9 ms·
GCC Poison
- CJefferson 13y agoThis header would be much more useful if it suggested safe alternatives for each of the functions it poisions
- hsmyers 13y agoHas GCC got the necessary pragma foo to implement this?
- CJefferson 13y agoProbably not, but could put comments in the header?
- jheriko 13y agoone of my favourite old school tricks for achieving such breakery is: #define const_cast CONST_CAST_IS_FORBIDDEN #define dynamic_cast DYNAMIC_CAST_IS_NEVER_NECESSARY etc... its dirty, but it gets the job done
- panzi 13y agoThen I'll just use a C-style cast. :P
- jheriko 13y agodon't worry, i can't do this across /all/ code anymore - some lazy ms monkeys were unkind enough to dump dynamic casts in library headers sometime around 2008. C-style cast at least doesn't make you pay through the nose in debug time or performance overheads - even if it is easily confusing :)
- yetanotherphd 13y agoif it does, it should be called antidote.
- jevinskie 13y agoClang has "fixit"s for this but they are defined in its checker code, you can't specify custom ones in your own source/header. Though you could probably do so by writing a plugin!
- aidenn0 13y agothis site is unusable on my phone.the sidebar dominates the screen.
- tcoppi 13y agoIt works fine on chrome for android
- snogglethorpe 13y agoYeah, various Blogger themes work fine in Chrome, but break horribly in Firefox on Android. [Though even in Chrome, the performance can be pretty glacial.] My theory (based purely on using the site, mind you) is that the all the crazy dynamic display stuff in Blogger (before that, it was a much more normal/boring blogging platform) was one last hurrah before the project was relegated to "legacy barely-maintained-mode," and that it hasn't had proper testing in years... Given that, I think really the best thing would be if they come up with a way to integrate it into Google+ and retire Blogger as a platform. Hopefully they'd add some more features[1] to G+ to keep the functionality roughly equivalent and support the longer-form type of article which is more common on blogs, and keep the domain and blog identities from Blogger around as a thin skin. At least then it would be well maintained. [1] E.g. better markdown support, multiple embedded images, some sort of easier access to older articles (Blogger lets you browse by year/month), etc.
- eitland 13y agoWhich phone? (It is perfect with no sidebar on Dolphin/Note 2. Arstechnica on the other hand has been broken for a few days already.)
- aidenn0 13y agoFirefox on Kyocera Torque
- MBlume 13y agoSomewhat off-topic, but I can't use my back-button to get off this page. Can we please, please stop breaking shit that worked just fine in '95? http://motherfuckingwebsite.com/ http://motherfuckingwebsite.com/
- margaretlmarin 13y agomy classmate's sister-in-law makes $79/hr on the laptop. She has been laid off for 5 months but last month her pay was $18942 just working on the laptop for a few hours. look here....... http://www.jobs25.com http://www.jobs25.com
- hashmymustache 13y ago+1. Seriously. Is this from circular redirects? faulty browser plugin?
- yk 13y agoWhile we are at it, if a site needs tweaking of noScript settings for displaying text...
- resu_nimda 13y agoDid you seriously load 22kb of Google Analytics because you weren't strong enough to truly uphold your ideals? You piece of shit. (to prevent confusion: this is a parody of the site MBlume linked)
- ANTSANTS 13y agoSeriously, try loading the page with NoScript, and you get nothing. Apparently, it needed nearly a megabyte of JavaScript (somehow managing to make Firefox unresponsive for a several seconds on every page load) to asynchronously load a 600 word plain text article. Not the author's fault (apart from choosing to use Blogger), but wow, how do you fuck web design up that badly? It's just a blog, a few paragraphs and links to more articles, it doesn't need to be an entire fucking web app complete with 5 other useless ways to view a list of summaries (Pinterest is big right now, people love grids, right? Here, let me smack you in the face with this stupid zooming JQuery effect).
- hk__2 13y agoI’m currently doing a school project in C and we wrote a shell script to check every source file for these insecure functions. It displays a warning and suggest you a more secure alternative function.
- jhhn 13y agoGood! I had never ignored that unsafe notices from visual studio console.
