|
|
Subscribe / Log in / New account

Lack of documentation

Lack of documentation

Posted May 19, 2008 20:56 UTC (Mon) by brinkmd (guest, #45122)
Parent article: Debian, OpenSSL, and a lack of cooperation

The *real* problem with the code in question is that it was poorly documented.  If you have to
go and ask upstream to understand the security implications of the patch, you have already
lost.  Two identical lines of code were used in the program in two very different contexts,
and the effect of the code relied on external factors (namely caller-provided buffer data),
that was not documented at that particular part of the code.  Code quality is a big issue for
maintainability.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds