vlovich123 2 hours ago

Not actually confirmed as compiler bugs yet.

Here’s a similar bug where OpenSSL’s inline asm was wrong and probably only GCC was smart enough to try to exploit the bug:

https://github.com/openssl/openssl/pull/23233

Same for rust - could be UB in quiche that is getting exposed.

  • account42 1 hour ago

    Can't even find an upstream compiler bug report not to mention a confirmation/patch. Doesn't look like the compiler output was analyzed at all either, they are just going by "-O3 results in valgrind warnings, -O2 doesn't".

    It's not like compiler bugs are unheard of but they are rare enough that the base assumption should be that the bug is in your own code.

rurban 1 hour ago

Looks like a valid new optimization to me, which only fails on valgrind, which is a bit too strict with uninitialized values. In openssl's strlcpy. They'll deal with that.