This is the mail archive of the libc-alpha@sourceware.org mailing list for the glibc project.
Index Nav: | [Date Index] [Subject Index] [Author Index] [Thread Index] | |
---|---|---|
Message Nav: | [Date Prev] [Date Next] | [Thread Prev] [Thread Next] |
Other format: | [Raw text] |
On 02/11/2018 08:32 PM, Zack Weinberg wrote:
With my security hat on, I would like glibc to define as many cases of undefined behavior as possible -- as prompt, guaranteed crashes. Defining the behavior as anything else leads to people relying on whatever the definition is, but leaving it as "whatever the code happens to do"_also_ leads to people relying on the actual behavior, plus it leaves room for exploits.
But in the case of strtok, the more relevant undefined behavior is that it's not thread-safe. There's a fairly large number of libraries which reference both pthread_create and strtok, which is rather sad.
Thanks, Florian
Index Nav: | [Date Index] [Subject Index] [Author Index] [Thread Index] | |
---|---|---|
Message Nav: | [Date Prev] [Date Next] | [Thread Prev] [Thread Next] |