so gnutls is BACKDOORED backdoored
@hipsterelectron how did this happen?
@RosaCtrl yes! LLM commits to the ceph cluster fs were also how red hat engineer david howells obfuscated his string of backdated changes to crypto/ which included an early exit from a checksum validation function used in module signature verification, so that any users selecting the new ML-DSA cryptographic keypair type to sign modules with would end up with a kernel that accepts literally any kernel module at all (back in march during the 7.0 rc cycle)
@RosaCtrl gnutls is particularly desperate. in addition to backdating you'll find they just repeat a set of very large commits and subsequent reverts and just do that back and forth spaced out by 10-15 intermediate shorter commits with complete bullshit
@RosaCtrl and of course people still accept "claude found a vuln" as if it's more likely that an LLM inferred something the human maintainers who wrote the broken code had missed, than the alternative explanation where the maintainers with the most expertise in their codebase's build system and non-local interactions are simply adding backdoors to their own codebase because the US declared war again
https://gitlab.com/gnutls/gnutls/-/work_items/1783
Tbh, I just threw Gemini CLI at
lib/and it reported this:Looking at the code, not knowing if there are any string size limiters on the caller side, I'd say that Gemini is right.
I'd suggest a simple overflow check withINT_MULTIPLY_OVERFLOW.
It has a negligible performance impact and stops any discussion.
"stops any discussion" is a ridiculous thing to say
@RosaCtrl i also very much enjoyed this PR https://gitlab.com/gnutls/gnutls/-/merge_requests/1788
LGTM.com has been deprecated and replaced by GitHub code analysis:
https://github.blog/2022-08-15-the-next-step-for-lgtm-com-github-code-scanning/
like oh gnutls is just relying upon github for static anal now? but then i saw the issue: https://gitlab.com/gnutls/gnutls/-/work_items/1461
As Semmle's LGTM is no longer supported, we should consider enabling other static code scanning tools. What I'm aware of and are integrated with GitLab/GitHub are:
Code Climate integration in GitLab
CodeQL scanning on the GitHub mirror
and that's bad enough but wait--github mirror? oh yes!!!
i still can't find the last good commit
@hipsterelectron can you find the first good commit?