LWN.net Logo

Security of distributing builds

Security of distributing builds

Posted Mar 6, 2008 12:07 UTC (Thu) by midg3t (subscriber, #30998)
In reply to: security of distributing builds by pjm
Parent article: Proposal: Fedora@Home

No-one would seriously entertain the idea of allowing untrusted builds into the official software archive.

There are many cases when the potential for bad data to be returned is not much of a problem. For instance the grid could be used as an unofficial build farm with on-commit autobuilds. If there's a strange build failure then the first step would be to reproduce that failure in a similar environment. The release builds would still be done on more secure (controlled) machines.

Similarly for scientific applications the aim might be to look for outliers - eg. how SETI works - once again "interesting" results are always reprocessed in a controlled environment.


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds