git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Buffer overflows

From
René Scharfe <rene.scharfe@lsrfire.ath.cx>
Date
Sep 2, 2007, 17:17 UTC
Message-ID
<46DAF039.2000208@lsrfire.ath.cx>
In-Reply-To
<200709021542.31100.johan@herland.net>
Johan Herland schrieb:
Show 17 quoted lines
> So why does the discussion end there? Lukas proposed an interesting 
> alternative in "The Better String Library" ( 
> http://bstring.sourceforge.net/ ). Why has there been lots of bashing on 
> Timo's efforts, but no critique of bstring? I'd be very keen to know what 
> the git developers think of it. AFAICS, it seems to fulfill at least _some_ 
> of the problems people find in Timo's patches. Specifically, it claims:
> 
> - High performance (better than the C string library)
> - Simple usage
> 
> I'd also say it's probably more widely used than Timo's patches.
> 
> 
> If the only response to Timo's highlighting of string manipulation problems 
> in git, is for us to flame his patches and leave it at that, then I have no 
> choice but to agree with him in that security does not seem to matter to 
> us.

Well, a patch (8dabdfcc) from Alex Riesen has made it into 1.5.3 which fixes some of the problems. That's a start.

And don't forget that we have our very own string library, viz. strbuf.c, which could see more use.

That said, I agree that bstring looks well thought out. It's also quite large (lots of functions, lots of code where a bug might lurk). Hmm.

Now if only someone could demonstrate the advantages of using bstring in git by posting a nice patch.. :-P

René
Previous: Junio C HamanoNext: Lukas Sandström
Message 19 of 26 in “Buffer overflows”
  1. Timo SirainenAug 30, 2007
  2. Lukas SandströmAug 30, 2007
  3. Linus TorvaldsAug 30, 2007
  4. Timo SirainenAug 30, 2007
  5. Reece DunnAug 30, 2007
  6. Timo SirainenAug 30, 2007
  7. Reece DunnAug 30, 2007
  8. Wincent ColaiutaAug 31, 2007
  9. Simon 'corecode' SchubertAug 31, 2007
  10. Junio C HamanoAug 30, 2007
  11. Pierre HabouzitAug 30, 2007
  12. Timo SirainenAug 30, 2007
  13. Johan HerlandSep 2, 2007
  14. Reece DunnSep 2, 2007
  15. David KastrupSep 2, 2007
  16. Reece DunnSep 2, 2007
  17. Jakub NarebskiSep 3, 2007
  18. Junio C HamanoSep 3, 2007
  19. René ScharfeSep 2, 2007
  20. Lukas SandströmSep 2, 2007
  21. Linus TorvaldsAug 31, 2007
  22. Timo SirainenAug 31, 2007
  23. Andreas EricssonAug 31, 2007
  24. Johannes SchindelinAug 31, 2007
  25. Temporary fix for stack smashing in mailinfoAlex Riesen, Aug 30, 2007
  26. Junio C HamanoAug 30, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.