Mirror of pcloudcc-lneely, an independent fork of pcloudcom/console-client hosted on Github.
Go to file
Levi Neely 60e43edec4
Fix pcl-a1j: buffer overflow in ptools_create_backend_event() via unchecked sprintf and strcat (#355)
* Fix pcl-a1j.1: replace sprintf with snprintf and add strcat length check in ptools_create_backend_event()

Add paramname length check (> 254 bytes → skip with warning) before
snprintf into charBuff[i][258], and validate the snprintf return
value. Add explicit length check before strcat into keyParams to
prevent overflow when paramname exceeds remaining buffer space.
Eliminates buffer overflow from long paramname.

Ref GH #195.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Fix pcl-a1j.1: clamp pCnt to PTOOLS_MAX_PARAMS to prevent charBuff stack overflow

charBuff[30][258] is a fixed-size stack array but pCnt was unbounded,
allowing any caller with params->paramCnt > 30 to overflow the stack
via charBuff[i] access. Add PTOOLS_MAX_PARAMS (30) define, use it to
size charBuff, and clamp pCnt to PTOOLS_MAX_PARAMS with a warning log
before the loop.

Ref GH #195.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Add ptools_create_backend_event() validation tests (pcl-a1j)

11 test cases covering pCnt clamping, paramname length guards,
snprintf boundary, keyParams overflow check, and comma-prefix
for subsequent params.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Levi Neely <lkn@darkstar.example.net>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-07 18:35:43 +01:00
.github/workflows upgrade to mbedtls 3.x (#118) 2025-03-09 15:16:46 +01:00
dev arm64 arch devhost 2025-07-20 16:01:47 +02:00
doc Fix MBEDTLS-3.x.md: Add LIBLDFLAGS update to linker path (#168) 2026-02-27 08:44:38 +01:00
pclsync Fix pcl-a1j: buffer overflow in ptools_create_backend_event() via unchecked sprintf and strcat (#355) 2026-03-07 18:35:43 +01:00
tests Fix pcl-a1j: buffer overflow in ptools_create_backend_event() via unchecked sprintf and strcat (#355) 2026-03-07 18:35:43 +01:00
.clang-format manual formatting (#136) 2025-03-11 21:36:26 +01:00
.envrc enable direnv for dev shell 2025-04-13 08:47:23 +02:00
.gitignore Add .kiro and .claude to .gitignore (#337) 2026-03-03 17:01:27 +01:00
CLI11.hpp Revert "Streamline CLI11.hpp to functionality actually used by pcloudcc" (#81) 2024-12-10 21:48:15 +01:00
LOG-MANAGEMENT.md Refactor logging, add cache-size, fs-event-log (#163) 2026-02-27 08:38:28 +01:00
Makefile Fix debug build segfault: add strong overrides for psql_lock/unlock functions (#177) 2026-03-03 07:59:30 +01:00
README.md Remove obsolete Pending Transfers section from README (#174) 2026-03-02 20:17:10 +01:00
control_tools.cpp Fix signal handler safety issues (pcl-2tv) (#351) 2026-03-06 21:34:00 +01:00
control_tools.h non interactive command processing (#123) 2025-03-09 19:18:38 +01:00
default.nix nix dev shell (#146) 2025-04-11 00:44:35 +02:00
flake.lock Nix shell uses flakes (#147) 2025-04-11 20:55:58 +02:00
flake.nix add watchexec to dev shell 2025-04-18 11:32:16 +02:00
main.cpp Fix exception handling and operator precedence bugs (#295) 2026-03-03 11:25:25 +01:00
pcloudcc.logrotate Refactor logging, add cache-size, fs-event-log (#163) 2026-02-27 08:38:28 +01:00
pclsync_lib.cpp Fix pcl-bga: make psync_status.status accesses atomic (#346) 2026-03-04 18:24:35 +01:00
pclsync_lib.h Fix #90, #109: Support 2FA when running as a daemon (#175) 2026-03-02 21:36:33 +01:00
rpcclient.cpp Fix pcl-6nb: readResponse buffer over-read via unchecked msg->length (#354) 2026-03-07 18:08:56 +01:00
rpcclient.h 130 use trustworthy location for log and socket (#134) 2025-03-11 19:03:58 +01:00

README.md

Introduction

pcloudcc is simple linux console client for pCloud cloud storage derived from the console-client developed by pCloud. This version is independently maintained by me, whose only affiliation with pCloud is as a user of their services. Due credit goes to Anton Titov, Ivan Stoev, and pCloud.

Supported Platforms & Distributions

The target operating system and platform for this program is linux/amd64, and has been reported to work on linux/aarch64. Program behavior on 32-bit architectures is considered undefined.

I aim to support as many distributions as possible. I maintain a package for AUR and Nix. I do not plan on providing or maintaining any other packages, but encourage anyone interested in doing so for their own distributions.

Notices

Security Notice

My code audits are best-effort, and I make security enhancements as I identify problems. However, I do not promise that this program is free of even older and well-known security vulnerabilities. Therefore, I recommend using this program only on a trusted single-user system. Security-related code audits and contributions are most welcome!

See Also

  • Contributing: Read this if you're interested in helping out. Short version: do your best to write good code, be courteous to maintainers, and most importantly: have fun!

  • Building: Read this if you're not sure how to build pcloudcc. For most users, make and make install are enough.

  • mbedtls 3.x migration notes: Read this if you use an older distribution such as debian:bookworm and encounter build problems.

  • Device Validation Guide: Read this if you're running pcloudcc and encounter device validation-related errors.

  • Usage Guide: Read this if you're unsure how to start using pcloudcc.

  • Log Management Guide: Read this to configure log rotation, cache size limits, and custom log paths. To set up automatic log rotation, copy pcloudcc.logrotate to /etc/logrotate.d/pcloudcc.

  • pcloudcc-service: Container-based systemd service for running pcloudcc in userspace with podman. Includes multi-stage Dockerfile that builds pcloudcc from source and Quadlet systemd unit for automated background syncing.