[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Android port

From: Eli Zaretskii
Subject: Re: Android port
Date: Sun, 06 Aug 2023 15:23:17 +0300

> From: Po Lu <luangruo@yahoo.com>
> Cc: Eli Zaretskii <eliz@gnu.org>,  eggert@cs.ucla.edu,  angelo.g0@libero.it,
>   emacs-devel@gnu.org
> Date: Sun, 06 Aug 2023 20:16:14 +0800
> Bruno Haible <bruno@clisp.org> writes:
> > Rationale: I cannot guarantee that Gnulib will be able to support %n
> > in the long run. The "security-aware community" are filing CVEs here and
> > there; %n is among their targets (it has already been disabled from libc
> > on Ubuntu, macOS, and MSVC); and I don't know when they will discover
> > that Gnulib still enables it.
> Then Gnulib should disregard their whims and move on.

I think what Bruno tells us is that removing %n where it is not
strictly needed is a good way of eliminating the cause for both
problems.  We may not agree with CVEs against %n, but we won't keep %n
just because we disagree, right?

reply via email to

[Prev in Thread] Current Thread [Next in Thread]