Z & Ales,

I would agree that there should be tickets for the issues.   In fact, there
may already be tickets for some of the issues found by the analysis.

Not having any info yet on what the code analysis shows, its pretty hard
to have any feeling for what, if anything, might really need to be fixed.

-- Jim Mankovich | jm...@hp.com (MST) --

On 1/4/2013 10:17 AM, Zdenek Styblik wrote:
> On Fri, Jan 4, 2013 at 5:48 PM, Ales Ledvinka <aledv...@redhat.com> wrote:
>>> I don't know how much I can help with the
>>> fixing, but if I have
>>> time I'll do what I can.
>> You are welcome. Send me mail with the list of files you are going to touch.
> I hope you two will find a better way than this. Like creating tickets
> for these issues at SF.net and use ``Assigned'' attribute.
>
>>> I'm curious as to how will you determine which issues to fix?
>> Reasonable minimal fix. If further question remain then add some XXX comment.
>>
> Hmm. I feel like question was about apples and answer oranges.
> Anyway, I wanted to say I've read: ``I'll hack in fixes'', but that's
> not the word I'm looking for. Sadly, I can't find English equivalent
> of word I'm looking for to ``reasonable minimal fix'', but let's say
> I'm looking forward for those code reviews.
>
> [...]
>>> What do you mean when you say you are going to release the report to
>>> the "public"
>>> with "the patch"?
>> Once the changes are public it's like releasing the report so I was
>> thinking of attaching it to tracker item with patch to aid review.
>>
> Ales, can you please stop making secrets about something that's not
> secret? ipmitool is open-source. Static analysis, I presume that's
> what you, or Fedora, have used, tools are available to pretty much
> everyone. Also, there are other security issues like over/underflow
> via user input. So I doubt whatever "you" found is worse.
> On the bright side, I'm glad somebody have found time and made an
> effort to run ipmitool through analysis tool.
>
> Z.
>
>> ------------------------------------------------------------------------------
>> Master HTML5, CSS3, ASP.NET, MVC, AJAX, Knockout.js, Web API and
>> much more. Get web development skills now with LearnDevNow -
>> 350+ hours of step-by-step video tutorials by Microsoft MVPs and experts.
>> SALE $99.99 this month only -- learn more at:
>> http://p.sf.net/sfu/learnmore_122812
>> _______________________________________________
>> Ipmitool-devel mailing list
>> Ipmitool-devel@lists.sourceforge.net
>> https://lists.sourceforge.net/lists/listinfo/ipmitool-devel


------------------------------------------------------------------------------
Master HTML5, CSS3, ASP.NET, MVC, AJAX, Knockout.js, Web API and
much more. Get web development skills now with LearnDevNow -
350+ hours of step-by-step video tutorials by Microsoft MVPs and experts.
SALE $99.99 this month only -- learn more at:
http://p.sf.net/sfu/learnmore_122812
_______________________________________________
Ipmitool-devel mailing list
Ipmitool-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/ipmitool-devel

Reply via email to