Precompiled binaries removed from serde v1.0.184
github.com
github.com
Authors comment:
>"Someone else is always auditing the code and will save me from anything bad in a macro before it would ever run on my machines." (At one point serde_derive ran an untrusted binary for over 4 weeks across 12 releases before almost anyone became aware. This was plain-as-day code in the crate root; I am confident that professionally obfuscated malicious code would be undetected for years.)
He got some hate for that in the replies but I think it is a great point. Pardon my snark, but every "security expert" that voiced their opinion over the last couple of days, yet failed to recognize the situation for almost a month, should reassess their reaction once the anger subsides.
The current macro situation is dangerous (and wasteful), hopefully some real progress can be made.
> Pardon my snark, but every "security expert" that voiced their opinion over the last couple of days, yet failed to recognize the situation for almost a month, should reassess their reaction once the anger subsides.
I'm not a "security expert", but I wondered why I hadn't noticed this situation, since I have the habit of always diffing between the previous and the current version of the crates in ~/.cargo/registry/src whenever cargo tells me it downloaded a new version of a dependency, and a new binary file would stick out like a sore thumb. But real life has intruded for me in the last few weeks, and the last serde_derive on my ~/.cargo is still 1.0.166, so it seems I luckily avoided all this mess.
(Yes, I know that reviewing the code after it has already compiled is suboptimal, and obfuscated malicious code or even the "new dependency" trick could easily pass through my cursory inspection; but at least it can be reviewed by comparing it with the previous version, unlike a precompiled binary blob where even small changes can lead to a huge difference between one binary and the other, not to mention that comparing objdump disassembly output is painful.)
I’m a purist personally, but I can see the other side
You have completely missed the point. It is because things go unnoticed that security minded folks are upset. We don't get off from finding security problems, we get off on being safe to begin with.
Someone did: the Fedora maintainer who raised the issue. One of the reasons I avoid installing from wild-west package managers like Cargo/NPM/..., is specifically because Debian/Fedora/... maintainers performs some basic checks like this so I don't have to.
Each exception needs to be documented and specific.
This isn't a serious comment. It really does not matter whether "almost anyone" became aware, it matters whether the sorts of people who pay attention to this became aware. OS packagers became aware of this super quickly and were working quietly to get this fixed. My understanding is that some security teams at large companies quickly flagged this as well and likely reached out via private channels.
The public outrage happened weeks later but it's not as if no one was paying attention.
Great, he made his point that we're all dummies and we'll all just blindly run any ol' code he sends us. In the process he did very serious damage to his reputation and any trust relationship he had with the broader community. Other projects have banned people for this kind of behavior.
I also think this displays 'emperors clothes' behaviour. In a perfect world, many eyeballs make all bugs shallow, and long term, it actually mostly works. But short term, we collectively severely fall short of our ideals. I think part of the harshness an OSS contributor receives in this kind of situation comes from everyone realizing we've been caught with our pants down.
It's human to shoot the messenger, but let's not forget this only happens because someone worked hard enough to make the whole world trust him or her.
As for making progress on the idea of improving build times, I agree with kayabaNerve from the Pre-RFC [1]
> It's effectively impossible to fairly review this on its merit now, nor to say it isn't being reviewed on an accelerated time span than it would otherwise have been.
[0] https://www.reddit.com/r/rust/comments/15va70a/serde_has_sta...
[1] https://internals.rust-lang.org/t/pre-rfc-sandboxed-determin...
https://github.com/serde-rs/serde/issues/2584#issue-18580752...
Due to the way that the derive feature was causing the dependency chain in Cargo to be longer than necessary, thereby making it impossible for cargo to compile multiple crates in parallel.
Distributing binaries is what distributions are for. It does not matter if it is for macros or for the rest of a crate.
Anyone can write and publish a cargo plugin that provides binaries via a separate channel.
https://crates.io/crates/cargo-prebuilt has been around for a while. (I've not used it, just looked for it now)
Some gains and losses are elaborated here where it was added: https://github.com/serde-rs/serde/pull/2514
I wish I could say this left a good taste in my mouth as a strong proponent of Rust.
Especially after dtolnay banned me on the repo after I commented on the PR. Can't even give thumbs up on someone else's comment let alone open an issue or a PR.
Interesting to see how glorified janitorial roles make people think they have some real power.
Just take a look at https://github.com/andreisilviudragnea/serde-blocked/discuss...
David went on a full on power trip rampage, going as far as banning people who participated with emojis on that PR from the serde org on GitHub.
>Just take a look at https://github.com/andreisilviudragnea/serde-blocked/discuss...
>David went on a full on power trip rampage, going as far as banning people who participated with emojis on that PR from the serde org on GitHub.
Yeah... I'm going to go ahead and assume there's a little more to it that you're telling us.
Not hard to imagine why he would have blocked you or the possibility you're not telling the whole story. This combination of entitlement and disregard is thoroughly toxic.
dtolnay has built an incredible amount of the Rust ecosystem. For anyone unfamiliar, just take a look here: https://crates.io/users/dtolnay?sort=recent-downloads
Some of his crates are a bit opinionated, and I don't agree with all the opinions, but the amount of effort and ingenuity that has gone into them is breath-taking, and we get the results of it without paying a dime. Maybe that deserves some gratitude and grace...
yeah, i'm quite supportive of him banning you.