> The code is nice and very well commented.
I opened the first file in src/: browser.c. Let's take the function browse_draw_mtime() and start picking nits :-)
It has a buffer of 26 chars, which will (for a regular C string) mean 25 characters + 1 NUL terminator.
char mbuf[26];
But in the end, it prints with the printf()-like function:printw("%26s", mbuf);
the count there is supposed to exclude the NUL terminator. So it should be 25 and not 26. Note that it cannot cause a problem, but it may indicate that the author didn't carefully grasp the exact definition of the format.
Before that, in a branch the mbuf buffer is filled with the strftime() function. This function is stupidly defined by the C standard and POSIX didn't make it better. It is not the author's fault, but one has to account for its flaws.
strftime(mbuf, sizeof(mbuf), "%Y-%m-%d %H:%M:%S %z", localtime(&t));
One would assume that the result string is truncated if it happens that the result would be too long, so that code would be fine. Well, not quite, it just protects from writing after the buffer. The standards say that in cases when the buffer is not long enough, the content of the result string is indeterminate :-/ Actually, it could even be not a string (not a properly terminated string).So one should check the value returned by strftime(), check if it is 0, and act accordingly.
Again, it is not dangerous, since the printw("%26s", mbuf) won't read after the buffer. But it may write garbage, for example after year 9999, when the expected result string is too long for the buffer.
-------------
Then in the last file, util.c, there are those macros:
#define oom_msg "\nOut of memory, press enter to try again or Ctrl-C to give up.\n"
and #define wrap_oom(f) \
which at some point does: write(2, oom_msg, sizeof(oom_msg));
This is going to emit a NUL character after the newline, because sizeof() of a string literal accounts for it. So, to stop after the newline is emitted, it should be sizeof(oom_msg)-1.