asprintf() issue
Florian Weimer
fweimer@redhat.com
Mon May 18 13:34:00 GMT 2015
On 05/14/2015 07:30 AM, Carlos O'Donell wrote:
> On 05/13/2015 01:24 PM, Joseph Myers wrote:
>> On Wed, 13 May 2015, Carlos O'Donell wrote:
>>
>>> My preference is that we set it to NULL. This will aid in debugging as any
>>> dereferences to NULL will immediately trap. Leaving the value unchanged
>>> could result in further manipulation of an invalid memory location and
>>> program corruption.
>>
>> If we do this, do we then want to
>>
>> (a) not have a new symbol version; or
>>
>> (b) have a new symbol version with the old version being an alias of the
>> new (so that new binaries that may rely on it being set to NULL don't run
>> with old glibc - similar to the symbol versioning of <fenv.h> functions
>> whose return type changed from void to int in C99 TC1, for example); or
>>
>> (c) have a new symbol version with the old version not changing *ptr on
>> error?
>
> IMO we should be conservative and do (c), and document in NEWS, Release wiki
> page, and hopefully the manual.
I don't think this is worth the cost. (Even such little changes add up
and eventually impact linking time and code size.) It does not even fix
a bug, and application code can easily set *ptr to NULL before calling
asprintf, to get uniform behavior across all known implementations (if
that simplifies application code).
So it turns out the asprintf manual pages is correct as-is, because the
manual pages have a tendency to describe more than just current GNU libc
behavior.
--
Florian Weimer / Red Hat Product Security
More information about the Libc-alpha
mailing list