[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: sharutils does not build with -Werror=format-security
From: |
Paul Eggert |
Subject: |
Re: sharutils does not build with -Werror=format-security |
Date: |
Sat, 12 Oct 2013 19:15:09 -0700 |
User-agent: |
Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.0 |
Bruce Korb wrote:
> That makes i18n an interesting challenge.
Yes, the assumption is that the translation libraries
are protected from tampering, just as much as the
application itself is; otherwise, one can attack
the application by supplying bogus translations.
So you're right that if FOO is safe to use as
a format string, then _(FOO) should be safe too.