rust-lang / rust-lang/rustup

Security page in the docs should mention that rustup assumes trusted file system

Open
#2,879 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Rust
Stars
7k
Forks
1.1k
Avg merge
22h 40m
Merged PRs (30d)
46

Description

Today, it's possible to make rustup execute arbitrary code by crafting a rust-toolchain.toml file:

https://github.com/jonas-schievink/mallory/blob/master/rust-toolchain

This probably should be mentioned on the security page: https://rust-lang.github.io/rustup/security.html

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the rustup security page linked in the issue and review the linked mallory rust-toolchain example. Update the security documentation to mention the trusted-file-system assumption and the relevant risk, then verify that the warning is clear and accurately reflects the example.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
documentation, security
Issue type
Documentation
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.