看板 FB_security 關於我們 聯絡資訊
--ibTvN161/egqYuK8 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2011-Dec-19 22:01:04 +0200, Kostik Belousov <kostikbel@gmail.com> wrote: >On Mon, Dec 19, 2011 at 11:54:46AM -0800, Xin LI wrote: >> It doesn't seem to me that this proposed change would do something >> with security? rtld is a fairly critical part of FreeBSD infrastructure and there have been several instances where rtld changes have resulted in security vulnerabilities. >I also think that UTRACE part is not bad, but will object against the >LD_PRINT_ERROR part. Could you please explain your objections to the LD_PRINT_ERROR part as I don't see an immediate problem with them. > FWIW, it should use rtld_printf() instead of printf(), >but this is moot point. Accepted. On 2011-Dec-19 21:02:49 +0100, Cl=E9ment Lecigne <clemun@gmail.com> wrote: >Dont know but the ld_printerror !=3D '\0' in the patch should be >*ld_printerror !=3D '\0', no? Oops, my mistake. Yes, there is a missing '*'. --=20 Peter Jeremy --ibTvN161/egqYuK8 Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.18 (FreeBSD) iEYEARECAAYFAk7vvGsACgkQ/opHv/APuIdG6wCdGygpY20erwvO4y2hSU4r2kTY lQYAn20Es5yqn6DFeX+ShnRbFn4qXwdn =HgJA -----END PGP SIGNATURE----- --ibTvN161/egqYuK8--