3 ms·
I've seen people file cve requests 20 years ago with the output of "grep strcpy" as the entire report. All an llm bought to this modern version is the apologisi
by technion 3y ago
I've seen people file cve requests 20 years ago with the output of "grep strcpy" as the entire report. All an llm bought to this modern version is the apologising, arguing and hallucinated code sample.
- itishappy 3y agoAh, the time wasting bits.
- shadowgovt 3y agoIt does make one wonder why anyone still uses strcpy in an open source project if it's going to be a perpetual source of having to flag down grep-identified bug reports forever.
- flohofwoe 3y agoThe recommended strncpy() is just as bad as strcpy() because you'll end up with a string that's not zero-terminated if the length of the copied string is >= the target buffer size. strlcpy() is a better option but is neither in the C nor POSIX standard. snprintf() is also a good option since C99 but a bit overkill.
- nneonneo 3y agoThe submitter’s proposed fix does add null termination, so it does work as expected. Still, strncpy is a horrible API in general. It even has the incredibly stupid behaviour of zeroing out the entire buffer past your string, which is almost never necessary and therefore just a waste of cycles. If zeroing is needed e.g. for security, it’s always better to include an obvious and explicit memset.
- arp242 3y agoAt least those could be dismissed with almost zero effort. "You clearly didn't spend any effort in your report, so I'm not going to spend a lot of effort replying". But with this it at least looks like they spent the effort, and even though you can suspect LLM chicanery, you can never be entirely sure, especially not from the initial message.