adjustment prioritizes code clarity and
maintenance, even while mitigating a minimal buffer overflow risk.

These enhancements bolster the code's robustness and comprehensibility,
aligning with secure coding principles and best practices.

Fixes #19837

Signed-off-by: Sumitra Sharma <sumitraartsy@gmail.com>
Reviewed-by: Paul Dale <pauli@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/21934)

(cherry picked from commit 2743594d73e65c38375c619e89ec62579e2c24a9)
ssl/ssl_lib.c