Re: Quick Code Audit

From: Date: Wed, 06 Sep 2000 08:22:17 +0000
Subject: Re: Quick Code Audit
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-32320@lists.php.net to get a copy of this message
Ron Chmara writes: > Are you volunteering? :-) You do a pretty good job of bull-dogging > (wrestling an issue down... it's a Rodeo term) issues... you certainly > pinned me down to exactitude, more than once.... > > Or there was that guy who flamed php-dev mightily today, he has that impersonal > ability to attack *all* the code without a friendly eye.... (in this case, > this would be a benefit, no?) > > -Bop Well, as long as it stays to attacking the *code* and not the *author*. :) That fellow seems so stuck in schoolyard tactics and willingness to slag others that I, at least, am willing to put little more stock in his mental prowess than in his emotional. I mean, he did raise valid points and all, but he also raised a lot of invalid points and threw in quite a lot of subjective detritus. Stanislav, on the other hand, at least makes points fairly and with honour (OK, I've been reading Narnia again :). Lots of people on these lists are like that. Sometimes it gets a bit rough, but today was truly exceptional. Blunt is fine--that little display of Ribbens' today is, IMHO, not. But we do need folks who are willing to say what needs to be said about security and other problems. And it's not good to hold back 'cause somebody might get hurt feelings. But it can always be alleviated to some degree. Oops--a bit OT there. Umm...security audit! Yes! But...I don't think this is really the sort of thing that can be spoken about as if the project might have an end: as long as PHP exists, it seems, the audit must continue. And it sounds like something that would fall under the umbrella of the QAT folks...or else a new group (PHP|SAT anyone? :) (Security Assessment Team). Perhaps a more formal introduction and reference on programming PHP 4 internals would be good: give folks who are writing extensions or hacking closer to the core an idea of what sorts of things to try to keep in mind, as well as a good understanding of how to best use the internal framework(s) for consistency and ease of proofreading (auditors/documentors both need to do this). Just my $0.02CDN. -- +----------------------------------------------------------------+ |Torben Wilson <torben@php.net> Netmill iTech| |http://www.coastnet.com/~torben http://www.netmill.fi| |Ph: 1 250 383-9735 torben@netmill.fi| +----------------------------------------------------------------+

« previous php.dev (#32320) next »