git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Buffer overflows

From
Simon 'corecode' Schubert <corecode@fs.ei.tum.de>
Date
Aug 31, 2007, 12:48 UTC
Message-ID
<46D80E39.8060106@fs.ei.tum.de>
In-Reply-To
<BD9F3FD0-94EF-4182-A03B-B26B18544894@wincent.com>
Wincent Colaiuta wrote:
Show 8 quoted lines
>> As an example, do your safe API do null pointer checks. This is
>> because strcpy, strlen and the like don't, which is one of the reasons
>> why they are considered unsafe. But then, if you guarantee that you
>> are not passing a null pointer to one of these API, why take the hit
>> of the additional checks when you know that these are safe.
> Do you really think that comparing a pointer to NULL is going to be a 
> speed hit? I would imagine that on most architectures it boils down to 
> one or two machine code instructions.
The question rather is, why should you bother comparing to a NULL pointer?  To return an error (EINVAL?)?  I'd rather have either a) the caller check or b) the process segfault.  A segfault gives me a nice core file which I can use to hunt the bug.
I also don't see why not checking for NULL pointers is unsafe.  Okay, maybe there are platforms out there which do not crash on a NULL pointer derefence, but I doubt these are consumers of git.  All other platforms are safe by the implicit check of the MMU.
The worst thing is something like
if (ptr == NULL)
	abort();
which only adds code (and thus needs maintenance), but no value whatsoever.  Either the following code tolerates NULL pointers or it will crash and segfault, so why bother panicing before.
Of course I might be totally of track...
cheers
  simon
Previous: Wincent ColaiutaNext: Junio C Hamano
Message 9 of 26 in “Buffer overflows”
  1. Timo SirainenAug 30, 2007
  2. Lukas SandströmAug 30, 2007
  3. Linus TorvaldsAug 30, 2007
  4. Timo SirainenAug 30, 2007
  5. Reece DunnAug 30, 2007
  6. Timo SirainenAug 30, 2007
  7. Reece DunnAug 30, 2007
  8. Wincent ColaiutaAug 31, 2007
  9. Simon 'corecode' SchubertAug 31, 2007
  10. Junio C HamanoAug 30, 2007
  11. Pierre HabouzitAug 30, 2007
  12. Timo SirainenAug 30, 2007
  13. Johan HerlandSep 2, 2007
  14. Reece DunnSep 2, 2007
  15. David KastrupSep 2, 2007
  16. Reece DunnSep 2, 2007
  17. Jakub NarebskiSep 3, 2007
  18. Junio C HamanoSep 3, 2007
  19. René ScharfeSep 2, 2007
  20. Lukas SandströmSep 2, 2007
  21. Linus TorvaldsAug 31, 2007
  22. Timo SirainenAug 31, 2007
  23. Andreas EricssonAug 31, 2007
  24. Johannes SchindelinAug 31, 2007
  25. Temporary fix for stack smashing in mailinfoAlex Riesen, Aug 30, 2007
  26. Junio C HamanoAug 30, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.