>> Does your understanding of programming language details differ from the view 
>> of
>> SEI CERT C Coding Standard (from the Carnegie Mellon University)?
>> https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp34-c/
> 
> We recently discussed a similar case where several people told you that
> the "problem" you fixed wasn't actually a problem.

We came along possible adjustments according to an application of another
questionable sanity check.


>                                                    This patch is in the
> same category and your reference doesn't match the code touched here.

Will development interests grow if bug reports will follow by further known
source code analysis tools?
https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp34-c/#automated-detection


> Please stop to absorb maintainer attention with useless stuff.
Do we need to start negotiations for allocation of a corresponding CVE ID
(as something happened for similar control flows before)?
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/process/cve.rst?h=v7.2-rc3#n16

Regards,
Markus

Reply via email to