4 ms·
Rust doesn’t have post install scripts
by nothinkjustai 5mo ago
Rust doesn’t have post install scripts
- tasn 5mo agoIt has build.rs, which has essentially the same problems.
- deeebug 5mo agoThey have build.rs (https://doc.rust-lang.org/cargo/reference/build-scripts.html https://doc.rust-lang.org/cargo/reference/build-scripts.html)
- fabrice_d 5mo agoIt has build.rs that will run as soon as you compile the dependency. That's not the same thing but pretty close to a post install script: it's very likely to run.
- est31 5mo agoThere is build.rs, proc macros are unsandboxed, and lastly you install the binary so that you can run it. Even if the build and install were fully sandboxed, the binary could still do malicious stuff if ran.
- drdaeman 5mo agoEven without post-install script, a malicious payload could be hiding in some function and just wait until the developer invokes `cargo run`. Not that many people audit the crates they pull into their projects.
- nothinkjustai 5mo agoYeah no shit, if you download malicious code from the internet and run it on your computer you will get pwned. No matter if it’s from a package manager a zip file or a submodule. However the current npm vulns used a post install script.
- mort96 5mo agoI maintain that NPM malware use postinstall scripts just because they exist and are convenient. Had NPM not had postinstall scripts, the malware would have used a different mechanism and been almost exactly as effective.