[#57574] [ruby-trunk - Feature #8976][Open] file-scope freeze_string directive — "akr (Akira Tanaka)" <akr@...>

70 messages 2013/10/02

[#57579] [ruby-trunk - Feature #8977][Open] String#frozen that takes advantage of the deduping — "sam.saffron (Sam Saffron)" <sam.saffron@...>

25 messages 2013/10/02

[#57679] [ruby-trunk - Feature #8987][Open] map/collect extension which handles arguments — "sowieso (So Wieso)" <sowieso@...>

16 messages 2013/10/05

[#57705] [ruby-trunk - Feature #8992][Open] Use String#freeze and compiler tricks to replace "str"f suffix — "headius (Charles Nutter)" <headius@...>

43 messages 2013/10/07

[#57727] [ruby-trunk - Feature #8998][Open] string keys for hash literals should use fstrings — "normalperson (Eric Wong)" <normalperson@...>

17 messages 2013/10/08

[#57771] [ruby-trunk - Bug #9008][Open] TestProcess#test_clock_getres_constants and TestProcess#test_clock_gettime_constants fails on ARM — "vo.x (Vit Ondruch)" <v.ondruch@...>

15 messages 2013/10/09

[#57888] [ruby-trunk - Feature #9025][Open] Clarify the error message when calling a method with the wrong number of arguments — Nerian (Gonzalo Rodríguez) <siotopo@...>

11 messages 2013/10/15

[#57993] [ruby-trunk - Feature #9047][Open] Alternate hash key syntax for symbols — "jamonholmgren (Jamon Holmgren)" <jamon@...>

13 messages 2013/10/23

[#58007] [ruby-trunk - Feature #9049][Open] Shorthands (a:b, *) for inclusive indexing — "mohawkjohn (John Woods)" <john.o.woods@...>

25 messages 2013/10/24

[#58033] [ruby-trunk - Bug #9053][Open] SSL Issue with Ruby 2.0.0 — "tisba (Sebastian Cohnen)" <ruby-lang@...>

16 messages 2013/10/25

[#58080] [ruby-trunk - Feature #9064][Open] Add support for packages, like in Java — "rosenfeld (Rodrigo Rosenfeld Rosas)" <rr.rosas@...>

23 messages 2013/10/30

[ruby-core:57934] Re: strlen and strnlen in Ruby

From: Eric Wong <normalperson@...>
Date: 2013-10-18 17:22:16 UTC
List: ruby-core #57934
Edward Ocampo-Gooding <edward@edwardog.net> wrote:
> (I’ve been dogmatically following the advice of my elders to favour
> strncpy whenever possible since it’s easy to run into security issues
> or accidentally feeding a non-null-byte-terminated string in and
> having the program crash or worse yet, use the result without
> checking.)

strncpy is wrong in many cases used since it pads with trailing zeros.
AFAIK strncpy is a historical artifact from an ancient database format.

There's also strlcpy from OpenBSD.  strlcpy is safe as far as crashes
go, but silently truncating data leads to other problems.

So memcpy is preferable for correctness, and heavily-used in Ruby
already since the length of Ruby strings is known.

I haven't taken the time to audit the existing uses of str*cpy in Ruby,
but I suspect many are for convenience and non-critical paths..

In This Thread

Prev Next