@elextr commented on this pull request.


>                       SETPTR(new_filename, g_strconcat(new_filename, ".", 
> ft->extension, NULL));
 
+               /* create new file */
+               fd = g_mkstemp(new_filename);
+               if (fd == -1)
+               {
+                       gchar *message = g_strdup_printf(
+                               _("Instant Save filename could not be generated 
(%s)."), g_strerror(errno));
+                       ui_set_statusbar(TRUE, "%s", message);
+                       g_warning("%s", message);
+                       g_free(message);
+                       return;

leaks `new_filename`

>               if (ft == NULL || ft->id == GEANY_FILETYPES_NONE)
                        /* ft is NULL when a new file without template was 
opened, so use the
                         * configured default file type */
                        ft = filetypes_lookup_by_name(instantsave_default_ft);
 
-               if (ft != NULL)
-                       /* add the filetype's default extension to the new 
filename */
+               /* construct filename */
+               directory = !EMPTY(instantsave_target_dir) ? 
instantsave_target_dir : g_get_tmp_dir();
+               new_filename = g_build_filename(directory, "gis_XXXXXX", NULL);
+               if (ft != NULL && !EMPTY(ft->extension))
                        SETPTR(new_filename, g_strconcat(new_filename, ".", 
ft->extension, NULL));

`ft == NULL` means `doc->file_type` is NULL, but its not set before being 
dereferenced at **here** below

>                       SETPTR(new_filename, g_strconcat(new_filename, ".", 
> ft->extension, NULL));
 
+               /* create new file */
+               fd = g_mkstemp(new_filename);
+               if (fd == -1)
+               {
+                       gchar *message = g_strdup_printf(
+                               _("Instant Save filename could not be generated 
(%s)."), g_strerror(errno));
+                       ui_set_statusbar(TRUE, "%s", message);
+                       g_warning("%s", message);
+                       g_free(message);
+                       return;
+               }
+
+               close(fd); /* close the returned file descriptor as we only 
need the filename */
+
                doc->file_name = new_filename;
 
                if (doc->file_type->id == GEANY_FILETYPES_NONE)

**here**

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/geany/geany/pull/2769#pullrequestreview-623684122

Reply via email to