Security page in the docs should mention that rustup assumes trusted file system
Open
Nobody has claimed this yet.
bug
- Dominant language
- Rust
- Stars
- 7k
- Forks
- 1.1k
- Avg merge
- 22h 40m
- Merged PRs (30d)
- 46
Description
Today, it's possible to make rustup execute arbitrary code by crafting a rust-toolchain.toml file:
https://github.com/jonas-schievink/mallory/blob/master/rust-toolchain
This probably should be mentioned on the security page: https://rust-lang.github.io/rustup/security.html
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the rustup security page linked in the issue and review the linked mallory rust-toolchain example. Update the security documentation to mention the trusted-file-system assumption and the relevant risk, then verify that the warning is clear and accurately reflects the example.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 52/100