Re: Buffer overflows
- From
René Scharfe <rene.scharfe@lsrfire.ath.cx>
- Date
- Sep 2, 2007, 17:17 UTC
- Message-ID
- <46DAF039.2000208@lsrfire.ath.cx>
- In-Reply-To
- <200709021542.31100.johan@herland.net>
Johan Herland schrieb:
Show 17 quoted lines
> So why does the discussion end there? Lukas proposed an interesting > alternative in "The Better String Library" ( > http://bstring.sourceforge.net/ ). Why has there been lots of bashing on > Timo's efforts, but no critique of bstring? I'd be very keen to know what > the git developers think of it. AFAICS, it seems to fulfill at least _some_ > of the problems people find in Timo's patches. Specifically, it claims: > > - High performance (better than the C string library) > - Simple usage > > I'd also say it's probably more widely used than Timo's patches. > > > If the only response to Timo's highlighting of string manipulation problems > in git, is for us to flame his patches and leave it at that, then I have no > choice but to agree with him in that security does not seem to matter to > us.
Well, a patch (8dabdfcc) from Alex Riesen has made it into 1.5.3 which fixes some of the problems. That's a start.
And don't forget that we have our very own string library, viz. strbuf.c, which could see more use.
That said, I agree that bstring looks well thought out. It's also quite large (lots of functions, lots of code where a bug might lurk). Hmm.
Now if only someone could demonstrate the advantages of using bstring in git by posting a nice patch.. :-P
René