From mboxrd@z Thu Jan 1 00:00:00 1970 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on inbox.vuxu.org X-Spam-Level: X-Spam-Status: No, score=-3.3 required=5.0 tests=MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED,RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL autolearn=ham autolearn_force=no version=3.4.4 Received: (qmail 7330 invoked from network); 9 Dec 2020 16:37:50 -0000 Received: from mother.openwall.net (195.42.179.200) by inbox.vuxu.org with ESMTPUTF8; 9 Dec 2020 16:37:50 -0000 Received: (qmail 3991 invoked by uid 550); 9 Dec 2020 16:37:42 -0000 Mailing-List: contact musl-help@lists.openwall.com; run by ezmlm Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-ID: Reply-To: musl@lists.openwall.com Received: (qmail 3970 invoked from network); 9 Dec 2020 16:37:41 -0000 Date: Wed, 9 Dec 2020 11:37:29 -0500 From: Rich Felker To: musl@lists.openwall.com Message-ID: <20201209163728.GL534@brightrain.aerifal.cx> References: <20201208193919.GA5522@spindle.one-eyed-alien.net> <20201208195327.GJ534@brightrain.aerifal.cx> <20201208224454.GB5522@spindle.one-eyed-alien.net> <20201208225717.GK534@brightrain.aerifal.cx> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.21 (2010-09-15) Subject: Re: [musl] out-of-bounds reads in strstr On Wed, Dec 09, 2020 at 09:54:51AM +0300, Alexander Monakov wrote: > On Tue, 8 Dec 2020, Rich Felker wrote: > > > > That being said. I'm still confused by the comment in strstr. `l | 63` > > > is closer to `MAX(l,63)` than `MIN(l,63)`. > > > > Yes, the comment is wrong. The point is just to scan at least l bytes > > forward for the end of the haystack (since we'll need that many > > immediately) and at least some decent minimum to avoid doing it over > > and over if the needle is short. But there's no need for it to be > > precise. > > It's not the first time this comes up. I suspect you'd save more time > correcting the misleading comment instead of responding to each inquiry > individually. Thanks for poking me again about this. Will do. Rich