Half of curl’s vulnerabilities are C mistakes
daniel.haxx.se
daniel.haxx.se
Perhaps related, does anyone know of an overlay-type application that allows me to colorpick part of the screen (on linux)? My current solution is usually to screenshot and open the image in the GIMP or similar, but it's very cumbersome and especially if there are multiple pictures usually not worth it.
Buffer overread: 22 Buffer overflow: 20 Use After Free: 4 Double Free: 3 NULL mistake: 2
I'm not aware of any colour disabilities that I have but I found it difficult to parse the colours as well, specifically in the second pie chart (areas). The colours in the chart only work to distinguish one slice from its neighbours, it's near impossible to map them to the categories listed in the legend. Perhaps the author is working on a super-colour-accurate computer screen where this problem isn't as noticeable, but on my older screens these colour profiles are near useless.
If you're in Firefox, you can find a colour picker in the dev tools (top left of the "inspect element" tab). That mostly focuses on devs though, so all you get is HTML colour hex.
But it doesn't matter for this article, author puts values in descending order for the labels so you dont really need colours.
Better yet if they put the values next to the label name too, but we can have it all.
I also recommend Color Oracle for testing:
EDIT: I see what you’re saying now. You can just read the legend, which lists things in order. But that just gives the ordering, not the sizes of the categories.
Where I like this approach is with big line charts like this one [2] (here it's D3 that's used). I am colorblind, and also not good at following things in general (I can have a hard time counting sequences of similar numbers), and I find charts made this way easier to read.
[1]: https://www.chartjs.org/docs/latest/charts/doughnut.html
Every piechart can be turned into a barchart that communicates the findings in a much clearer way.
No C vulnerabilities at all
There was a blog post a while back where he more or less said "I am being paid to add Rust".
A rewrite would introduce new bugs, even if they aren't memory issues. The rewrite could end up buggier than the original.
https://daniel.haxx.se/blog/2016/11/14/i-have-toyota-corola/
I love using Rust for new development but curl is _everywhere_ and a port would need to spend a lot of time copying old quirks. Given how clunky C APIs are, I’d think it’d be better to migrate more of the callers to a higher-level interface anyway.
Defaults matter.
P.D: Think if web browser were not fixed or improved because maybe somebody is using Win95. Its the same. The path to better is stop using what is proven to be bad (C/C++ is proven to be very bad!). The path to make sure niche platforms are covered is turn what is better in something more popular until it replace the old... and niche platforms use it...
This is called progress. Is how its done.
OTOH, a rewrite could be useful in splitting up the problem-space as well as reducing errors. This is where Ada excels, and one nice way of splitting the problem-space could be in providing types (perhaps with provable properties via SPARK) that properly decompose the problem-space.
-- Small, quick/dirty "back-of-napkin" design.
Package Uniform_Resource_Locator is
Type Protocol is (HTTP, HTTPS, FTP, SFTP, ETC );
Type URL is private;
Function Get_Protocol(Object : URL) return Protocol;
-- other operations.
Function Parse(Text : String) return URL; -- Text to URL.
Function "+"(Object : URL) return String; -- URL to Text.
Private
Type URL is record
--...
end record;
End Uniform_Resource_Locator;
> The rewrite could end up buggier than the original.Given the properties of a language like Ada, you could decompose the problem-space into types (like above) and leverage the language properties to ensure the correctness of the program. For example, Ada mandates full-coverage on cases can so when you say `case Get_Protocol(The_URL) is ...` you have to provide for every value in the enumeration (Protocol here), and the compiler enforces this. So, every place you have a case-statement operating on a Protocol value, absent the `others` option, the compiler will error-out and point you to the location you're missing a value.
...meaning that you can update the Protocol enumeration and have the compiler complain at every location you need to fix/implement the new protocol.