Security
- diskinfo: replace popen("du -d 1 "%s" | sort -rn") with an in-process
openat/fstatat directory walk. On-disk directory names were interpolated
into a shell command, allowing command injection (e.g. a dir named
"$(reboot)") when drilling into Disk Info. The walk sums actual usage
(st_blocks*512), stays on one filesystem (du -x), never follows symlinks,
and stays cancellable — also faster (no subprocess/pipe/parse). - lang: validate translation format strings at load time. tr() values are
used as printf formats at 60+ sites; an untrusted .ini with %n or a wrong
specifier count/type was undefined behaviour (memory write / over-read).
Each value is now checked against the English baseline's argument
signature; mismatched/unsafe entries fall back to English or the key.
Rejects %n and * dynamic width outright. No call-site changes.
Data safety (editor saves)
- hexview: save in place via pwrite instead of fopen("wb")+fwrite, which
truncated files larger than the 16 MB window to the window. Bytes past
the window are now preserved; errors and fsync are checked; modified flag
cleared only on success. Added a "[first 16M]" header marker. - viewer: never overwrite the full file with a partially-loaded prefix.
Files exceeding the cap (raised to 8192 lines / 2 MB) load view-only with
a "[too large - view only]" banner (Viewer_TooLarge added to all 4 langs).
Saves are now atomic (temp + fsync + rename), preserve permissions, check
errors, and clear modified only on success.
Large files / 32-bit (armhf)
- Makefile: add -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 so off_t/stat/
fseeko/ftello are 64-bit on 32-bit targets (no-op on 64-bit). Required for2 GB files and so copy_file_range's loff_t* offsets match off_t.
- viewer/hexview: fseek/ftell -> fseeko/ftello into off_t (correct size
probe and truncation detection for >2 GB files). - fileop: do_cfr copy_file_range offsets are explicitly int64_t, so the
kernel's 64-bit loff_t* write-back can never clobber a smaller stack slot,
independent of the LFS flag.
Robustness / hardening
- Add copy_str() (always NUL-terminates) and convert the non-terminating
strncpy idiom across fileop/config/main/imgview/hexview/viewer/snake/lang.
Fixes latent over-reads of untrusted data (filenames, config values,
toast strings) and clears the -Wstringop-truncation class. - Makefile: release build adds -D_FORTIFY_SOURCE=2 -fstack-protector-strong.
- format_size: 1024LL10241024 (explicit 64-bit, guards future TB tier).
Files: main.c, fileop.c, viewer.c, hexview.c, lang.c, config.c, imgview.c,
snake.c, vtree.h, Makefile, lang/{English,Spanish,Polish,Vietnamese}.ini