It seems like many of the code examples are incorrect in the pdf for example, figure 6b vs the file in the actual dataset experiments_dow/cwe-787/codeql-eg-PotentialBufferOverflow/Copilot -- lines are truncated at the first "%" char or something along those lines.
Argh! Thanks for spotting it! As moyix said, we were tricked by the arXiv latex cleaner tool. We've now updated this, but it will take a couple of days to clear arXiv moderation.