A backdoor in xz
A backdoor in xz
Posted Mar 30, 2024 6:50 UTC (Sat) by intelfx (subscriber, #130118)In reply to: A backdoor in xz by cjwatson
Parent article: A backdoor in xz
> But if there's a reasonably standard inlined C reimplementation that covers all the necessary API surface, I'd definitely consider it.
Yep, that's why I tried to emphasize "as used". The implementation you see is shared between several mostly-disjoint users (e. g. it is also used to communicate with hypervisors via vsock) and also implements other features of this ad-hoc protocol (such as fd passing) which are not used in openssh.
The usage in openssh (to signal readiness) is covered by writing a fixed, static text string into an AF_UNIX datagram socket pointed to by the $NOTIFY_SOCKET variable.