Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20181018145729.dlq7sljlhevxa4xo@jwilk.net>
Date: Thu, 18 Oct 2018 16:57:29 +0200
From: Jakub Wilk <jwilk@...lk.net>
To: oss-security@...ts.openwall.com
Subject: Re: Using quilt on untrusted RPM spec files

* Randy Barlow <randy@...ctronsweatshop.com>, 2018-09-27, 22:39:
>In Fedora we have similar challenges. We've got a tool called 
>fedora-review[0] that is maybe kinda similar to quilt.

Quilt is a tool to manage patch series, so maybe not that similar. :-)

>It uses mock[1] to build the source RPM (and mock does this in a chroot 
>to help with the problems you described)

If it's really just chroot, then I'm afraid that's not a sufficient 
protection. One can easily escape the chroot with ptrace(2).

-- 
Jakub Wilk

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.