guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH] tar bombs and muscle


From: Ben Woodcroft
Subject: [PATCH] tar bombs and muscle
Date: Sun, 17 Jan 2016 11:30:03 +1000
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.4.0

Hi,

There is a somewhat popular bioinformatics program muscle whose download tgz is a tar bomb. The bomb moniker seems especially appropriate here, since it made the gnu-build-system error out, and patching gnu-build-system requires a lot of rebuilding. In the attached patches I fixed gnu-build-system so that the "chdir" is omitted when there is no directory to chdir into, and then added muscle itself.

Is it OK in these rare instances to put the archive contents into the directory as-is, or is something more complex like making a directory and moving everything there more appropriate?

I imagine it might be best to let this slide into the next core-updates.

Thanks,
ben

Attachment: 0002-gnu-Add-muscle.patch
Description: Text Data

Attachment: 0001-build-Accept-source-archives-that-do-not-contain-a-d.patch
Description: Text Data


reply via email to

[Prev in Thread] Current Thread [Next in Thread]