3 comments

  • vlovich1231 hour ago
    Not actually confirmed as compiler bugs yet.<p>Here’s a similar bug where OpenSSL’s inline asm was wrong and probably only GCC was smart enough to try to exploit the bug:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;openssl&#x2F;openssl&#x2F;pull&#x2F;23233" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;openssl&#x2F;openssl&#x2F;pull&#x2F;23233</a><p>Same for rust - could be UB in quiche that is getting exposed.
    • account4220 minutes ago
      Can&#x27;t even find an upstream compiler bug <i>report</i> not to mention a confirmation&#x2F;patch. Doesn&#x27;t look like the compiler output was analyzed at all either, they are just going by &quot;-O3 results in valgrind warnings, -O2 doesn&#x27;t&quot;.<p>It&#x27;s not like compiler bugs are unheard of but they are rare enough that the base assumption should be that the bug is in your own code.
  • edoceo1 hour ago
    The social post links to this bug <a href="https:&#x2F;&#x2F;github.com&#x2F;curl&#x2F;curl&#x2F;issues&#x2F;23237" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;curl&#x2F;curl&#x2F;issues&#x2F;23237</a>
  • rurban24 minutes ago
    Looks like a valid new optimization to me, which only fails on valgrind, which is a bit too strict with uninitialized values. In openssl&#x27;s strlcpy. They&#x27;ll deal with that.