97, 1/4 회원가입  로그인  
   멍멍
   http://www.hackerschool.org
   WIKI 또 다운돼서 파트 7 여기에 올립니다

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=57 [복사]


Does that help?
답변이 됐나요?

Any other questions before we get move forward?
계속 진행하기에 앞서 또 다른 질문 있나요?

ok, cool.
좋아요

So, how do you review code?
그래서 어떻게 코드를 리뷰할까요?

Ah.. the next part I'll talk will be very interactive
다음 파트는 대화형이 될 것입니다.

I would like as much info from you guys as possible
여러분들에게서 많은 정보들을 기대하겠습니다.

We have already talked about the major portions.
이미 중요한 부분들에 대해서는 이야기를 했지요

And talked about threat analysis
그리고 위협 분석에 대해서도 이야기를 했고요

ok, the second step everyone should read code.
좋아요, 다음 단계로 모두가 코드 리뷰를 해야 합니다

everyone should read code since they need to understand all the global variables and local variables.
모두가 코드 리뷰를 통해 전역변수와 지역변수를 이해하기 위해서입니다.

It should be docummented and they should understand
이것은 문서화돼야하고, 모두가 이해해야 합니다.

always always do 2 person reviews.
항상 2명이 리뷰를 해야합니다.

Not only the main person who is managing the code review project to lead it everyone should *** give a ** review of the code
코드 리뷰 프로젝트를 이끄는 사람뿐만 아니라, 모두가 코드 리뷰를 해야합니다.

break the code into major chunks if you have done same thing with the DFD or broken the application into an application architecture or you own method
DFD와 같은 방식으로 코드를 나누거나, 어플리케이션 아키텍쳐 레벨로 나누거나, 혹은 당신만의 방법으로 나눕니다.

you want to break it down there because even indivisuals can't review major chunks of the code
개개인이 코드의 메인 영역을 리뷰할 수는 없기 때문에 코드를 나누어야 합니다.

because you wont all the application code review by one person or one team ?***cal
왜냐면 한명의 사람에 의해 모든 코드가 리뷰되기를 원하기 때문입니다.

that communication constantly should not be at all
지속적으로 커뮤니케이션해야 합니다.

person access reviewing part of the documented code and person reviewing there's no real communication which happens all the time.
문서화된 코드에 접근하는 사람과 실제 리뷰하고 있는 사람 사이에 항상 커뮤니케이션이 이루어지지는 않습니다.

maintain code notes with the reviewer's name simply because of questions
리뷰어의 이름을 적으면서 코드를 관리해야 하는 이유입니다.

that happens so many times that uh.. somebody has gone through a function
이런 일이 종종 발생합니다. 누군가 함수 전체를 리뷰했습니다.

he's not written notes definetly his name when talk to him about it ** entire file  
그런데 그에 대한 이름를 남기지 않았습니다.

why do ***** it helps reduce among the effort
그것이 노력을 줄여주기 때문입니다.

detailed code analysis.
자세한 코드 분석

before we go into detailed code analysis,
좀더 자세한 코드 분석으로 나아가기 전에

we will talk about one of the different techniques of doing a detailed code analysis.
자세한 코드 분석을 위한 몇가지 다른 방법에 대해 이야기해 봅시다

I recommend always always come up with a major lists of issues that you should review so that everyone game on the same page ok?
저는 여러분이 항상 중요한 코드 리뷰 리스트를 만들고, 모두가 똑같은 코드 리뷰를 할수 있도록 하기를 권장합니다.

So reviewing code I'm gonna talk about just three major issues, termination issues, validation issues, and calculation issues.
저는 여기서 세 가지 중요한 주제에 대해서만 이야기 하겠습니다. 종결 문제, 유효성 문제, 그리고 계산 문제입니다.

termination issues are again devided into major categories.
종결 문제는 다시 몇가지 중요한 부분들로 나뉘어 집니다.

null termination and strlen, null termination and strncpy, condtional termination, and premature termination
NULL 종결과 strlen, NULL 종결과 strncpy, 조건부 종결, 그리고 너무 이른 종결

so, there's where I need your input.
자, 여기부터는 여러분의 참여가 필요합니다.

I'm gonna put the point out there hopely you guys will be little more interactive
여러분이 좀더 적극적으로 이 코드에서 어떤 문제의 가능성이 있는지 찾아내 주시면 좋겠군요

and tell me what the possible problems will be in this piece of code.
그리고 이 코드 안에 어떠한 잠재적인 문제가 있는지 저에게 말해주세요.

Yes sir
예 그쪽분

Integer overflow
정수 오버플로우 입니다.

Integer overflow? why?
정수 오버플로우라고요? 왜지요?

*************************
답변

perfect
완벽합니다.

so, you said it's integer overflow and the reason is simply because strlen
자, 저분께서 답이 정수 오버플로우라고 했고, 그 이유는 strlen이기 때문이라고 했습니다.

what is strlen do?
strlen이 하는게 뭐지요?

it does not count for the NULL
NULL을 세지 않습니다.

and you need to ban and have one more place or there ****** integer overflow
한 바이트의 공간이 더 필요합니다. 그렇지 않으면 integer overflow가 발생합니다.

Any questions on that?
이에 대해 질문 있나요?

*************************
[질문]

right right. that would be. another technical
맞습니다. 그건 다른 기술입니다.

ok uh.. the next one is null termination and strncpy.
좋아요 다음은 strncpy에서의 NULL 종결 문제입니다.

This should be pretty similar to what you just said
당신이 말했던 것과 상당히 비슷할 것입니다.

Yes sir.
예 그쪽분

*************************
[답변]

absolutely correct
정확히 맞습니다.

So this is something slightly unique and lot of developments forget about this.
그러니까 이건 약간 특별하고 많은 개발자들이 잊어버리는 것입니다.

As MSDN actually exquisitely states this
MSDN은 실제로 이것을 자세히 언급하고 있습니다.

that if this strncpy copy function copy that initial count by count that mean the size of what you putting over there.
strncpy는 사용자에 의해 지정된 count 값만큼 복사를 합니다.

the characters of the string source to string dest
source의 문자열들을 dest로 복사를 합니다.

right?
맞지요?

the count is if less then or equal to the length of the source an none character is not appended
카운트 값이 소스의 길이보다 값이 작거나 같다면, 문자가 추가되지 않을 겁니다.



  Hit : 2194     Date : 2011/06/02 05:57