7 ms·
Even if there were basic unit & regression tests, this bug might not have been caught. This bug should have gone through detailed security review and should pro
by muricula 6y ago
Even if there were basic unit & regression tests, this bug might not have been caught. This bug should have gone through detailed security review and should probably also undergo fuzzing.
- jeffbee 6y agoYou can bet your bottom banana that the GRU, the NSA, Chinese state security, and the mob have all thoroughly fuzzed sudo and are sitting on the results. It just seems SO EASY to add a test for this problem, literally the relevant test input is one slash by itself, or any string ending in a slash! So simple! If I sent a change like this at work, no matter how trivial, that said it fixed this bug but I didn't send any tests, the reviewer would reject it out of hand or, probably, just silently ignore my change. But that's the real problem here. This program is a monograph. There are no reviewers and there are, consequently, no standards.
- bnroberts 6y agoSingle persons often have superhuman standards. It is easy to see that most of the best works in math or art were produced by an individual. Code review can work, but often it doesn't. There are countless examples of projects with "strict" review requirements that have similar issues (whereas qmail only had one). Writing tests is the important thing, it keeps you honest.
- jeffbee 6y ago31 CVEs later I think it's safe to say that this particular author does not possess superhuman standards. How much more evidence would we need?
- mike_d 6y agoIt sounds like you'd find great pleasure in writing harnesses for oss-fuzz. Google has found and reported over 25,000 bugs in 375 projects, but they need people like you to help wire up new projects. You can get started here: https://google.github.io/oss-fuzz/ https://google.github.io/oss-fuzz/
- arp242 6y agoMaybe expecting projects that mostly consist of a single guy working on it in their spare time to be "NSA proof" isn't really realistic? Folk love to bring up "responsibility" and all of that, but you can't really expect people to bear the responsibility of the world on their shoulders for their spare time projects. It's neither realistic nor fair.
- jolux 6y agoNo, but having tests is an acceptable baseline.
- arp242 6y agoThere are tests. Are there enough tests? Maybe not. But people can do in their spare time whatever they want, including writing code without tests.
- brigandish 6y agoPeople can do what they want in their spare time, true, but that it is their spare time does not make the action responsible or irresponsible, nor does it shelter them from responsibility. Not wearing a seatbelt when at work or in your spare time is irresponsible. Writing code, without tests, that others use (and for security at that) is irresponsible.
- arp242 6y ago> Writing code, without tests, that others use (and for security at that) is irresponsible. You can choose to run this code, or you can choose not to run this code. It's really up to you. This is very different from a sealbelt, as I can't choose to not have an accident with you, potentially causing a needless fatality.
- lmm 6y agoThis code is advertised as a security tool, is it not? The only reason anyone runs sudo is because it (supposedly) improves their security. I think some responsibility comes with that.
- jjoonathan 6y ago> It just seems SO EASY Then do it! On your own time, rather than complaining that someone else didn't do it on theirs!
- natevancouver 6y agoDoes the project have a testing framework in place? How is the project built and distributed? Can testing be integrated into its CI/CD pipeline? Is there a CI/CD pipeline? Adding frameworks and infrastructure to a project is one of those things that is a lot more work than it appears to be. They should do it, for sure, but I wouldn’t dismiss it as trivial on a decades-old system that was never built for it.
- acdha 6y agoWe’d all like that, true, but look here: https://github.com/sudo-project/sudo/graphs/contributors https://github.com/sudo-project/sudo/graphs/contributors That’s one maintainer, not even full time according to his résumé. What you just described is multiple specialists and some supporting tools, so another way of looking at this is to ask how much value the IT world has gotten from sudo but not contributed back in support. When something is this widely used, it’s easy to forget that the answer to who should do more isn’t the one person who actually steps up to keep it alive.
- anonymousiam 6y agoDoes he moonlight for the NSA?
- acdha 6y agoThis response is the “must be aliens” of security. If you remotely think this is the case, ask whether one of the top intelligence agencies in the world would be more likely to attract attention to a deep cover operation many, many years in the making or would invest in making sure that the bug was well concealed so nobody else would be able to use it on, say, .gov servers. If you remember Dual EC_DRBG I know which one I’d bet on…
- anonymousiam 6y agoIt was meant as a joke. Lighten up. Having worked with the IC for decades, I'm well aware of what's going on.
- acdha 6y agoI figured it was a joke but it's about as original as a standup routine complaining about airline food.
- jart 6y agoWow he changed two million lines of the sudo codebase over the project history and made 10,548 commits. That's bonkers. Sudo is clearly doing a lot more under the hood than I thought it did. A simple security critical command shouldn't have that much churn. It should arc towards immutability like TeX, which has had like twelve changes in the last 40 years.