|
Message-Id: <1540265618.431.2@mail.gathman.org> Date: Mon, 22 Oct 2018 23:33:38 -0400 From: "Stuart D. Gathman" <stuart@...hman.org> To: oss-security@...ts.openwall.com Subject: Re: Using quilt on untrusted RPM spec files Fedora avoids the problem by running rpmbuild in a chroot mini container (provided by systemd) as the mockbuild user with no network access - this extracts source, does %prep, etc. This is done with the 'mock' utility. The reviewer can still examine the prepped source in the host filesystem. The reviewer can also run commands inside the mock chroot container, install additional packages (like vim), get a shell inside the container, etc.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.