Re: OpenSSL static analysis, was: De Raadt + FBSD + OpenSSH + ho
On 23 April 2014 02:12, Ronald F. Guilmette <rfg@tristatelogic.com> wrote:
>
> In message <20140423010054.2891E143D098@rock.dv.isc.org>,
> Mark Andrews <marka@isc.org> wrote:
>
>>As for the number of CLANG analysis warnings. Clang has false
>>positives
>
> Please define your terms.
>
> I do imagine that the truth or falsehood of your assertion may depend
> quite substantally on what one does or does not consider a "false
> positive" in this context.
>
>>some of which are impossible to remove regardless of how
>>you recode the section...
>
> I, for one, would dearly love to see one or more concrete examples
> which purport to support the above assertion (of which I am dubious).
So try wading through the morass of false positives yourself and
discover what a joy it is for yourself.
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
討論串 (同標題文章)
完整討論串 (本文為第 7 之 49 篇):