Mailinglist Archive: opensuse-buildservice (145 mails)

< Previous Next >
Re: [opensuse-buildservice] view=solvstate
On Tue, Nov 08, 2011 at 11:41:49AM +0200, Johannes Lahti wrote:
I'd just like to know why "view=cache" is the default and if there are
some drawbacks when using "view=solvstate"?

Sat-solver's solv parser was never checked against corrupt solv
files, so it's probably possible to exploit it and do nasty things.
That's not a problem for libzypp, as it only handles solv files
written by itself.
So I didn't dare to make view=solvstate the default because of
security reasons. If you trust the other side, you can use it
to speed up things.

And how the hell the api.opensuse.org can handle the situation? :)

I don't know, it doesn't seem to be an issue here.

Cheers,
Michael.

--
Michael Schroeder mls@xxxxxxx
SUSE LINUX Products GmbH, GF Jeff Hawn, HRB 16746 AG Nuernberg
main(_){while(_=~getchar())putchar(~_-1/(~(_|32)/13*2-11)*13);}
--
To unsubscribe, e-mail: opensuse-buildservice+unsubscribe@xxxxxxxxxxxx
To contact the owner, e-mail: opensuse-buildservice+owner@xxxxxxxxxxxx

< Previous Next >
Follow Ups
References