lua-users home
lua-l archive

[Date Prev][Date Next][Thread Prev][Thread Next] [Date Index] [Thread Index]

On Thu, Nov 5, 2015 at 9:47 AM, Roberto Ierusalimschy
<> wrote:
>> Alternatively, the attached is based on "A Killer Adversary for
>> Quicksort". At least for 2^8, it ends up finding a remarkably similar
>> bad-case input:
>> [...]
> This is a quite different beast. If you allow the attacker to choose
> the comparison function, all bets are off.
> -- Roberto

Quite, and trivially so: That's an untrusted code execution, plain and
simple. It can do anything the attacker wants. Finding a way to sneak
it into the sort function is, at most, an attempt to obfuscate the

/s/ Adam