AP_Param: make fgets buflen semantics match C's fgets

buflen now includes the space required for the null terminator, so up
to buflen-1 characters are returned.  Previously fgets could write
buf[buflen], one byte beyond the caller-nominated length.  All
in-tree callers passed sizeof(buf)-1 to compensate, but
posix_compat's apfs_fgets forwards its C-style size argument
directly, so a caller supplying a size-byte buffer could have that
buffer overrun by one byte on an over-long line.

Update callers to pass the full buffer size; usable capacity is
unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Peter Barker
2026-07-23 17:37:00 +10:00
committed by Peter Barker
co-authored by Claude Opus 4.8
parent 10dfd237a2
commit 95f0a91c8d
+2 -2
View File
@@ -2327,7 +2327,7 @@ bool AP_Param::count_defaults_in_file(const char *filename, uint16_t &num_defaul
/*
work out how many parameter default structures to allocate
*/
while (AP::FS().fgets(line, sizeof(line)-1, file_apfs)) {
while (AP::FS().fgets(line, sizeof(line), file_apfs)) {
char *pname;
float value;
bool read_only;
@@ -2356,7 +2356,7 @@ bool AP_Param::read_param_defaults_file(const char *filename, bool last_pass, ui
bool done_all = true;
char line[100];
while (AP::FS().fgets(line, sizeof(line)-1, file_apfs)) {
while (AP::FS().fgets(line, sizeof(line), file_apfs)) {
char *pname;
float value;
bool read_only;