[PING][PATCH] [RFCv2] Document Security process for binutils

Alan Modra amodra@gmail.com
Tue Jan 19 08:27:01 GMT 2021


If you are serious about security then "don't run any of binutils as
root" is sufficient advice.  I don't think any of this documentation
in info files is necessary for binutils, and I'd rather not see more
people fuzzing binutils.

As someone who has spent rather a lot of time over the past year
responding to asan, ubsan, and fuzzed object file bug reports, I can
tell you that the great majority of those reports do not fix real
bugs.  By "real bugs", I mean bugs that might conceivably be triggered
by real object files created by compilers or assemblers.

Yes, we do have libbfd and libopcodes that are used by more than just
binutils and gdb, but the number of projects is small.

-- 
Alan Modra
Australia Development Lab, IBM


More information about the Binutils mailing list