Free software's not-so-eXZellent adventure
Free software's not-so-eXZellent adventure
Posted Apr 3, 2024 16:40 UTC (Wed) by draco (subscriber, #1792)In reply to: Free software's not-so-eXZellent adventure by smurf
Parent article: Free software's not-so-eXZellent adventure
Of course, both should be disallowed
Posted Apr 4, 2024 10:36 UTC (Thu)
by smurf (subscriber, #17840)
[Link] (2 responses)
Posted Apr 4, 2024 18:28 UTC (Thu)
by draco (subscriber, #1792)
[Link] (1 responses)
Here's a picture: https://cdn.arstechnica.net/wp-content/uploads/2024/04/xz...
Posted Apr 5, 2024 9:11 UTC (Fri)
by smurf (subscriber, #17840)
[Link]
So yes you're right in that in this case the test output didn't actually influence the build. Thus to be safe against "hide an exploit's core in plain sight" attacks we'd have to go a step further and mandate that the builder cannot access its test data, binary or otherwise.
Free software's not-so-eXZellent adventure
Free software's not-so-eXZellent adventure
Free software's not-so-eXZellent adventure