[concurrency-interest] Concurrency and security

Jed Wesley-Smith jwesleysmith at atlassian.com
Thu May 20 01:15:53 EDT 2010


David Holmes wrote:
> James Gan writes:
>   
>> Yes, data race tool can detect this problem. On the other hand, even
>> if we fixed the data race problem by adding synchronization, it's
>> still a security problem.
>>     
>
> Oops! Indeed. Even with sync the API is fatally flawed.
>
> I don't know if the tools will be able to detect the inherent check-then-act
> sequence.
>   

I just thought you were being droll…

cheers,

jed.


More information about the Concurrency-interest mailing list