567 karma · joined February 1, 2017
https://www.gnu.org/software/coreutils/rejected_requests.htm...
* recompiling with -march=native can give significant wins over more generic binaries provided by linux distros.
* parallel processing helps with bigger files, and it's easy enough to leverage the existing wc binary to process in parallel.
Both points are discussed at: https://www.pixelbeat.org/docs/unix-parallel-tools.html
sha256sum uses 128KiB blocks when reading, which may be more optimized than the openssl program.
sha256sum supports using openssl libs as they are generally faster. This is enabled on Red Hat flavored distros and arch, but not debian flavored as yet
The upcoming release of sha256sum (8.32) will auto enable use of openssl for >= v 3, as openssl's licence has changed to apache in that version
https://www.maizure.org/projects/decoded-gnu-coreutils/timeo...
https://www.gnu.org/software/coreutils/rejected_requests.htm...
But for actual debugging, especially for code you're not familiar with, they can save huge amounts of time. Some more notes on this at:
Note one can build the coreutils like busybox with the --enable-single-binary configure option. In this mode all 100 or so utils are combined to a single 1MB binary. I would not consider this bloated given the functionality provided.
It's an interesting contrast to banning cars and essentially banning walking
It takes a certain scale to herd all the open source cats
My own debugging with gdb summary: http://www.pixelbeat.org/programming/debugger/
http://www.pixelbeat.org/programming/gcc/integer_overflow.ht...
If one want the older unsafe defaults you can add -N to your ls alias
http://www.pixelbeat.org/cmdline.html#sets
Note comm output is a bit awkward to parse, so I use another coreutils `join` command to process already sorted data
I.E. libguestfs is safer when dealing with images of unknown origin, and losetup has inbuilt support now for partition scanning.
Here's an old fdisk/parted wrapper I used to use:
We've had a quick look at using oss-fuzz, which will need a bit of work since it's more suited to libraries rather than standalone utils.
We put a lot of effort into the test suite which makes it easy for others to test various experimental security checkers. This has been detailed in the "third party testing" section at: http://www.pixelbeat.org/docs/coreutils-testing.html
thunderbird has over 20 years lineage, and I've screenshots of the major stages at:
As a maintainer of a project¹ that many use, I've had private messages encouraging me to commit suicide etc. Not ideal.