coreutils: Protect against env -a for security#10773
coreutils: Protect against env -a for security#10773oech3 wants to merge 1 commit intouutils:mainfrom
Conversation
|
GNU testsuite comparison: |
01b6655 to
753f86c
Compare
|
GNU testsuite comparison: |
Merging this PR will improve performance by 3.22%
Performance Changes
Comparing Footnotes
|
59e307c to
ac75ff7
Compare
|
GNU testsuite comparison: |
|
I think it would make sense for this code to go into the validation.rs file instead of in the main.rs, then you don't have to worry about importing libc. It would be good to have an additional integration test that shows the env -a working |
This comment was marked as resolved.
This comment was marked as resolved.
|
coreutils/src/common/validation.rs Lines 69 to 77 in 194d980 Wait! Why are we using |
This comment was marked as resolved.
This comment was marked as resolved.
1337cbc to
40581ee
Compare
|
GNU testsuite comparison: |
Done |
|
GNU testsuite comparison: |
env -a false lsdoes not fail. Works under masked/proc.Closes #10135