- eliasmacpherson 13y agoI never liked those microsoft functions, and disable all the warnings in each new project. What are you supposed to use instead of memcpy? It's a bit of a rant but I find myself in agreement with this: http://unspecified.wordpress.com/2009/05/16/microsoft-bans-memcpy/ http://unspecified.wordpress.com/2009/05/16/microsoft-bans-m...
- aaronbrethorst 13y agomemcpy_s: http://msdn.microsoft.com/en-us/library/dswaw1wk(v=vs.80).aspx http://msdn.microsoft.com/en-us/library/dswaw1wk(v=vs.80).as... edit: I read the link you included and I have to take exception with this line: it’s a perfectly safe function if you use it properly Sure, same thing as automobiles, alcohol, condoms… Problems arise because people do not use them correctly.
- penguindev 13y agoLOL, That's a fucking joke! "If the source and destination overlap, the behavior of memcpy_s is undefined." Wow, way to improve things microsuck! It's not like anyone has ever mistakenly used memcpy on overlapping buffers....
- deleted 13y ago[deleted]
- quotemstr 13y agoYou can use memmove_s, you know.
- EpicEng 13y agoThe same is true for memcpy ya know... that's what memmove is for. Perhaps you should make sure you know what you're talking about before bashing others ("others" who are probably far more experienced than yourself).
- tedunangst 13y ago
- dfox 13y agoWhile there is probably no meaningful use for gets() (which is missing from that list and certainly is not Win32 specific) and maybe sprintf() and even more maybe strcat(), what is exactly so insecure about things like memcpy() or alloca()?
- dkersten 13y agoBuffer overflows
- tokenrove 13y agoI'm not convinced people should be writing applications in C if they can't call memcpy safely. (I say this not to downplay the many pitfalls of writing correct C, but to suggest that anyone giving less than careful consideration of the arguments to memcpy each time it is used is better off not using C at all -- we have many fine alternatives.)
- kennywinker 13y agoShort of implementing some kind of drivers license for C coders, I think this is a bad way to look at things. There will always be programs written by people who don't know about buffer overruns, or SQL injection, or just aren't thinking about security at the time because it's a trivial piece of code that "won't make it into a production environment". You can tell them they shouldn't be doing what they are doing all you want, but that doesn't fix the security problem. Fix the tools, don't blame people for using them as best they know how.
- yalue 13y agoI am actually happy that gcc doesn't find it important to support a library that prevents its users from using functions that are clearly defined in the specification of the language it supports.
- panzi 13y agoI don't understand why functions like gets and sprintf weren't removed from the standard and headers a long time ago. It can't be for legacy reasons, because removing them from the headers has no effect on binaries and when you compile source it should easy to replace gets with fgets and sprintf with snprintfe etc. These functions have no right to exist.
- finnw 13y agogets has no right to exist. But sprintf does. It's a workaround for some old embedded C compilers that lack the safe string copy functions (strcpy_s, strlcpy.) char dst[5]; sprintf(dst, "%.*s", (int)sizeof(dst)-1, "Hello!"); Copies a null-terminated string to dst, truncating if necessary to avoid overflow. Just don't forget the "." or the "-1".
- tedunangst 13y agoThat code is just as easily converted to use snprintf, and then you don't need to worry about the . Or -1.
- epsylon 13y agosnprintf is C99 IIRC. Which means legacy C89 compilers (or worse!) don't have it.
- panzi 13y agoWhich brings it back again to my initial comment: "I don't understand why functions like gets and sprintf weren't removed from the standard and headers a long time ago." And by a long time I mean before 1989 (certainly before 1999).
- MichaelMoser123 13y agoIt turns out there is a project - the safe C library - that implements strcpy_s and friends as an open source library (MIT license). so this header can be used with the Safe C library. https://sourceforge.net/projects/safeclib/ https://sourceforge.net/projects/safeclib/
- MichaelMoser123 13y agoAlso interesting: with gcc you can add the -include poison.h command line option; now the poison.h header file is included as the first include of the source file. http://linux.die.net/man/1/gcc http://linux.die.net/man/1/gcc -include file Process file as if "#include "file"" appeared as the first line of the primary source file. However, the first directory searched for file is the preprocessor's working directory instead of the directory containing the main source file. If not found there, it is searched for in the remainder of the "#include "..."" search chain as normal. If multiple -include options are given, the files are included in the order they appear on the command line.