Re: [Openvpn-devel] [PATCH] hardening: add insurance to exit on a failed ASSERT()

2015-10-21 Thread Arne Schwabe
ACK. Fine, whatever makes the analyzers happy. Arne Am 21.10.15 um 10:08 schrieb Steffan Karger: > The code behind our ASSERT() macro is pretty complex. Although it seems > to be correct, make it trivially clear we will never return from a failed > assert by adding an _exit(1) call. As was sugg

[Openvpn-devel] [PATCH] hardening: add insurance to exit on a failed ASSERT()

2015-10-21 Thread Steffan Karger
The code behind our ASSERT() macro is pretty complex. Although it seems to be correct, make it trivially clear we will never return from a failed assert by adding an _exit(1) call. As was suggested by Sebastian Krahmer of the SuSE security team. To make sure they that tools like clang static ana

Re: [Openvpn-devel] [PATCH] hardening: add insurance to exit on a failed ASSERT()

2015-10-21 Thread Arne Schwabe
Am 21.10.15 um 00:37 schrieb Steffan Karger: > The code behind our ASSERT() macro is pretty complex. Although it seems > to be correct, make it trivially clear we will never return from a failed > assert by adding an _exit(1) call. As was suggested by Sebastian Krahmer > of the SuSE security te

[Openvpn-devel] [PATCH] hardening: add insurance to exit on a failed ASSERT()

2015-10-20 Thread Steffan Karger
The code behind our ASSERT() macro is pretty complex. Although it seems to be correct, make it trivially clear we will never return from a failed assert by adding an _exit(1) call. As was suggested by Sebastian Krahmer of the SuSE security team. A secondary benefit is that tools like clang stati