Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pascal_cuoq
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
91.
▲
Do Fiddly Buffer Overruns Matter?
(blog.regehr.org)
5 points
by
pascal_cuoq
11y ago
|
0 comments
92.
▲
Asantoo: Gentoo compiled with AddressSanitizer
(wiki.gentoo.org)
3 points
by
pascal_cuoq
11y ago
|
0 comments
93.
▲
Performance anomaly on the Intel Broadwell processor
(stackoverflow.com)
4 points
by
pascal_cuoq
11y ago
|
0 comments
94.
▲
by
pascal_cuoq
11y ago
No, passing SIZE_MAX does not violate any precondition of strncat(), because preconditions are fixed properties chosen in advance, not something you add retrospectively when you feel like it. The C standard does not place any upper bound on
95.
▲
by
pascal_cuoq
11y ago
Both. “They” (and by they I do not necessarily imply a large number of engineers at Airbus, but some people who are engineers at Airbus) use CompCert and “they” also use Coq in order to finish up the correctness arguments for part of the pr
96.
▲
by
pascal_cuoq
11y ago
If there existed any possibility of an influence of the entertainment system over the controls of that model of plane, an EAD would have been published by now. EADs are public: http://www.faa.gov/aircraft/air_cert/
97.
▲
by
pascal_cuoq
11y ago
> What is 0.5f, then? Since the article is about C preprocessor expressions and it says that in that context, there can't be any of them, I would say the answer is: “not a C preprocessor expression”.
98.
▲
by
pascal_cuoq
11y ago
The article is on the difficulty of writing specifications. The fridge is a metaphor. Your insight amounts to “we can always assume that the specification has already been written and correctly implemented on the other side of the interface
99.
▲
by
pascal_cuoq
11y ago
Benchmark would not be relevant here. Souper is intended to detect missing optimizations that could have applied to LLVM code already generated by, say, Clang, and to point out new patterns to recognize and transform to the LLVM developers.
100.
▲
API Fuzzing vs. File Fuzzing: A Cautionary Tale
(blog.regehr.org)
2 points
by
pascal_cuoq
11y ago
|
0 comments
101.
▲
by
pascal_cuoq
11y ago
I have followed the Dafny language from a distance since the beginning. The Ironclad project I am just discovering, but it is everything I would expect from Microsoft: a willingness to give formal methods a chance at real use and to get val
102.
▲
by
pascal_cuoq
11y ago
Proving formal properties requires formal specifications. “absence of undefined behavior”, the property that Astrée more or less verifies, is one more or less formal piece of specification that authors of formal tools for C get for free. In
103.
▲
by
pascal_cuoq
11y ago
No. The discussion is about compiler bugs . The attack “your” solution does not apply against is if the compiler actually has a bug . Compiler have bugs, and some of these bugs cause them to silently emit the wrong assembly code for the s
104.
▲
by
pascal_cuoq
11y ago
And about the same time, Adam Langley retweeted: https://twitter.com/MSEdgeDev/status/638762308089438208 (Ending support for the RC4 cipher in Microsoft Edge and Internet Explorer 11)
105.
▲
Dropping RC4
(twitter.com)
3 points
by
pascal_cuoq
11y ago
|
1 comments
106.
▲
by
pascal_cuoq
11y ago
> guaranteed to be free of such backdoors. You are thinking of another kind of backdoor than the one being discussed. The backdooring technique being discussed relies on a compiler bug hidden in plain sight in the compiler's source
107.
▲
by
pascal_cuoq
11y ago
Reproducible builds do not solve the problem of a compiler bug being used to introduce a backdoor during the translation from source code to binary.
108.
▲
by
pascal_cuoq
11y ago
> As a side note, I think the shell script version would have been multicore friendly, at least up to six cores. That's not how the sort command, in lines 3 and 5, works.
109.
▲
by
pascal_cuoq
11y ago
Yes, it's a shame that you were not a reviewer, mid-2009, of my article published in September 2009.
110.
▲
by
pascal_cuoq
11y ago
Reference counting is a garbage-collection system like the others (and if you are going to use a garbage-collection system, you can for many usecases do better than reference counting).
111.
▲
by
pascal_cuoq
11y ago
Despite the drastic page limit in the category I was submitting in, I made sure to include a paragraph about how GC enable sharing and how the only reasonable alternative when implementing a similar system in a non-GC language is a lot of g
112.
▲
by
pascal_cuoq
11y ago
Why would a person who isn't a member of ICANN not be free to comment personally on publicly available information using as medium their personal blog?
113.
▲
by
pascal_cuoq
11y ago
A better link for tis-interpreter is http://trust-in-soft.com/tis-interpreter/ I was going to advertise it more at some point, but I just announced it here and already we are saturated with new OpenSSL tests that the i
114.
▲
by
pascal_cuoq
11y ago
This article was written to answer this exact request: http://frama-c.com/u3cat/download/CuoqICFP09.pdf
115.
▲
by
pascal_cuoq
11y ago
Xavier's first sentence states that they two operating systems have a visibly different philosophy, not that one is better than the other. The second sentence should be interpreted in the context of this first sentence: if you try to e
116.
▲
by
pascal_cuoq
11y ago
If you have references showing that formal methods are used for missiles and satellites, I would love to see them. [I work on formal methods tools and I am currently working on a usecase from the space industry, but that one is not document
117.
▲
by
pascal_cuoq
11y ago
> no, it's not allowed to just delete code that invokes undefined behaviour. I think it is.
118.
▲
by
pascal_cuoq
11y ago
StackOverflow user tmyklebu provided an efficient algorithm to solve a more general floating-point equation, C1 + x = C2, using only computations in the very floating-point system that the equation is written in: http://stackover
119.
▲
by
pascal_cuoq
11y ago
> I also don't understand the mindset behind the usage of the word "exploit" in this. See the dictionary definition a couple of comments down. It is the perfect word to use because the two points of view (“the compiler is
120.
▲
by
pascal_cuoq
11y ago
The owner of the GitHub account is not looking for a job. The owner of the GitHub account, on the other hand, speaks English and had heard the word “exploit” outside the context of infosec posturing. Definition appended for your perusal. Th
More ›