4 ms·
I don’t think it’s a theory. He certainly tried to use the precompiled macros in service of this pre-RFC: https://internals.rust-lang.org/t/pre-rfc-sandboxed-de
by lexlash 3y ago
I don’t think it’s a theory. He certainly tried to use the precompiled macros in service of this pre-RFC: https://internals.rust-lang.org/t/pre-rfc-sandboxed-deterministic-reproducible-efficient-wasm-compilation-of-proc-macros/19359 https://internals.rust-lang.org/t/pre-rfc-sandboxed-determin...
Relevant section:
"Someone else is always auditing the code and will save me from anything bad in a macro before it would ever run on my machines." (At one point serde_derive ran an untrusted binary for over 4 weeks across 12 releases before almost anyone became aware. This was plain-as-day code in the crate root; I am confident that professionally obfuscated malicious code would be undetected for years.)
- nextaccountic 3y ago> I am confident that professionally obfuscated malicious code would be undetected for years There was even a contest for underhanded code (malicious code that, if found, someone could plausibly claim that it was just a honest programmer mistake rather than intentional malware), it was pretty cool https://www.reddit.com/r/rust/comments/72v194/the_2016_underhanded_rust_contest_the_results/ https://www.reddit.com/r/rust/comments/72v194/the_2016_under... And there were talks to revive it https://github.com/rust-community/team/issues/256 https://github.com/rust-community/team/issues/256