Indeed it might be worth another look; there has been upstream activity addressing issues and the commit messages even reference Coverity. They've been trying.
If jpeg2000 support in Ubuntu is important to you, I'd like to encourage you to: - read the openjpeg2 source code and suggest improvements - contribute images to a test suite - contribute a test suite if that's still lacking - run coverity or cppcheck or other static analysis tools on the codebase - fuzz the library with ubsan, asan, libdislocator, etc. - write libfuzzer-friendly wrappers around the functions and contribute these to the project if that's still lacking. Something really simple would be to build an asan or libdislocator variant and test with the files I've already generated and attached here. If any of the files I've attached in the last year still cause asan alerts when I get around to looking at the library again, it'll be a pretty poor report on the state of the library. Thanks -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/711061 Title: [MIR] openjpeg2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openjpeg2/+bug/711061/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
