@@ -14,9 +14,6 @@
<suppress>
<id>usleepCalled</id>
</suppress>
- <suppress>
- <id>variableScope</id>
- </suppress>
<!-- We have a lot of library includes, not all of them are really required,
so ignore them -->
<suppress>
@@ -288,4 +285,15 @@
<id>unusedStructMember</id>
<fileName>tests/unit_tests/openvpn/test_pkcs11.c</fileName>
</suppress>
+ <!-- IGN: nicer -->
+ <suppress>
+ <id>variableScope</id>
+ <fileName>src/openvpnserv/interactive.c</fileName>
+ <symbolName>cmds</symbolName>
+ </suppress>
+ <suppress>
+ <id>variableScope</id>
+ <fileName>src/openvpnserv/interactive.c</fileName>
+ <symbolName>sys_key</symbolName>
+ </suppress>
</suppressions>
@@ -120,13 +120,14 @@
ASN1_OBJECT *fn;
ASN1_STRING *val;
X509_NAME *x509_name;
- X509_NAME_ENTRY *ent;
const char *objbuf;
x509_name = X509_get_subject_name(x509);
- int i, n = X509_NAME_entry_count(x509_name);
- for (i = 0; i < n; ++i)
+ int n = X509_NAME_entry_count(x509_name);
+ for (int i = 0; i < n; ++i)
{
+ X509_NAME_ENTRY *ent;
+
if (!(ent = X509_NAME_get_entry(x509_name, i)))
{
continue;
@@ -197,7 +197,6 @@
ASN1_OBJECT *fn;
ASN1_STRING *val;
X509_NAME *x509_name;
- X509_NAME_ENTRY *ent;
const char *objbuf;
unsigned char *buf = NULL;
@@ -205,7 +204,7 @@
n = X509_NAME_entry_count(x509_name);
for (i = 0; i < n; ++i)
{
- ent = X509_NAME_get_entry(x509_name, i);
+ X509_NAME_ENTRY *ent = X509_NAME_get_entry(x509_name, i);
if (!ent)
{
continue;
@@ -228,13 +228,13 @@
int ret = false;
if (buf_defined(buf))
{
- va_list arglist;
uint8_t *ptr = BEND(buf);
int cap = buf_forward_capacity(buf);
if (cap > 0)
{
int stat;
+ va_list arglist;
va_start(arglist, format);
stat = vsnprintf((char *)ptr, cap, format, arglist);
va_end(arglist);
@@ -50,12 +50,11 @@
print_client_nat_list(const struct client_nat_option_list *list, msglvl_t msglevel)
{
struct gc_arena gc = gc_new();
- int i;
msg(msglevel, "*** CNAT list");
if (list)
{
- for (i = 0; i < list->n; ++i)
+ for (int i = 0; i < list->n; ++i)
{
const struct client_nat_entry *e = &list->entries[i];
msg(msglevel, " CNAT[%d] t=%d %s/%s/%s", i, e->type,
@@ -77,7 +77,6 @@
bool is_console = (GetFileType(in) == FILE_TYPE_CHAR);
DWORD flags_save = 0;
int status = 0;
- WCHAR *winput;
if (is_console)
{
@@ -100,7 +99,7 @@
if (is_console)
{
- winput = malloc(capacity * sizeof(WCHAR));
+ WCHAR *winput = malloc(capacity * sizeof(WCHAR));
if (winput == NULL)
{
return false;
@@ -1774,13 +1774,10 @@
static const cipher_name_pair *
get_cipher_name_pair(const char *cipher_name)
{
- const cipher_name_pair *pair;
- size_t i = 0;
-
/* Search for a cipher name translation */
- for (; i < cipher_name_translation_table_count; i++)
+ for (size_t i = 0; i < cipher_name_translation_table_count; i++)
{
- pair = &cipher_name_translation_table[i];
+ const cipher_name_pair *pair = &cipher_name_translation_table[i];
if (0 == strcmp(cipher_name, pair->openvpn_name)
|| 0 == strcmp(cipher_name, pair->lib_name))
{
@@ -387,9 +387,6 @@
else if (epoch > opt->key_ctx_bi.decrypt.epoch
&& epoch <= opt->key_ctx_bi.decrypt.epoch + opt->epoch_data_keys_future_count)
