Mailinglist Archive: opensuse-buildservice (145 mails)

< Previous Next >
Re: [opensuse-buildservice] view=solvstate
  • From: Johannes Lahti <johannes@xxxxxxxxxx>
  • Date: Tue, 8 Nov 2011 13:49:33 +0200
  • Message-id: <CAENz9e0hRjcpZb46_S8qiy+7L=kmcxcMw_iic8JcaY6pMo27TQ@mail.gmail.com>
Sat-solver's solv parser was never checked against corrupt solv
files, so it's probably possible to exploit it and do nasty things.
That's not a problem for libzypp, as it only handles solv files
written by itself.
So I didn't dare to make view=solvstate the default because of
security reasons. If you trust the other side, you can use it
to speed up things.

Ok. Thank you for the clear up!

And how the hell the api.opensuse.org can handle the situation? :)

I don't know, it doesn't seem to be an issue here.

Nice to hear that. :) You definitely have more horsepower in use, but
I can imagine that the number of requests is huge.

-Johannes
--
To unsubscribe, e-mail: opensuse-buildservice+unsubscribe@xxxxxxxxxxxx
To contact the owner, e-mail: opensuse-buildservice+owner@xxxxxxxxxxxx

< Previous Next >