From d6f513a25cf005f81833045fb21afccbc4111cb9 Mon Sep 17 00:00:00 2001 From: envision3d Date: Sat, 19 Sep 2026 12:49:16 -0500 Subject: [PATCH 1/2] Unix filesystem: long-path safety --- .../Engine/Platform/Unix/UnixFileSystem.cpp | 21 +++++++++++-------- 1 file changed, 12 insertions(+), 9 deletions(-) diff --git a/Source/Engine/Platform/Unix/UnixFileSystem.cpp b/Source/Engine/Platform/Unix/UnixFileSystem.cpp index df854c138..d2550255e 100644 --- a/Source/Engine/Platform/Unix/UnixFileSystem.cpp +++ b/Source/Engine/Platform/Unix/UnixFileSystem.cpp @@ -89,8 +89,9 @@ bool DeleteUnixPathTree(const char* path) continue; // Determinate a full path of an entry - char full_path[256]; - ASSERT(pathLength + strlen(entry->d_name) < ARRAY_COUNT(full_path)); + char full_path[4096]; + if (pathLength + strlen(entry->d_name) + 2 > ARRAY_COUNT(full_path)) + continue; strcpy(full_path, path); strcat(full_path, "/"); strcat(full_path, entry->d_name); @@ -199,8 +200,9 @@ bool UnixFileSystem::GetChildDirectories(Array& results, const String& p continue; // Determinate a full path of an entry - char fullPath[256]; - ASSERT(pathLength + strlen(entry->d_name) < ARRAY_COUNT(fullPath)); + char fullPath[4096]; + if (pathLength + strlen(entry->d_name) + 2 > ARRAY_COUNT(fullPath)) + continue; strcpy(fullPath, pathStr); strcat(fullPath, "/"); strcat(fullPath, entry->d_name); @@ -353,9 +355,9 @@ bool UnixFileSystem::getFilesFromDirectoryTop(Array& results, const char continue; // Determinate a full path of an entry - char fullPath[256]; - const int32 pathLength = strlen(entry->d_name); - ASSERT(pathLength + strlen(entry->d_name) < ARRAY_COUNT(fullPath)); + char fullPath[4096]; + if (pathLength + strlen(entry->d_name) + 2 > ARRAY_COUNT(fullPath)) + continue; strcpy(fullPath, path); strcat(fullPath, "/"); strcat(fullPath, entry->d_name); @@ -419,8 +421,9 @@ bool UnixFileSystem::getFilesFromDirectoryAll(Array& results, const char continue; // Determinate a full path of an entry - char full_path[256]; - ASSERT(pathLength + strlen(entry->d_name) < ARRAY_COUNT(full_path)); + char full_path[4096]; + if (pathLength + strlen(entry->d_name) + 2 > ARRAY_COUNT(full_path)) + continue; strcpy(full_path, path); strcat(full_path, "/"); strcat(full_path, entry->d_name); From 7470877c4c5ce8a3ac097235eb095961187ad414 Mon Sep 17 00:00:00 2001 From: Wojtek Figat Date: Sun, 20 Sep 2026 23:39:20 +0200 Subject: [PATCH 2/2] Improve #4267 for consoles and web --- Source/Engine/Platform/Unix/UnixFileSystem.cpp | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/Source/Engine/Platform/Unix/UnixFileSystem.cpp b/Source/Engine/Platform/Unix/UnixFileSystem.cpp index d2550255e..4765ccdd3 100644 --- a/Source/Engine/Platform/Unix/UnixFileSystem.cpp +++ b/Source/Engine/Platform/Unix/UnixFileSystem.cpp @@ -25,6 +25,12 @@ typedef StringAsANSI<> UnixString; typedef StringAsUTF8<> UnixString; #endif +#if PLATFORM_CONSOLE || PLATFORM_WEB +#define MAX_PATH 256 // Shorter path limit on fixed environments +#else +#define MAX_PATH 4096 +#endif + const DateTime UnixEpoch(1970, 1, 1); bool UnixFileSystem::CreateDirectory(const StringView& path) @@ -89,7 +95,7 @@ bool DeleteUnixPathTree(const char* path) continue; // Determinate a full path of an entry - char full_path[4096]; + char full_path[MAX_PATH]; if (pathLength + strlen(entry->d_name) + 2 > ARRAY_COUNT(full_path)) continue; strcpy(full_path, path); @@ -200,7 +206,7 @@ bool UnixFileSystem::GetChildDirectories(Array& results, const String& p continue; // Determinate a full path of an entry - char fullPath[4096]; + char fullPath[MAX_PATH]; if (pathLength + strlen(entry->d_name) + 2 > ARRAY_COUNT(fullPath)) continue; strcpy(fullPath, pathStr); @@ -355,7 +361,7 @@ bool UnixFileSystem::getFilesFromDirectoryTop(Array& results, const char continue; // Determinate a full path of an entry - char fullPath[4096]; + char fullPath[MAX_PATH]; if (pathLength + strlen(entry->d_name) + 2 > ARRAY_COUNT(fullPath)) continue; strcpy(fullPath, path); @@ -421,7 +427,7 @@ bool UnixFileSystem::getFilesFromDirectoryAll(Array& results, const char continue; // Determinate a full path of an entry - char full_path[4096]; + char full_path[MAX_PATH]; if (pathLength + strlen(entry->d_name) + 2 > ARRAY_COUNT(full_path)) continue; strcpy(full_path, path);