4 ms·
Work on a massive decades old software project and get ready to have your eyes opened. All the automated static and dynamic software analyzers catch only the ea
by wmt 11y ago
Work on a massive decades old software project and get ready to have your eyes opened. All the automated static and dynamic software analyzers catch only the easiest flaws, but can catch the more serious ones only if you're skilled and lucky.
Firing people for software bugs is the stupidest thing I've heard in a while. Everyone writes horrific software flaws. Everyone. The best of the best programmers just write less of them. Firing people for bugs is a job perk that will only motivate any good developers to find a less stupid employer as soon as possible.
- PhantomGremlin 11y agoAll the automated static and dynamic software analyzers catch only the easiest flaws In a 64-bit environment, at least for development purposes, why can't every single malloc() cause an allocation from new memory page(s)? Then free() removes the page(s) from accessible virtual memory. Too much overhead for production, but it would sure catch a lot of use-after-free bugs during development. Is nobody doing something like that, or is that part of what you consider "the easiest flaws"?
- yoklov 11y agoIt's been a while but I'm pretty sure the issues here only happen in extremely contrived edge cases. Not to say they aren't big deals or to downplay them, but I don't think even that would catch them reliably. Not without extremely heavy fuzzing or something.
- wmt 11y agoWait, you mean like _CRTDBG_DELAY_FREE_MEM_DF which will just mark freed blocks as freed and inaccessible? https://msdn.microsoft.com/en-us/library/5at7yxcs.aspx https://msdn.microsoft.com/en-us/library/5at7yxcs.aspx