GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Rich Felker (dalias@hachyderm.io)'s status on Monday, 25-Mar-2024 10:27:32 JST Rich Felker Rich Felker
    in reply to
    • Damien Miller

    @djm Have you seen the musl ones? They were sent off list but I cc'd the list & quoted on replies. All were wrong, most completely broke the functions they purported to fix. And the static analysis was erroneous.

    In conversation about a year ago from hachyderm.io permalink
    • Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Damien Miller (djm@cybervillains.com)'s status on Monday, 25-Mar-2024 10:27:33 JST Damien Miller Damien Miller
      in reply to

      @dalias we've received a few that haven't been terrible

      In conversation about a year ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Monday, 25-Mar-2024 10:27:34 JST Rich Felker Rich Felker

      Heads-up FOSS maintainers!

      There is a person sending bulk patches/PRs to FOSS projects for supposed issues "Found by RASU JSC" (not sure if that's a static analysis tool itself, or some org).

      The patches I've received are all very, VERY wrong formulatic changes, maybe even LLM-generated, doing things as stupid as replacing sprintf(s, fmt, ...) with snprintf(s, sizeof s, fmt, ...) where s has pointer type.

      If you've accepted any such patches, review carefully & possibly revert!

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: and Pleroma-tan like this.
      Haelwenn /элвэн/ :triskell: repeated this.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Monday, 25-Mar-2024 10:50:53 JST Rich Felker Rich Felker
      in reply to
      • Damien Miller

      @djm The most dangerous part is the combination of really low quality static analysis like that with authoritative sounding "this is the fix for this issue" formulatic patches.

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Monday, 25-Mar-2024 10:50:54 JST Rich Felker Rich Felker
      in reply to
      • Damien Miller

      @djm One was "this pointer is dereferenced later so return early if it's null" when the deref was conditional and not reachable if null, but where returning early made the common case completely non operational.

      In conversation about a year ago permalink
    • Embed this notice
      Amber (puppygirlhornypost@transfem.social)'s status on Tuesday, 26-Mar-2024 02:42:52 JST Amber Amber
      in reply to

      @dalias@hachyderm.io https://www.reddit.com/r/HobbyDrama/comments/nku6bt/kernel_development_that_time_linux_banned_the/ reminds me of things like supply chain attack proof of concepts. Could be part of a study, could be intentionally malicious etc.

      In conversation about a year ago permalink

      Attachments


      Haelwenn /элвэн/ :triskell: likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.