What changed, and why it matters
This commit swaps the two arguments in two calloc() calls so they follow the conventional order (number of elements first, then element size). On standard platforms this produces identical memory allocation results and does not change program behavior or fix any security bug. It only silences compiler warnings.
No security action needed; treat as a normal code-quality/clean-up commit.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The patch changes calloc(nmemb, size) argument order from calloc(sizeof(type), 1) to calloc(1, sizeof(type)) in oaes_key_import_data() and oaes_alloc(). The C standard defines calloc(nmemb, size), but for nmemb=1 and size=N the allocated byte count is the same either way (1×N = N×1). Therefore the change is cosmetic and warning-suppression only, with no functional or security effect.
Changed components
src/crypto/oaes_lib.cInspect captured patch +2 / −2
diff --git a/src/crypto/oaes_lib.c b/src/crypto/oaes_lib.c
index 138f87a..1190d4e 100644
--- a/src/crypto/oaes_lib.c
+++ b/src/crypto/oaes_lib.c
@@ -224,7 +224,7 @@ OAES_RET oaes_key_import_data( OAES_CTX * ctx,
if( _ctx->key )
oaes_key_destroy( &(_ctx->key) );
- _ctx->key = (oaes_key *) calloc( sizeof( oaes_key ), 1 );
+ _ctx->key = (oaes_key *) calloc( 1, sizeof( oaes_key ) );
if( NULL == _ctx->key )
return OAES_RET_MEM;
@@ -253,7 +253,7 @@ OAES_RET oaes_key_import_data( OAES_CTX * ctx,
OAES_CTX * oaes_alloc(void)
{
- oaes_ctx * _ctx = (oaes_ctx *) calloc( sizeof( oaes_ctx ), 1 );
+ oaes_ctx * _ctx = (oaes_ctx *) calloc( 1, sizeof( oaes_ctx ) );
if( NULL == _ctx )
return NULL;
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.