看板FB_security
标 题Re: OpenSSL static analysis, was: De Raadt + FBSD + OpenSSH + hole?
发信站NCTU CS FreeBSD Server (Thu Apr 24 21:49:24 2014)
转信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
In message <
[email protected]>,
Erik Cederstrand <
[email protected]> wrote:
>As others have pointed out, 'too hard' can also mean 'too hard' to get
>someone with commit access to actually commit the patch and accept the
>risk of introducing new bugs. Case in point: I contributed this
>one-liner patch for ZFS found by Clang Analyzer, adding the __noreturn__
>pragma you also mention:
https://www.illumos.org/issues/3363. For 1,5
>years, I have been unable to get anyone from FreeBSD or Illumos to
>commit it or even review it.
Ah! OK. That is a different sort of problem entirely, and one for which
I personally have no suggestion, nor any ready answer.
Regards,
rfg
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"