3 ms·
Could a malicious macro generate code so that the compiled program would e.g. access /etc/password? Will there be some verification that precompiled macro bina
by gunn 7y ago
Could a malicious macro generate code so that the compiled program would e.g. access /etc/password?
Will there be some verification that precompiled macro binaries come from their published source?
- steveklabnik 7y agoYes, that’s already possible today, they can do anything. We haven’t decided for sure if we’re going to do this upstream yet, so those kinds of policy questions have yet to be answered. I’d imagine so, but there’s a lot of details there!
- swsieber 7y agoI would say precompiled proc macros via wasm narrows that hole - since it can't access any outside source, it becomes deterministic and greatly simplifies testing it for malicous output.
- steveklabnik 7y agoYes, this particular implementation does. That doesn’t mean the final one will follow suit. This could be considered breaking backwards compatibility, for example.
- swsieber 7y agoTrue. I'd hope future implementations are very explicit about what operations are allowable (for example, globs for files in allowed inputs/outputs), such that you still have an easier time testing.