do-not-compile-this-code | edit ; since this got the team
kandi X-RAY | do-not-compile-this-code Summary
kandi X-RAY | do-not-compile-this-code Summary
do-not-compile-this-code is a Rust library. do-not-compile-this-code has no bugs, it has no vulnerabilities, it has a Permissive License and it has low support. You can download it from GitHub.
edit; since this got out the team has reached out and said that it is by design. This proof-of-concept demonstrates how Rust macros can be abused to interact with the machine that the compliation happens on. When the do_not_compile_this_code is opened in VS Code with the rust-analyzer plugin, the editor expands the some_macro!() macro. This macro reads then content of ~/.ssh/id_rsa_do_not_try_this_at_home and deletes the file. This behavior also occurs when cargo build is run or when the application is run. The key insight is that Rust macros are expanded before/during compilation, i.e. arbitrary code execution during compilation. This is a demostration that this is a huge vulnerability in the rust ecosystem that needs to be taken seriously.
edit; since this got out the team has reached out and said that it is by design. This proof-of-concept demonstrates how Rust macros can be abused to interact with the machine that the compliation happens on. When the do_not_compile_this_code is opened in VS Code with the rust-analyzer plugin, the editor expands the some_macro!() macro. This macro reads then content of ~/.ssh/id_rsa_do_not_try_this_at_home and deletes the file. This behavior also occurs when cargo build is run or when the application is run. The key insight is that Rust macros are expanded before/during compilation, i.e. arbitrary code execution during compilation. This is a demostration that this is a huge vulnerability in the rust ecosystem that needs to be taken seriously.
Support
Quality
Security
License
Reuse
Support
do-not-compile-this-code has a low active ecosystem.
It has 60 star(s) with 2 fork(s). There are 3 watchers for this library.
It had no major release in the last 6 months.
do-not-compile-this-code has no issues reported. There are no pull requests.
It has a neutral sentiment in the developer community.
The latest version of do-not-compile-this-code is current.
Quality
do-not-compile-this-code has no bugs reported.
Security
do-not-compile-this-code has no vulnerabilities reported, and its dependent libraries have no vulnerabilities reported.
License
do-not-compile-this-code is licensed under the MIT License. This license is Permissive.
Permissive licenses have the least restrictions, and you can use them in most projects.
Reuse
do-not-compile-this-code releases are not available. You will need to build from source code and install.
Installation instructions are not available. Examples and code snippets are available.
Top functions reviewed by kandi - BETA
kandi's functional review helps you automatically verify the functionalities of the libraries and avoid rework.
Currently covering the most popular Java, JavaScript and Python libraries. See a Sample of do-not-compile-this-code
Currently covering the most popular Java, JavaScript and Python libraries. See a Sample of do-not-compile-this-code
do-not-compile-this-code Key Features
No Key Features are available at this moment for do-not-compile-this-code.
do-not-compile-this-code Examples and Code Snippets
No Code Snippets are available at this moment for do-not-compile-this-code.
Community Discussions
No Community Discussions are available at this moment for do-not-compile-this-code.Refer to stack overflow page for discussions.
Community Discussions, Code Snippets contain sources that include Stack Exchange Network
Vulnerabilities
No vulnerabilities reported
Install do-not-compile-this-code
You can download it from GitHub.
Rust is installed and managed by the rustup tool. Rust has a 6-week rapid release process and supports a great number of platforms, so there are many builds of Rust available at any time. Please refer rust-lang.org for more information.
Rust is installed and managed by the rustup tool. Rust has a 6-week rapid release process and supports a great number of platforms, so there are many builds of Rust available at any time. Please refer rust-lang.org for more information.
Support
For any new features, suggestions and bugs create an issue on GitHub.
If you have any questions check and ask questions on community page Stack Overflow .
Find more information at:
Reuse Trending Solutions
Find, review, and download reusable Libraries, Code Snippets, Cloud APIs from over 650 million Knowledge Items
Find more librariesStay Updated
Subscribe to our newsletter for trending solutions and developer bootcamps
Share this Page