{
- /* Key in the range of future keys */
- int index = epoch - (opt->key_ctx_bi.decrypt.epoch + 1);
-
/* If we have reached the edge of the valid keys we do not return
* the key anymore since regenerating the new keys would move us
* over the window of valid keys and would need all kind of
@@ -400,6 +397,9 @@
}
else
{
+ /* Key in the range of future keys */
+ const int index = epoch - (opt->key_ctx_bi.decrypt.epoch + 1);
+
return &opt->epoch_data_keys_future[index];
}
}
@@ -444,7 +444,6 @@
key_to_nvlist(const uint8_t *key, const uint8_t *implicit_iv, const char *ciphername)
{
nvlist_t *nvl;
- size_t key_len;
nvl = nvlist_create(0);
@@ -452,7 +451,7 @@
if (strcmp(ciphername, "none") != 0)
{
- key_len = cipher_kt_key_size(ciphername);
+ const size_t key_len = cipher_kt_key_size(ciphername);
nvlist_add_binary(nvl, "key", key, key_len);
nvlist_add_binary(nvl, "iv", implicit_iv, 8);
@@ -271,7 +271,6 @@
{
char tmp_buf[256];
size_t len = 0;
- size_t label_length_pos;
for (int i = 0; i < array_len; i++)
{
@@ -290,7 +289,7 @@
/* label_length_pos points to the byte to be replaced by the length
* of the following domain label */
- label_length_pos = len++;
+ size_t label_length_pos = len++;
while (true)
{
@@ -62,14 +62,13 @@
static bool
env_string_equal(const char *s1, const char *s2)
{
- int c1, c2;
ASSERT(s1);
ASSERT(s2);
while (true)
{
- c1 = *s1++;
- c2 = *s2++;
+ int c1 = *s1++;
+ int c2 = *s2++;
if (c1 == '=')
{
c1 = 0;
@@ -214,12 +213,11 @@
if (check_debug_level(msglevel))
{
const struct env_item *e;
- int i;
if (es)
{
+ int i = 0;
e = es->list;
- i = 0;
while (e)
{
@@ -2039,13 +2039,13 @@
unsigned int socket = 0;
unsigned int tuntap = 0;
static uintptr_t tun_shift = TUN_SHIFT;
- static uintptr_t err_shift = ERR_SHIFT;
/*
* Calculate the flags based on the provided 'flags' argument.
*/
if ((c->options.mode != MODE_SERVER) && (flags & IOW_WAIT_SIGNAL))
{
+ static uintptr_t err_shift = ERR_SHIFT;
wait_signal(es, (void *)err_shift);
}
@@ -34,12 +34,9 @@
static void
CvtHex(IN HASH Bin, OUT HASHHEX Hex)
{
- unsigned short i;
- unsigned char j;
-
- for (i = 0; i < HASHLEN; i++)
+ for (unsigned short i = 0; i < HASHLEN; i++)
{
- j = (Bin[i] >> 4) & 0xf;
+ unsigned char j = (Bin[i] >> 4) & 0xf;
if (j <= 9)
{
Hex[i * 2] = (j + '0');
@@ -368,7 +368,6 @@
{
struct gc_arena gc = gc_new();
struct log_entry e;
- const char *out = NULL;
unsigned int action_flags = 0;
++recursive_level;
@@ -391,6 +390,8 @@
if (!man_password_needed(man))
{
+ const char *out = NULL;
+
if (flags == M_CLIENT)
{
out = log_entry_print(&e, LOG_PRINT_CRLF, &gc);
@@ -3036,14 +3037,15 @@
static void
man_output_peer_info_env(struct management *man, const struct man_def_auth_context *mdac)
{
- char line[256];
if (man->persist.callback.get_peer_info)
{
const char *peer_info =
(*man->persist.callback.get_peer_info)(man->persist.callback.arg, mdac->cid);
if (peer_info)
{
+ char line[256];
struct buffer buf;
+
buf_set_read(&buf, (const uint8_t *)peer_info, strlen(peer_info));
while (buf_parse(&buf, '\n', line, sizeof(line)))
{
