coreutils: Protect against env -a for security#10773
coreutils: Protect against env -a for security#10773oech3 wants to merge 1 commit intouutils:mainfrom
Conversation
|
GNU testsuite comparison: |
01b6655 to
753f86c
Compare
|
GNU testsuite comparison: |
This comment was marked as resolved.
This comment was marked as resolved.
Merging this PR will not alter performance
Comparing Footnotes
|
59e307c to
ac75ff7
Compare
|
GNU testsuite comparison: |
|
I think it would make sense for this code to go into the validation.rs file instead of in the main.rs, then you don't have to worry about importing libc. It would be good to have an additional integration test that shows the env -a working |
Did you mean |
|
coreutils/src/common/validation.rs Lines 69 to 77 in 194d980 Wait! Why are we using |
|
So should I imprement |
e3320d4 to
1337cbc
Compare
|
GNU testsuite comparison: |
env -a false lsdoes not fail. Works under masked/proc.Closes #10135