2 ms·
Dependency detection is usually done during source code review for software packaging (like Debian), there it is relatively trivial; look at declared dependenci
by pabs3 6mo ago
Dependency detection is usually done during source code review for software packaging (like Debian), there it is relatively trivial; look at declared dependencies, search for language functionality that loads libraries or calls executables and mostly you will be done. Like dlopen for C or import for Python.
The Linux kernel has the IMA subsystem that is intended to prevent executing untrusted binaries, enroll all the hashes from your package manager, and then you will know where every executed binary came from. Or just verify the block device with dm-verity. Or both. I believe that similar functionality exists on Windows and some interpreters have support for asking the kernel to check if files can be executed before loading them.
https://ima-doc.readthedocs.io/en/latest/ https://ima-doc.readthedocs.io/en/latest/
https://www.kernel.org/doc/html/latest/admin-guide/device-mapper/verity.html https://www.kernel.org/doc/html/latest/admin-guide/device-ma...
The Bootstrappable Builds toolchain requires the use of machine code of course since CPUs only accept machine code, but that machine code is in hex numbers in a text file with comments and that form is considered the "source code" not "a binary", aka it is "the preferred form for modification" (the phrase used by the GPL). The human starting the bootstrap process has to review it is correct, enter it into the computer in some trustworthy way, and start it. Yes, the bootstrap process does go to unbelievably extraordinary measures :)