[tz] localtime.c patch

Paul Eggert eggert at cs.ucla.edu
Wed Oct 8 18:24:28 UTC 2014


On 10/08/2014 06:20 AM, Christos Zoulas wrote:
> I prefer not to return random bits from the heap to the user.

On my platform a timezone_t struct has 25488 bytes, and clearing them 
all would take a bit of time.  Since the user can look at the heap 
anyway, clearing the bits wouldn't add security.

> There were other NetBSD changes that were
> not carried forward, and perhaps they should

Thanks, the attached proposed patch should address those issues. I've 
left the issue of documenting return and errno values for another day.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-Fix-EOVERFLOW-related-problems-noted-by-Chistos-Zoul.patch
Type: text/x-patch
Size: 4485 bytes
Desc: not available
URL: <http://mm.icann.org/pipermail/tz/attachments/20141008/175c2a9a/attachment.bin>


More information about the tz mailing list