[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <boris.20210927162833@codesynthesis.com>
Date: Mon, 27 Sep 2021 16:34:22 +0200
From: Boris Kolpackov <boris@...esynthesis.com>
To: Richard Weinberger <richard@....at>
Cc: masahiroy <masahiroy@...nel.org>,
linux-kernel <linux-kernel@...r.kernel.org>,
linux-kbuild <linux-kbuild@...r.kernel.org>
Subject: Re: [PATCH 2/2] kconfig: Deny command substitution in string values
Richard Weinberger <richard@....at> writes:
> Yes. auto.conf is .config post processed.
> This is exactly where my mitigation takes place.
No, sym_escape_string_value() is called by conf_write_symbol()
which in turn is called from conf_write() and conf_write_defconfig()
(used to write .config files) besides conf_write_autoconf() (used to
write auto.conf).
Powered by blists - more mailing lists