4 ms·
> This reminds me of the time Debian developers "knew better" with the openssh key handling... This is a totally unfair comparison. The upstream OpenSSL code w
by orra 2y ago
> This reminds me of the time Debian developers "knew better" with the openssh key handling...
This is a totally unfair comparison. The upstream OpenSSL code was broken: it was invoking undefined behaviour. Moreover, the Debian maintainer had asked upstream whether it was OK to remove the code, because it was causing Valgrind memory warnings.
- lmm 2y ago> The upstream OpenSSL code was broken: it was invoking undefined behaviour. No it wasn't. It was reading indeterminate character values, which has defined behaviour (char cannot have a trap representation). > the Debian maintainer had asked upstream whether it was OK to remove the code They hadn't asked the correct mailing list, and they only asked at all for one of the two cases where they removed similar code, which wasn't the one taht caused the problem.
- orra 2y agoReading an indeterminate value is its own undefined behaviour. See the second bottom paragraph on page 492: https://www.open-std.org/jtc1/sc22/wg14/www/docs/n1256.pdf https://www.open-std.org/jtc1/sc22/wg14/www/docs/n1256.pdf
- lmm 2y agoThat's a change in C11. It was not undefined behaviour in C99 (which was the live standard at the time).
- orra 2y agoI linked N1256, which is essentially C99 plus the errata (Tchnical Corrigendum 1, 2, & 3).
- lmm 2y agoThe standard did not state that at the time. Consider Defect Report #451 (as discussed in 2013 and 2014), and observe that the committee did not simply respond that the example therein is undefined behaviour.