@@ -3820,13 +3822,12 @@
{
int ok;
char *result = NULL;
- const struct buffer *buf;
ok = management_query_multiline(man, b64_data, prompt, cmd, state, input);
if (ok && buffer_list_defined(*input))
{
buffer_list_aggregate_separator(*input, 10000, "\n");
- buf = buffer_list_peek(*input);
+ const struct buffer *buf = buffer_list_peek(*input);
if (buf && BLEN(buf) > 0)
{
result = (char *)malloc(BLENZ(buf) + 1);
@@ -3847,15 +3848,13 @@
management_query_multiline_flatten(struct management *man, const char *b64_data, const char *prompt,
const char *cmd, int *state, struct buffer_list **input)
{
- int ok;
char *result = NULL;
- const struct buffer *buf;
- ok = management_query_multiline(man, b64_data, prompt, cmd, state, input);
+ const int ok = management_query_multiline(man, b64_data, prompt, cmd, state, input);
if (ok && buffer_list_defined(*input))
{
buffer_list_aggregate(*input, 2048);
- buf = buffer_list_peek(*input);
+ const struct buffer *buf = buffer_list_peek(*input);
if (buf && BLEN(buf) > 0)
{
result = (char *)malloc(BLENZ(buf) + 1);
@@ -474,7 +474,7 @@
purge_user_pass(struct user_pass *up, const bool force)
{
const bool nocache = up->nocache;
- static bool warn_shown = false;
+
if (nocache || force)
{
secure_memzero(up, sizeof(*up));
@@ -482,6 +482,8 @@
}
else
{
+ static bool warn_shown = false;
+
protect_user_pass(up);
/*
* don't show warning if the pass has been replaced by a token: this is an
@@ -721,11 +723,10 @@
bool
validate_peer_info_line(char *line)
{
- uint8_t c;
int state = 0;
while (*line)
{
- c = *line;
+ const uint8_t c = *line;
switch (state)
{
case 0:
@@ -4200,13 +4200,11 @@
static void
tunnel_server_loop(struct multi_context *multi)
{
- int status;
-
while (true)
{
/* wait on tun/socket list */
multi_get_timeout(multi, &multi->top.c2.timeval);
- status = multi_io_wait(multi);
+ const int status = multi_io_wait(multi);
MULTI_CHECK_SIG(multi);
/* check on status of coarse timers */
@@ -1375,13 +1375,11 @@
sitnl_parse_rtattr_flags(struct rtattr *tb[], size_t max, struct rtattr *rta, size_t len,
unsigned short flags)
{
- unsigned short type;
-
memset(tb, 0, sizeof(struct rtattr *) * (max + 1));
while (RTA_OK(rta, len))
{
- type = rta->rta_type & ~flags;
+ const unsigned short type = rta->rta_type & ~flags;
if ((type <= max) && (!tb[type]))
{
@@ -1409,7 +1407,6 @@
static int
sitnl_type_save(struct nlmsghdr *n, void *arg)
{
- char *type = arg;
struct ifinfomsg *ifi = NLMSG_DATA(n);
struct rtattr *tb[IFLA_MAX + 1];
@@ -1418,6 +1415,7 @@
if (tb[IFLA_LINKINFO])
{
struct rtattr *tb_link[IFLA_INFO_MAX + 1];
+ char *type = arg;
sitnl_parse_rtattr_nested(tb_link, IFLA_INFO_MAX, tb[IFLA_LINKINFO]);
@@ -1019,10 +1019,9 @@
for (current = *list, prev = NULL; current != NULL; current = current->next)
{
- char *tmp_value = NULL;
if (!strncmp(current->string, "foreign_option_", sizeof("foreign_option_") - 1))
{
- tmp_value = strchr(current->string, '=');
+ const char *tmp_value = strchr(current->string, '=');
if (tmp_value && ++tmp_value)
{
if (!strncmp(tmp_value, "dhcp-option ", sizeof("dhcp-option ") - 1))
