Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pascal_cuoq
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
pascal_cuoq
8y ago
There is no reason to estimate the required precision as 3 times the original precision, because floating-point addition does not work like that. If you want to compute the exact result of a floating-point addition, you need approximately e
62.
▲
by
pascal_cuoq
8y ago
I cannot tell you if it is the solution they chose, but the fastest known implementation for single-precision FMA using double-precision multiplication and addition on conventional hardware is to use “round-to-odd” for the intermediate resu
63.
▲
by
pascal_cuoq
8y ago
double-double or quad precision is necessary to emulate double-precision FMA. The article is talking about emulating single-precision FMA with double-precision. The relevant paragraph is: > Luckily the vast majority of floating-point mat
64.
▲
by
pascal_cuoq
8y ago
Bruce Dawson always does an excellent job of explaining subtle floating-point behaviors simply, but there is one sentence I do not agree with in this particular post: > However, for any rounding rule that you might come up with there is
65.
▲
by
pascal_cuoq
8y ago
And if we are talking about several gorillas, they guard they're bananas. It makes sense now, thanks.
66.
▲
by
pascal_cuoq
8y ago
“bugs”
67.
▲
by
pascal_cuoq
8y ago
The reverse argument also works: using HTTPS may lead you to link and expose, say, OpenSSL where you otherwise would not have needed to. OpenSSL has had dozens of vulnerabilities in the past: https://www.openssl.org/news
68.
▲
by
pascal_cuoq
8y ago
> What a dumb gamble, even if he was trying to get laid, the risk/reward just doesn't make sense in the context. What risk are you thinking of? There has been no consequence for him that I can see. He correctly assessed that th
69.
▲
by
pascal_cuoq
8y ago
You should contact them[1]. TrustInSoft has a document that matches the classes of defects that its analyzer can guarantee the absence of to the vocabulary and recommendations of EN 50128. If you are preoccupied by this standard in particul
70.
▲
by
pascal_cuoq
8y ago
I was more thinking of the case where >2GiB strings are not useful for normal use and the programmer does not anticipate them, but a malicious user can cause such strings to happen, for instance by sending them over the network in minute
71.
▲
by
pascal_cuoq
8y ago
Yes. “snprintf(dest, sizeof dest, "%s", src);” where dest is a char array almost is the programmer-friend version of strncpy() that does exactly what one would expect, neither more nor less. It always does '\0'-termina
72.
▲
by
pascal_cuoq
9y ago
It would only matter to cryptographic code if an implementation somehow used floating-point, but the source-level conversion from floating-point to unsigned integer can also leak information in execution time when translated to x86 code: h
73.
▲
by
pascal_cuoq
9y ago
I would advise against making educated guesses about the result of overflow in the conversion from floating-point to integer: http://blog.frama-c.com/index.php?post/2013/10/09/Overflow-f... Note: the opt
74.
▲
by
pascal_cuoq
10y ago
You are correct, but the screen's last two lines of text required some tricks to take advantage of (search for “reserved” in http://www.tebbo.com/archive/pw810601.htm ), so “64x44” is also a correct description fr
75.
▲
by
pascal_cuoq
10y ago
Since I have it at hand, here is a list of examples of how compilers are broken if an array is larger than SIZE_MAX / 2 (which is called PTRDIFF_MAX in the post): http://trust-in-soft.com/objects-larger-than-ptrdiff_max
76.
▲
by
pascal_cuoq
10y ago
https://en.wikipedia.org/wiki/Superfish “On February 20, 2015, Microsoft released an update for Windows Defender which removes Superfish.” Microsoft has to uninstall the malware that Lenovo had put on the computers it
77.
▲
by
pascal_cuoq
10y ago
> I don't see how getting rid of the ME helps. If you don't trust Intel then you don't trust Intel. As dandelion_lover says, security is not boolean. I may or I may not trust Intel to backdoor the processor I run code of m
78.
▲
by
pascal_cuoq
10y ago
> In short, if you think it's so easy to do, feel free to fix it. Naturally. The GCC developers have not documented their choices; what GCC actually does is fuzzy enough that a GCC developer who actually worked on the implementation
79.
▲
by
pascal_cuoq
10y ago
> First, this is not undefined, so you are going to need to find another example :) This example will do just fine, in fact. It is arguably not undefined, as you say. It is also silently miscompiled by both Clang and GCC. https:/&#
80.
▲
by
pascal_cuoq
10y ago
tis-interpreter does not detect strict aliasing violations yet. An analysis for exactly that is being worked on, and it will warn on this example, but this is a minefield of ambiguous specification by the standard, compiler practices that s
81.
▲
by
pascal_cuoq
10y ago
Just a small remark, on any platform that has 32-bit integer types and 64-bit integer types and nothing in between, regardless of how these are mapped to int/long/long long, 0x81000000 is an unsigned integer. You can see the C11 r
82.
▲
by
pascal_cuoq
10y ago
You are right. Either I was thinking of another comment by Derek Jones (one of the two persons I know on the C standardization committee, which is otherwise quite opaque) or I projected my own image of a patiently malevolent committee on th
83.
▲
by
pascal_cuoq
10y ago
On the other hand, using nonstandard extensions makes it harder to move away from a compiler the direction of which you are not happy with, and can make your situation worse in the long term.
84.
▲
by
pascal_cuoq
10y ago
This post, written by someone who is or has been on the standardization committee gives a different point of view: http://shape-of-code.coding-guidelines.com/2014/08/31/undefi... What always surprises me is t
85.
▲
by
pascal_cuoq
11y ago
On the density of SQLite's tests, Hwaci owns a test suite with MC/DC coverage[1][2], that Richard kindly loaned to John for this experiment. MC/DC coverage is used as a criterion for safety-critical software testing. Before h
86.
▲
by
pascal_cuoq
11y ago
I'm not sure what in the article gave you the impression that Richard Hipp doesn't have a strong, positive opinion about fixing undefined behavior in SQLite. He has patiently fixed all the issues that were straightforward to fix.
87.
▲
by
pascal_cuoq
11y ago
Because malloc() can signal failure to allocate by returning a null pointer. VLAs make it impossible to handle a failure to allocate: there is no interface to indicate what the program should do when it happens. You can only follow the decl
88.
▲
The Strict Aliasing Situation Is Pretty Bad
(blog.regehr.org)
150 points
by
pascal_cuoq
11y ago
|
67 comments
89.
▲
by
pascal_cuoq
11y ago
6.5:6 is certainly not saying that malloced memory always aliases with “everything”. Quite the contrary, it says that malloced memory cannot be used for type-punning. The following works and is idiomatic: uint32_t u; float f = …; memcpy(&am
90.
▲
by
pascal_cuoq
11y ago
> The correct way of accessing a variable like that is trough an union. It's funny you should say that, because people have been taking the exact opposite viewpoint for years: “union do not allow type-punning because it was only cla
More ›