From nobody Thu Apr 30 01:53:23 2026 X-Original-To: testing@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4g5cdb3j5nz6cNQj for ; Thu, 30 Apr 2026 01:53:23 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R13" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4g5cdb37YKz4Q7H for ; Thu, 30 Apr 2026 01:53:23 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1777514003; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=9Ozuu4wPRdkIwpJke9fJ0WtnYzPyix+ztloDha79p9c=; b=ySzXcwGlXHhC/+pi55paq6pabtg/qSDdB1EN11SUpk+8k80LrhrqxUBLglvzN37wobaVtK jevjRhv+VrNuFFtuxuq1jiQ9cVw3XEOhB5N5eD0ydAkY+Wr6PCbOQ5xJ9DTwcgBB8wxjId yTzWqRWLqsI7cBPR9NHku7NFuIMusum+tiAipeg247npOrPJlWJU4lstfEd5utJRM4fR+v 0HAIbBCzZuF99bBqhoECkIjvlvCeRLeWj/sqyLke/8np1LXHZysbZtHLsA4+K+HdETT8z7 zePQDS/Td4wYo3Dt/5EDp/OKmFD075OPKu5bDnANUlCrOiIFOKVMsXCmHNhh8Q== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1777514003; a=rsa-sha256; cv=none; b=VsHxSgRhWyJf8Z6CwbySburJUe50hpvmXNy06V1PxnbSBCeFB2qQfrIQyUHLWVFx1liQ/s JeQrwyxjnA9pidgV0PW7cwsYbsCoz9HNScd9Om3nM8BQuBSIP2IRqzI9DfKDF+1+lWINNF 2G6Is0ik2OSC25x+v1ZkVQnFMZseVpNPXs51ylVXAhBAE92R4eESNFyhpV9ulULQ35PGxo YHBUXUtLdJcOJ/10l4Eeq9ISMDcxjcQ7Z7W+mVQtbFfbg5fMAwkT8FZmeWBViyqo1ELqF5 MyKIw7U44EucI4VkLkMreaUmWjyAYmNe//2FFvgo8K29lImJUNvMgmazh093SA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1777514003; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=9Ozuu4wPRdkIwpJke9fJ0WtnYzPyix+ztloDha79p9c=; b=hymG4JsFWVn6aCZ86M9bxuYU1VD9KFy/CRd6Gi4O+WzeQuLpLgvRcv8Gv3VHbKwkEzZVwV JB1LOzD/m2yAWIieqS0P0Sc7ypTLxVBv4l4NMuNzWhj2xGGkTHgFP2imGfe7jx4IpbcbkJ RqRZ1TBiqPMNbgqYN0KsghP+ygPhIexj4yeJeBdxqBeF1SRGLhfAB/pG61A+KOPsLvdXTP RZ4Q/3HC18AnEHbjOJ+Wh6nwwXaclr9m86YKuxnhw9ETsYl1BN0tTfcQZBH86zgiIycNhC SuEjegGHS1qJrNKgCvRgKL0d6CVAHEjnHj6VU/RVfyTH0oeFXQnywyRJu7ZliA== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4g5cdb2kmtz169N for ; Thu, 30 Apr 2026 01:53:23 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 63U1rNWt040818 for ; Thu, 30 Apr 2026 01:53:23 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 63U1rNBi040817 for testing@FreeBSD.org; Thu, 30 Apr 2026 01:53:23 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: testing@FreeBSD.org Subject: [Bug 294881] test failures with FORTIFY_SOURCE=2 Date: Thu, 30 Apr 2026 01:53:23 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: tests X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: kevans@freebsd.org X-Bugzilla-Status: Open X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: testing@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8" X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Testing List-Archive: https://lists.freebsd.org/archives/freebsd-testing List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-testing@freebsd.org Sender: owner-freebsd-testing@FreeBSD.org MIME-Version: 1.0 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D294881 --- Comment #2 from Kyle Evans --- Hmm, I have mixed feelings here. These are all good examples of things designed to take a buffer size and it's not unreasonable for us to let these transgressions slide because the functions are designed acccordingly, on pa= per, to handle these situations. However, the flip side of that: 1. We're triggering because we *do* know the buffer size, and we know that they're trying to exceed that. How do you tell the difference between a logical error, and someone maybe trying to do something malicious? 2. Following the latter part of that question, if they *are* trying to do something malicious, is it better to err on the side of caution or to rely = on the fact that we're testing the correct handling of this scenario? My first instinct is to err on the side of caution and assume that the implementation could be flawed, disable FORTIFY_SOURCE (or at least these specific fortified shims) for these tests so that we have coverage for the scenario that the size is wrong, but still crash out at runtime. --=20 You are receiving this mail because: You are the assignee for the bug.=