@@ -351,7 +351,6 @@
{
const int max_recursive_levels = 10;
FILE *fp;
- int line_num;
char line[OPTION_LINE_SIZE + 1];
char *p[MAX_PARMS + 1];
@@ -368,7 +367,7 @@
}
if (fp)
{
- line_num = 0;
+ int line_num = 0;
while (fgets(line, sizeof(line), fp))
{
int offset = 0;
@@ -219,8 +219,6 @@
bool
packet_id_test(struct packet_id_rec *p, const struct packet_id_net *pin)
{
- uint64_t diff;
-
packet_id_debug(D_PID_DEBUG, p, pin, "PID_TEST", 0);
ASSERT(p->initialized);
@@ -247,7 +245,7 @@
}
/* check packet-id sliding window for original/replay status */
- diff = p->id - pin->id;
+ const uint64_t diff = p->id - pin->id;
/* keep track of maximum backtrack seen for debugging purposes */
if (diff > p->max_backtrack_stat)
@@ -512,7 +510,6 @@
{
struct packet_id_persist_file_image image;
CLEAR(image);
- ssize_t n;
off_t seek_ret;
struct gc_arena gc = gc_new();
@@ -521,7 +518,7 @@
seek_ret = lseek(p->fd, (off_t)0, SEEK_SET);
if (seek_ret == (off_t)0)
{
- n = write(p->fd, &image, sizeof(image));
+ const ssize_t n = write(p->fd, &image, sizeof(image));
if (n == sizeof(image))
{
p->time_last_written = p->time;
@@ -599,7 +596,6 @@
{
char c;
time_t v;
- int diff;
v = CIRC_LIST_ITEM(sl, i);
if (v == SEQ_UNSEEN)
@@ -612,7 +608,7 @@
}
else
{
- diff = (int)(prev_now - v);
+ const int diff = (int)(prev_now - v);
if (diff < 0)
{
c = 'N';
@@ -539,8 +539,6 @@
const char *
platform_create_temp_file(const char *directory, const char *prefix, struct gc_arena *gc)
{
- int fd;
- const char *retfname = NULL;
unsigned int attempts = 0;
char fname[256] = { 0 };
const char *fname_fmt = PACKAGE "_%.*s_%08" PRIx64 "%08" PRIx64 ".tmp";
@@ -557,7 +555,7 @@
return NULL;
}
- retfname = platform_gen_path(directory, fname, gc);
+ const char *retfname = platform_gen_path(directory, fname, gc);
if (!retfname)
{
msg(M_WARN, "Failed to create temporary filename and path");
@@ -566,7 +564,7 @@
/* Atomically create the file. Errors out if the file already
* exists. */
- fd = platform_open(retfname, O_CREAT | O_EXCL | O_WRONLY, S_IRUSR | S_IWUSR);
+ const int fd = platform_open(retfname, O_CREAT | O_EXCL | O_WRONLY, S_IRUSR | S_IWUSR);
if (fd != -1)
{
close(fd);
@@ -494,22 +494,21 @@
for (i = 0; i < pool->size; ++i)
{
const struct ifconfig_pool_entry *e = &pool->list[i];
- struct in6_addr ip6;
- in_addr_t ip;
- const char *ip6_str = "";
- const char *ip_str = "";
if (e->common_name)
{
+ const char *ip6_str = "";
+ const char *ip_str = "";
+
if (pool->ipv4.enabled)
{
- ip = ifconfig_pool_handle_to_ip_base(pool, i);
+ const in_addr_t ip = ifconfig_pool_handle_to_ip_base(pool, i);
ip_str = print_in_addr_t(ip, 0, &gc);
}
if (pool->ipv6.enabled)
{
- ip6 = ifconfig_pool_handle_to_ipv6_base(pool, i);
+ const struct in6_addr ip6 = ifconfig_pool_handle_to_ipv6_base(pool, i);
ip6_str = print_in6_addr(ip6, 0, &gc);
}
@@ -39,7 +39,6 @@
is_ipv_X(int tunnel_type, struct buffer *buf, int ip_ver)
{
int offset;
- uint16_t proto;
const struct openvpn_iphdr *ih;
verify_align_4(buf);
@@ -61,7 +60,7 @@
eh = (const struct openvpn_ethhdr *)BPTR(buf);
