The sudo feature

David Miller justdave at bugzilla.org
Tue Dec 13 08:52:27 UTC 2005


I discussed this on IRC a bit tonight, but mentioning it here as well 
for a little wider audience.

The sudo feature is making me damn nervous.  Just the kinds of bugs I'm 
seeing going by, and the particular places in the code that are getting 
touched by the patches fixing them.  The authentication code is getting 
hacked to hell and back, and I'm just scared we're going to wind up 
introducing more security bugs that we haven't even thought of.

At this point, I'm kind of regretting ever approving that feature.  But 
it's a bit late for that now I guess.  Just everyone keep a vigilant eye 
out on that code...  pound the heck out of it, and let's make sure it 
really is safe.

-- 
Dave Miller                                   http://www.justdave.net/
System Administrator, Mozilla Corporation      http://www.mozilla.com/
Project Leader, Bugzilla Bug Tracking System  http://www.bugzilla.org/



More information about the developers mailing list