3 ms·
I've got to say, Git resignifying -- and requiring --end-of-options instead is bonkers
by ufo 2y ago
I've got to say, Git resignifying -- and requiring --end-of-options instead is bonkers
- musicale 2y agoThe pathway of untrusted/malicious input -> trusted command line argument seems to be a common problem, and one that could possibly be mitigated by better type/taint checking. It looks like there is some prior work in this area, but it hasn't resulted in commonly available implementations (even something basic like a type/taint checking version of exec() etc. on one side and getopt() etc. on the other.)
- PhilipRoman 2y agoI could've sworn I remember something about bash and glibc cooperating to indicate which arguments come from expanded variables but I cannot find anything on the internet or in the sources. Either I'm going insane or it was an unmerged proposal.
- BobbyTables2 2y agoSeems like it would be quite painful to do that in C without heavy refactoring. Maybe a Rust alternative ?
- yjftsjthsd-h 2y agoWhy would that be painful in C? The code is already handling all the pieces
- pluto_modadic 2y agoPainful to write vs painful to audit for correctness. Writing code that you barely understand is a surefire recipe to have /no clue/ how to debug said code (because debugging it will be more complex). (let alone audit it for correctness/security).
- yjftsjthsd-h 2y agoThat just sounds like you don't believe it's ever possible to change existing C code, which... is a position you can argue, but I'm pretty sure that bash and glibc are actively developed to the point where I wouldn't personally commit to that position.
- ForOldHack 2y agoInsert obligatory ref to "on trusting trust" what is the compiler doing? Has the pre-processor been vetted? This is looking more and more like hardware solutions are becoming more attractive.
- yjftsjthsd-h 2y ago1. I don't see why you need to solve Trusting Trust to make libc and the shell more robust. 2. If we are worried about Trusting Trust, then Rust is worse; at least C has the wide range of compilers needed for diverse double-compiling and as of https://guix.gnu.org/en/blog/2023/the-full-source-bootstrap-building-from-source-all-the-way-down/ https://guix.gnu.org/en/blog/2023/the-full-source-bootstrap-... we arguably have a working solution. Rust only has a single compiler, and that compiler is used to build itself, making it the poster child for Trusting Trust targets.
- steveklabnik 2y agoRust has a second compiler, mrustc, written in C++ and that is able to bit-reproduce rustc. This has been the case for a few years now.
- yjftsjthsd-h 2y agoOh, excellent; I didn't realize that was capable of building rustc. In that case, I'm wrong and Rust is just as good as C.
- Avamander 2y agoBesides what has already been said in other comments, I think reality has already shown how it _is_ painful in C. It's painful to implement both safe and ergonomic. The amount of subtly incorrect and/or differing implementations doing easier things out there is just incredible.
- jwilk 2y agoIt was a thing back in 1996/1997: https://sourceware.org/cgit/glibc/commit/?id=bf079e19f50d64aa5e05b5e1 https://sourceware.org/cgit/glibc/commit/?id=bf079e19f50d64a...
- PhilipRoman 2y agoYeah this is exactly what I was thinking of, thanks for finding it.
- musicale 2y ago> "disabled later" because "it caused problems" ;-(
- pests 2y agoSadly due to legacy. —- disambiguates revisions and paths in some commands so another option was needed.
- immibis 2y agoJust write all commands with structured I/O instead, like Powershell. Now I want an operating system where everything is a YANG model...