4 ms·
Amazing write-up. Informative and gripping in its prose.
by squidlogic 9y ago
Amazing write-up. Informative and gripping in its prose.
- saurik 9y agoThis article was an extremely long rant about "something has a if but templates are hard so I have no clue what it is". The author figured out a workaround to the issue, but we still don't know what the bug was, and the strongly worded conclusion that it is a bug in libstdc++ isn't even defended well (as this is similar to concluding "there is a bug in the compiler's code optimizer" from "I compiled my code with -O0 and it started working")... I can't really see calling this "informative" :(.
- rhaps0dy 9y agoI'm curious, what is usually the cause of code starting to work when it is compiled with -O0?
- bostik 9y agoI don't have an answer to that, but I have seen - and worked with - several codebases which work fine when compiled with -g, but will crash (in good cases) or behave irrationally (in bad cases) without. The crashing ones at least are easy. Somewhere a list or variable-argument array is missing the NULL terminator...
- tonyarkles 9y agoThis was on Windows with VC++, but same deal. The code that some cow-orkers had written was copying strings like "LAX" and "ORD" into `char airport[3]` using strcpy(). In debug builds, VC was allocating a whole 32-bit word, but in release builds it was packing everything on the stack. Write to it, and the terminating null ends up overwriting a byte of the next variable on the stack. Urgh. Of course, these were several hundred line functions, so the strcpy and the subsequent use of the trashed variable were a long ways away.
- ryl00 9y agoIn my experience, it often means variables that are used before they are initialized, or dangling pointers.
- gvb 9y ago* Optimizer bugs. Thankfully these are less common nowadays. It the "good old days" of new compilers this happened quite a bit. Embedded code: * Missing "volatiles" which allow the optimizer to optimize out "unused" loads and stores to hardware or multitasking shared variables. * Race conditions (e.g. unsynchronized access to multitasking shared variables). Making the code run slower changes the access pattern, often times obscuring the bug.
- gpderetta 9y agoCrap code that hit undefined behaviour every other line (like accessing dead temporaries or freed memory, assuming stack layout, out of bound accesses, etc.).
- ahoka 9y agoYes, I'm pretty sure the bug is not in the c++ library, but in his code.
- nickpsecurity 9y agoIt was a great, gripping write-up. It also corroborated why I told api he was better off using a subset of C or safe language that generated it for software like this. I told him there were tons of ways to analyze or make safe C subsets but almost nothing available that will get similarly great results on C++ code. This was a good example of where its complexity and style of sneaking in abstractions bit him in the ass in a way that might be easier to spot in C, Ada/SPARK, a Wirth language, etc. C++ style is safer on average but highly-robust code is better in restricted, analyzed C if not a safe language.
- api 9y ago(Original blog author here.) That's a nice idea, and we've considered "minus minus"ing the ZT core as part of an embedded port. But code like this that shleps a lot of structures around and works with JSON is eye gougingly painful to write in C and the chance of a worse and possibly exploitable memory bug is much higher. This is the first time we have encountered an actual problem with C++ compilers or runtimes.
- nickpsecurity 9y agoYou don't write those parts in C alone. You use something that shows the C is safe automatically, use tool that generates secure C from specs (eg Nail), and/ use safe language that compiles to C. This way, you get benefits of C ecosystem without risks of totally using C.