|
From: | Florian Weimer |
Subject: | Re: Document hardening flags in the coding standards |
Date: | Mon, 09 Jul 2012 10:51:47 +0200 |
User-agent: | Mozilla/5.0 (X11; Linux x86_64; rv:13.0) Gecko/20120605 Thunderbird/13.0 |
On 07/07/2012 12:27 AM, Karl Berry wrote:
They turn bugs which would result in code execution into mere crashers (most of the time). Sure sounds good. I passed that on to rms.
Thanks. I've sent him a more verbose explanation he requested.
Your reply made me think that you wanted to put, not just more-or-less informal advice and information, but the full reference documentation for the features in the coding standards. For example, that node does not describe POSIX signals or what O_EXCL does, it just says using them is good.
I see. I think we're in roughly on the same page. -- Florian Weimer / Red Hat Product Security Team
[Prev in Thread] | Current Thread | [Next in Thread] |