yacc(1) causes a fault -- "fault VA = 0xa5a5a5b1"

Roman Divacky rdivacky at FreeBSD.org
Wed May 9 19:02:39 UTC 2007


> >Sounds like a regression in malloc(3) ?
> >
> >Thanks,
> >
> 
> No, that looks like a use-after-free, with malloc filling the freed 
> memory with trash.  It's a debugging option that is turned off in
> RELENG_N branches and left on in HEAD, for precisely this reason.

this makes me ask a question - what is the state of running coverity
on fbsd userland? some of the programs in the userland are really
old and noone has touched them in ages... (yacc being obviously one of
them)

thnx for answer


More information about the freebsd-current mailing list