Dear Mike Frysinger, In message <201111281810.03260.vap...@gentoo.org> you wrote: > > On Monday 28 November 2011 14:24:49 Wolfgang Denk wrote: > > common/menu.c used printf() in a number of places to print user > > provided, constant strings (like the "title" string). printf() is > > dangerous here for example in case the user unwittingly embeds some > > '%' caracters that printf() would interpret as formatting and then > > pick up random arguments. Use puts() instead. > > i'm not seeing this problem based on your patch below ...
Yes, you are right. I was incorrectly extrapolating from another issue fixed elsewhere. > > - printf("^C\n"); > > + puts("^C\n"); > > this change makes sense, but not for any of the reasons cited in the > changelog; this looks like a simple optimization ... True. But d*mn, I have messed this up, and it sneaked into the master branch already. Sorry... Best regards, Wolfgang Denk -- DENX Software Engineering GmbH, MD: Wolfgang Denk & Detlev Zundel HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany Phone: (+49)-8142-66989-10 Fax: (+49)-8142-66989-80 Email: w...@denx.de If there was anything that depressed him more than his own cynicism, it was that quite often it still wasn't as cynical as real life. - Terry Pratchett, _Guards! Guards!_ _______________________________________________ U-Boot mailing list U-Boot@lists.denx.de http://lists.denx.de/mailman/listinfo/u-boot