/* start by assuming this is a standard Eth fram */
- proto = eh->proto;
+ uint16_t proto = eh->proto;
offset = sizeof(struct openvpn_ethhdr);
/* if this is a 802.1q frame, parse the header using the according
@@ -1155,7 +1155,6 @@
while (e)
{
char *p[MAX_PARMS + 1];
- bool enable = true;
/* parse the push item */
CLEAR(p);
@@ -1163,6 +1162,8 @@
&& parse_line(e->option, p, SIZE(p) - 1, "[PUSH_ROUTE_REMOVE]", 1, D_ROUTE_DEBUG,
&gc))
{
+ bool enable = true;
+
/* is the push item a route directive? */
if (p[0] && !strcmp(p[0], "route") && !p[3] && o->iroutes)
{
@@ -2773,7 +2773,6 @@
{
struct gc_arena gc = gc_new();
bool ret = false;
- DWORD status;
const DWORD if_index = windows_route_find_if_index(r, tt);
if (if_index != TUN_ADAPTER_INDEX_INVALID)
@@ -2787,8 +2786,7 @@
fr.dwForwardNextHop = htonl(r->gateway);
fr.dwForwardIfIndex = if_index;
- status = DeleteIpForwardEntry(&fr);
-
+ const DWORD status = DeleteIpForwardEntry(&fr);
if (status == NO_ERROR)
{
ret = true;
@@ -3826,12 +3824,11 @@
bool
netmask_to_netbits(const in_addr_t network, const in_addr_t netmask, int *netbits)
{
- int i;
const int addrlen = sizeof(in_addr_t) * 8;
if ((network & netmask) == network)
{
- for (i = 0; i <= addrlen; ++i)
+ for (int i = 0; i <= addrlen; ++i)
{
in_addr_t mask = netbits_to_netmask(i);
if (mask == netmask)
@@ -176,14 +176,13 @@
#if defined(ENABLE_FEATURE_EXECVE)
if (openvpn_execve_allowed(flags))
{
- const char *cmd = a->argv[0];
- char *const *argv = a->argv;
char *const *envp = (char *const *)make_env_array(es, true, &gc);
- pid_t pid;
- pid = fork();
+ const pid_t pid = fork();
if (pid == (pid_t)0) /* child side */
{
+ const char *cmd = a->argv[0];
+ char *const *argv = a->argv;
execve(cmd, argv, envp);
exit(OPENVPN_EXECVE_FAILURE);
}
@@ -283,17 +282,17 @@
static bool warn_shown = false;
if (script_security() >= SSEC_BUILT_IN)
{
- const char *cmd = a->argv[0];
- char *const *argv = a->argv;
char *const *envp = (char *const *)make_env_array(es, true, &gc);
- pid_t pid;
+ const char *cmd = a->argv[0];
int pipe_stdout[2];
if (pipe(pipe_stdout) == 0)
{
- pid = fork();
- if (pid == (pid_t)0) /* child side */
+ const pid_t pid = fork();
+ if (pid == (pid_t)0) /* child side */
{
+ char *const *argv = a->argv;
+
close(pipe_stdout[0]); /* Close read end */
dup2(pipe_stdout[1], 1);
execve(cmd, argv, envp);
@@ -113,7 +113,6 @@
uint64_t v3 = UINT64_C(0x7465646279746573);
uint64_t k0 = U8TO64_LE(kk);
uint64_t k1 = U8TO64_LE(kk + 8);
- uint64_t m;
int i;
const unsigned char *end = ni + inlen - (inlen % sizeof(uint64_t));
const int left = inlen & 7;
@@ -130,7 +129,7 @@
for (; ni != end; ni += 8)
{
- m = U8TO64_LE(ni);
+ uint64_t m = U8TO64_LE(ni);
v3 ^= m;
TRACE;
@@ -1014,12 +1014,12 @@
tls_ctx_personalise_random(struct tls_root_ctx *ctx)
{
#if MBEDTLS_VERSION_NUMBER < 0x04000000
- static char old_sha256_hash[32] = { 0 };
- unsigned char sha256_hash[32] = { 0 };
mbedtls_ctr_drbg_context *cd_ctx = rand_ctx_get();
if (NULL != ctx->crt_chain)
{
+ static char old_sha256_hash[32] = { 0 };
+ unsigned char sha256_hash[32] = { 0 };
