On Wed, 29 Dec 2010, Alan Barrett wrote:
On Wed, 29 Dec 2010, Joerg Sonnenberger wrote:I don't know where "len" comes from, but bad things will happen if len > sizeof(b)....which is exactly the intention here, isn't it?You are probably right. I think that there should be comments explaining that the purpose of the code is to test how buffer overflows are handled.
The code is located in
        src/tests/lib/libc/ssp/
            ^^^^^          ^^^
-------------------------------------------------------------------------
| Paul Goyette     | PGP Key fingerprint:     | E-mail addresses:       |
| Customer Service | FA29 0E3B 35AF E8AE 6651 | paul at whooppee.com    |
| Network Engineer | 0786 F758 55DE 53BA 7731 | pgoyette at juniper.net |
| Kernel Developer |                          | pgoyette at netbsd.org  |
-------------------------------------------------------------------------