Re: Zeroed pages returned for heap

From: Peter Staubach
Date: Tue Jun 07 2005 - 11:03:32 EST


Nagendra Singh Tomar wrote:

Hi all,
The short version first.
Is it OK for an application (a C library implementing malloc/calloc is also an application) to assume that the pages returned by the OS for heap allocation (either directly thru brk() or thru mmap(MAP_ANONYMOUS)) will be zero filled.


An application which makes assumptions about the contents of newly allocated
memory would seem to be making very dangerous assumptions.

Ignoring that, would it not be considered to be a security violation to hand
pieces of memory to applications without erasing the old contents of the pages?

Thanx...

ps
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/