mbedtls_x509_crt *cert = ctx->crt_chain;
const mbedtls_md_info_t *kt = md_get("SHA256");
@@ -1784,10 +1784,7 @@
{
STACK_OF(X509_INFO) *info_stack = NULL;
STACK_OF(X509_NAME) *cert_names = NULL;
- X509_LOOKUP *lookup = NULL;
X509_STORE *store = NULL;
- BIO *in = NULL;
- openssl_stack_size_t added = 0, prev = 0;
ASSERT(NULL != ctx);
@@ -1800,6 +1797,9 @@
/* Try to add certificates and CRLs from ca_file */
if (ca_file)
{
+ openssl_stack_size_t added = 0;
+ BIO *in = NULL;
+
if (ca_file_inline)
{
in = BIO_new_mem_buf((char *)ca_file, -1);
@@ -1816,6 +1816,8 @@
if (info_stack)
{
+ openssl_stack_size_t prev = 0;
+
for (openssl_stack_size_t i = 0; i < sk_X509_INFO_num(info_stack); i++)
{
X509_INFO *info = sk_X509_INFO_value(info_stack, i);
@@ -1916,7 +1918,7 @@
/* Set a store for certs (CA & CRL) with a lookup on the "capath" hash directory */
if (ca_path)
{
- lookup = X509_STORE_add_lookup(store, X509_LOOKUP_hash_dir());
+ X509_LOOKUP *lookup = X509_STORE_add_lookup(store, X509_LOOKUP_hash_dir());
if (lookup && X509_LOOKUP_add_dir(lookup, ca_path, X509_FILETYPE_PEM))
{
msg(M_WARN, "WARNING: experimental option --capath %s", ca_path);
@@ -74,8 +74,6 @@
int e1, e2;
uint8_t *b = BPTR(buf);
- uint8_t buf1[SWAP_BUF_SIZE];
- uint8_t buf2[SWAP_BUF_SIZE];
if (incoming)
{
@@ -92,6 +90,9 @@
if (buf->len >= e1 + e2)
{
+ uint8_t buf1[SWAP_BUF_SIZE];
+ uint8_t buf2[SWAP_BUF_SIZE];
+
memcpy(buf1, b, e1);
memcpy(buf2, b + e1, e2);
memcpy(b, buf2, e2);
@@ -701,7 +701,6 @@
void
x509_setenv(struct env_set *es, int cert_depth, mbedtls_x509_crt *cert)
{
- unsigned char c;
const mbedtls_x509_name *name;
char s[128] = { 0 };
@@ -729,7 +728,7 @@
break;
}
- c = name->val.p[i];
+ const unsigned char c = name->val.p[i];
if (c < 32 || c == 127 || (c > 128 && c < 160))
{
s[i] = '?';
@@ -1893,7 +1893,6 @@
openvpn_net_ctx_t *ctx)
{
char dynamic_name[256];
- bool dynamic_opened = false;
/*
* unlike "open_tun_generic()", DCO on Linux and FreeBSD follows
@@ -1905,6 +1904,8 @@
if (strcmp(dev, "tun") == 0)
{
+ bool dynamic_opened = false;
+
for (int i = 0; i < 256; ++i)
{
snprintf(dynamic_name, sizeof(dynamic_name), "%s%d", dev, i);
@@ -3263,7 +3264,6 @@
if (tt->reads.iostate == IOSTATE_INITIAL)
{
BOOL status;
- int err;
/* reset buf to its initial state */
tt->reads.buf = tt->reads.buf_init;
@@ -3290,7 +3290,7 @@
}
else
{
- err = GetLastError();
+ const int err = GetLastError();
if (err == ERROR_IO_PENDING) /* operation queued? */
{
tt->reads.iostate = IOSTATE_QUEUED;
@@ -3318,7 +3318,6 @@
if (tt->writes.iostate == IOSTATE_INITIAL)
{
BOOL status;
- int err;
/* make a private copy of buf */
tt->writes.buf = tt->writes.buf_init;
@@ -3345,7 +3344,7 @@
}
else
{
- err = GetLastError();
+ const int err = GetLastError();
if (err == ERROR_IO_PENDING) /* operation queued? */
{
tt->writes.iostate = IOSTATE_QUEUED;
@@ -3542,8 +3541,6 @@
char enum_name[256];
char unit_string[256];
HKEY unit_key;
- char component_id_string[] = "ComponentId";
- char component_id[256];
const char net_cfg_instance_id_string[] = "NetCfgInstanceId";
