Free Republic
Browse · Search
General/Chat
Topics · Post Article

Interesting albeit it light read..
1 posted on 05/10/2006 8:52:50 AM PDT by N3WBI3
[ Post Reply | Private Reply | View Replies ]


To: N3WBI3; ShadowAce; Tribune7; frogjerk; Salo; LTCJ; Calvinist_Dark_Lord; amigatec; Fractal Trader; ..

OSS PING

2 posted on 05/10/2006 8:53:32 AM PDT by N3WBI3 ("I can kill you with my brain" - River Tam)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: N3WBI3
I've seen some articles about their methods that aren't entirely flattering. It's an interesting report, in that their reports point up code that can be cleaned up a bit. I don't know if Coventry has found any exploitable code before. Wouldn't me particularly suprised if they had, but I can't recall offhand if that is the case.

 You might be interested in the following Link sent to me by a co-worker today regarding "ESX Server Modified Source" at VMware considering the discussion we had about this a month or so ago.

I haven't had a chance to look at exactly what it includes closely, especially in light of a page I'd found on their site after much digging that stated the ESX kernel was something of their own making, rather than being a Linux derivative. Perhaps it's just a kernel tuned for running in a VMWare container or something. Just thought I'd pass it along.

3 posted on 05/10/2006 9:31:06 AM PDT by zeugma (Come to the Dark Side... We have cookies!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: N3WBI3
Coverity catches some bugs that automatic analysis can get, from tracking data and code flow. Some of its complaints aren't bugs at all, just the result of code flow that is, perhaps intentionally in the case of some performance critical code paths, too obscure for it to track.

Almost none of the really interesting, or really dangerous, bugs are caught by it, and while it reports alot of bugs (kind of a nuiscance) few of them are more than mildly interesting.

Unlike 'real' bugs that start with a symptom - such as the system generates an error if such-and-such is done, Coverity bugs start with the specific code complaint, such as this variable doesn't seem to be initialized before use on this code path. This makes Coverity bugs less useful, because one can't see what, if any, impact that alledged bug has on actual system behaviour, and so can't really tell what is the severity of the bug or the impact of the change.

4 posted on 05/10/2006 11:43:43 AM PDT by ThePythonicCow (We are but Seekers of Truth, not the Source.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: N3WBI3

Why is the government spending our tax dollars on this?

Isn't the open source community supposed to be doing this on their own?

You always claim they are. Next you'll be backing Richard Stallman's call for a tax increase to pay for this. If you aren't already.


5 posted on 05/10/2006 3:59:43 PM PDT by Golden Eagle (Buy American. While you still can.)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson