4 ms·
Wait a second, this is not domain name. This is an IP address, it is 46 bytes maximum. Thanks for posting this, but I don't see any issue with this.
by indutny 11y ago
Wait a second, this is not domain name. This is an IP address, it is 46 bytes maximum. Thanks for posting this, but I don't see any issue with this.
- vardump 11y agoWell, you should still range check it. If someone manages to [un]intentionally corrupt bud_client_s.remote.(unsigned int)host_len, it's not secure, it will become a stack overwrite. Defensive programming like that is a very good idea especially for something network facing. If you're sure it's always at most 46 bytes, make it 48 bytes and specify "#define BUD_MAX_HOST_IP_LEN (48)". Very secure and compiler will probably replace those memcpys with a few SSE [1] instructions, because 48 is a multiply of 16. Copying 48 bytes is always much faster than copying 1 byte with a dynamic length argument for memcpy. [1]: Like 6x MOVDQU instructions. Probably interleaved with the rest of the code to hide latency.
- indutny 11y agoGreat feedback! I wonder if you might be interested in contributing this to bud? This thing will be very valuable addition!
- vardump 11y agoWriting networking code in C/C++ is very stressful, for safety and security reasons. I write enough safety critical C/C++ at my day job. If bud was my own pet project, I'd write it in Golang, which is great for networking code. The software I've written so far in Golang has been rock solid, with practically zero defects, in addition to being very understandable and readable code for other people. I wish I could say same of C/C++... Or maybe in Rust to get a better hang of it. I think Rust will eventually capture a lot of C/C++'s "market share". It should be feasible to write firmware, operating systems and device drivers in Rust.