BYTE net_cfg_instance_id[256];
DWORD data_type;
@@ -3573,6 +3570,8 @@
}
else
{
+ const char component_id_string[] = "ComponentId";
+ char component_id[256];
len = sizeof(component_id);
status = RegQueryValueEx(unit_key, component_id_string, NULL, &data_type,
(LPBYTE)component_id, &len);
@@ -3657,7 +3656,6 @@
char enum_name[256];
char connection_string[256];
HKEY connection_key;
- WCHAR name_data[256];
DWORD name_type;
const WCHAR name_string[] = L"Name";
@@ -3689,6 +3687,7 @@
}
else
{
+ WCHAR name_data[256];
len = sizeof(name_data);
status = RegQueryValueExW(connection_key, name_string, NULL, &name_type,
(LPBYTE)name_data, &len);
@@ -3813,8 +3812,6 @@
bool warn_panel_dup = false;
bool warn_tap_dup = false;
- int links;
-
const struct tap_reg *tr;
const struct tap_reg *tr1;
const struct panel_reg *pr;
@@ -3827,7 +3824,7 @@
/* loop through each TAP-Windows adapter registry entry */
for (tr = tap_reg; tr != NULL; tr = tr->next)
{
- links = 0;
+ int links = 0;
/* loop through each network connections entry in the control panel */
for (pr = panel_reg; pr != NULL; pr = pr->next)
@@ -4110,10 +4107,11 @@
{
ULONG size = 0;
IP_PER_ADAPTER_INFO *pi = NULL;
- DWORD status;
if (index != TUN_ADAPTER_INDEX_INVALID)
{
+ DWORD status;
+
if ((status = GetPerAdapterInfo(index, NULL, &size)) != ERROR_BUFFER_OVERFLOW)
{
msg(M_INFO, "GetPerAdapterInfo #1 failed (status=%lu) : %s", status,
@@ -4308,7 +4306,6 @@
bool
is_adapter_up(const struct tuntap *tt, const IP_ADAPTER_INFO *list)
{
- int i;
bool ret = false;
const IP_ADAPTER_INFO *ai = get_tun_adapter(tt, list);
@@ -4318,7 +4315,7 @@
const int n = get_adapter_n_ip_netmask(ai);
/* loop once for every IP/netmask assigned to adapter */
- for (i = 0; i < n; ++i)
+ for (int i = 0; i < n; ++i)
{
in_addr_t ip, netmask;
if (get_adapter_ip_netmask(ai, i, &ip, &netmask))
@@ -4352,7 +4349,6 @@
bool
is_ip_in_adapter_subnet(const IP_ADAPTER_INFO *ai, const in_addr_t ip, in_addr_t *highest_netmask)
{
- int i;
bool ret = false;
if (highest_netmask)
@@ -4363,7 +4359,7 @@
if (ai)
{
const int n = get_adapter_n_ip_netmask(ai);
- for (i = 0; i < n; ++i)
+ for (int i = 0; i < n; ++i)
{
in_addr_t adapter_ip, adapter_netmask;
if (get_adapter_ip_netmask(ai, i, &adapter_ip, &adapter_netmask))
@@ -1042,7 +1042,6 @@
openvpn_execve(const struct argv *a, const struct env_set *es, const unsigned int flags)
{
int ret = OPENVPN_EXECVE_ERROR;
- static bool exec_warn = false;
if (a && a->argv[0])
{
@@ -1093,6 +1092,8 @@
}
else
{
+ static bool exec_warn = false;
+
ret = OPENVPN_EXECVE_NOT_ALLOWED;
if (!exec_warn && (script_security() < SSEC_SCRIPTS))
{
@@ -1489,11 +1490,10 @@
static void
set_openssl_env_vars(void)
{
- const WCHAR *ssl_fallback_dir = L"C:\\Windows\\System32";
-
WCHAR install_path[MAX_PATH] = { 0 };
if (!get_openvpn_reg_value(NULL, install_path, _countof(install_path)))
{
+ const WCHAR *ssl_fallback_dir = L"C:\\Windows\\System32";
/* if we cannot find installation path from the registry,
* use Windows directory as a fallback
*/
@@ -254,10 +254,8 @@
MsgToEventLog(DWORD flags, LPCWSTR format, ...)
