We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.
We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.
Firing people for software bugs is the stupidest thing I've heard in a while. Everyone writes horrific software flaws. Everyone. The best of the best programmers just write less of them. Firing people for bugs is a job perk that will only motivate any good developers to find a less stupid employer as soon as possible.
In a 64-bit environment, at least for development purposes, why can't every single malloc() cause an allocation from new memory page(s)? Then free() removes the page(s) from accessible virtual memory.
Too much overhead for production, but it would sure catch a lot of use-after-free bugs during development. Is nobody doing something like that, or is that part of what you consider "the easiest flaws"?
This comment was heavily voted down a day or so ago (not by me, I voted it up). But just now I'm reading about yet another zero-day, this time against Java.
So the question is, when are we going to get disgusted, sick and tired of all this sloppy code? When will "heads will roll for this" revert to being a meaningful punishment instead of just a historic cliche?
Enough is enough! If there are no consequences there will be no improvement.