Security issues found within rust-coreutils

30 points by hugoarnal


dpc_pw

I sampled > 10 random issues. Most of them involve symlinks (these are always fun, ha?). quite a few non-UTF-8 handling issues. Some of the issues seem ... kind of basic, even surprising. E.g... discarding errors seems like a easy "don't do that" kind of a bug.

Don't want to be too harsh, as it's always easy to judge, but it does seem like not at level of maturity required. Which is a check-and-egg problem too.

BTW. What's on my mind immediately is how feasible it is to do some kind of a file-system-centring fuzzing-like suite, to run new and original implementations side by side to detect mismatches automatically.