{
HANDLE hEventSource;
- WCHAR msg[2][256];
DWORD error = 0;
LPCWSTR err_msg = L"";
- va_list arglist;
if (flags & MSG_FLAGS_SYS_CODE)
{
@@ -268,6 +266,9 @@
hEventSource = RegisterEventSource(NULL, APPNAME);
if (hEventSource != NULL)
{
+ va_list arglist;
+ WCHAR msg[2][256];
+
swprintf(msg[0], _countof(msg[0]), L"%ls%ls%ls: %ls", APPNAME, service_instance,
(flags & MSG_FLAGS_ERROR) ? L" error" : L"", err_msg);
@@ -311,10 +312,10 @@
const wchar_t *
get_win_sys_path(void)
{
- const wchar_t *default_sys_path = L"C:\\Windows\\system32";
-
if (!GetSystemDirectoryW(win_sys_path, _countof(win_sys_path)))
{
+ const wchar_t *default_sys_path = L"C:\\Windows\\system32";
+
wcscpy_s(win_sys_path, _countof(win_sys_path), default_sys_path);
win_sys_path[_countof(win_sys_path) - 1] = L'\0';
}
@@ -933,7 +933,6 @@
RegisterDNS(LPVOID unused)
{
DWORD err;
- size_t i;
DWORD timeout = RDNS_TIMEOUT * 1000; /* in milliseconds */
/* path of ipconfig command */
@@ -956,7 +955,7 @@
if (WaitForMultipleObjects(2, wait_handles, FALSE, timeout) == WAIT_OBJECT_0)
{
/* Semaphore locked */
- for (i = 0; i < _countof(cmds); ++i)
+ for (size_t i = 0; i < _countof(cmds); ++i)
{
ExecCommand(cmds[i].argv0, cmds[i].cmdline, cmds[i].timeout);
}
@@ -21,7 +21,6 @@
BOOL
ReportStatusToSCMgr(SERVICE_STATUS_HANDLE service, SERVICE_STATUS *status)
{
- static DWORD dwCheckPoint = 1;
BOOL res = TRUE;
if (status->dwCurrentState == SERVICE_START_PENDING)
@@ -39,6 +38,7 @@
}
else
{
+ static DWORD dwCheckPoint = 1;
status->dwCheckPoint = dwCheckPoint++;
}
@@ -55,7 +55,6 @@
static int
CmdInstallServices(void)
{
- SC_HANDLE service;
SC_HANDLE svc_ctl_mgr;
WCHAR path[512];
int i, ret = _service_max;
@@ -78,7 +77,7 @@
for (i = 0; i < _service_max; i++)
{
- service = CreateService(
+ SC_HANDLE service = CreateService(
svc_ctl_mgr, openvpn_service[i].name, openvpn_service[i].display_name,
SERVICE_QUERY_STATUS, SERVICE_WIN32_SHARE_PROCESS, openvpn_service[i].start_type,
SERVICE_ERROR_NORMAL, path, NULL, NULL, openvpn_service[i].dependencies, NULL, NULL);
@@ -378,12 +378,11 @@
static void
xkey_provider_test_generic_sign_cb(void **state)
{
- EVP_PKEY *pubkey;
const char *dummy = "xkey_handle"; /* a dummy handle for the external key */
for (size_t i = 0; i < _countof(pubkeys); i++)
{
- pubkey = load_pubkey(pubkeys[i]);
+ EVP_PKEY *pubkey = load_pubkey(pubkeys[i]);
assert_non_null(pubkey);
EVP_PKEY *privkey =