Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 22 Oct 2018 23:33:38 -0400
From: "Stuart D. Gathman" <stuart@...hman.org>
To: oss-security@...ts.openwall.com
Subject: Re: Using quilt on untrusted RPM spec files

Fedora avoids the problem by running rpmbuild in a chroot mini 
container (provided by systemd) as the mockbuild user with no network 
access - this extracts source, does %prep, etc.   This is done with the 
'mock' utility.  The reviewer can still examine the prepped source in 
the host filesystem.  The reviewer can also run commands inside the 
mock chroot container, install additional packages (like vim), get a 
shell inside the container, etc.

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.