Ancestors

Toot

Written by Even Rouault on 2025-01-11 at 14:01

How reasonable it is to try to replace > 600 calls to a couple functions that are potentially dangerous (maybe 1% of them are in practice) by calls to their safe versions...

=> More informations about this toot | More toots from EvenRouault@mastodon.social

Descendants

Written by Javier Jimenez Shaw on 2025-01-11 at 15:25

@EvenRouault how big/bad is the danger?

=> More informations about this toot | More toots from jjimenezshaw@mapstodon.space

Written by Even Rouault on 2025-01-11 at 15:28

@jjimenezshaw Read heap-buffer-overflow (maybe write too ?). so potentially security sensitive . That kind of thing: https://github.com/OSGeo/gdal/pull/11638

=> More informations about this toot | More toots from EvenRouault@mastodon.social

Written by Javier Jimenez Shaw on 2025-01-11 at 15:56

@EvenRouault 😕 it doesn't look good.

And somebody will complain sooner or later.

I hate the black magic manipulating char* variables. It performs better, I know (how much is another discussion). But playing with magic is dangerous.

=> More informations about this toot | More toots from jjimenezshaw@mapstodon.space

Written by Javier Jimenez Shaw on 2025-01-11 at 16:01

@EvenRouault is your PR enough to fix it?

=> More informations about this toot | More toots from jjimenezshaw@mapstodon.space

Written by Even Rouault on 2025-01-11 at 16:11

@jjimenezshaw No, that's just the appetizer of the appetizer (https://github.com/OSGeo/gdal/pull/11639). The later covering maybe 20% of the changes to fix everything... ? RFC in progress...

=> More informations about this toot | More toots from EvenRouault@mastodon.social

Written by Pirmin Kalberer on 2025-01-11 at 16:19

@EvenRouault So it's only 6 to replace, sounds easy!

=> More informations about this toot | More toots from implgeo@mapstodon.space

Written by Even Rouault on 2025-01-11 at 16:31

@implgeo Yes, thanks for volunteering helping doing the replacement in the whole code base 😜

=> More informations about this toot | More toots from EvenRouault@mastodon.social

Written by Ian Turton on 2025-01-11 at 18:10

@EvenRouault @implgeo sounds like an easy sed job 😁

=> More informations about this toot | More toots from ianturton@fosstodon.org

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113810085051265811
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
287.254188 milliseconds
Gemini-to-HTML Time
1.537284 milliseconds

This content has been proxied by September (3851b).