> This patch, as of yet, only gives 'non-safe' version of decompressor.
> The 'safe' version will be included soon.
How are you planning to add that back?
The LZO author had some concerns about this code. The major issue heI found certain parts which were 64-bit unsafe - corrected them. Now,
highlighted was that it was 64-bit unsafe. Have you addressed that
problem?
Has it been tested on 64bit?No. I am still looking for some 64-bit machine to test on (also some
I'm worried that in converting this code the way you have, you've
possibly introduced potential security holes. You've removed all bounds
checking and are going to have to add that back to create the "safe"
version of the decompression function. Until I mentioned it, you seemed
unaware of the potential problem and the comments above suggest you
don't understand this code as fully as I'd like with regard to
overflows.
The version I submitted has at least been subject to userspace scrutiny
over a period of time and is basically unchanged with regard to
security. It is much uglier though.
Richard