Re: GNU Coding Standards, automake, and the recent xz-utils backdoor

2024-04-02 Thread Jose E. Marchesi
> Jose E. Marchesi wrote: >>> Jose E. Marchesi wrote: >>> >>>>> [...] >>>>> >>>>>> I agree that distcheck is good but not a cure all. Any static >>>>>> system can be attacked when there is

Re: GNU Coding Standards, automake, and the recent xz-utils backdoor

2024-04-01 Thread Jose E. Marchesi
> Jose E. Marchesi wrote: >>> [...] >>> >>>> I agree that distcheck is good but not a cure all. Any static >>>> system can be attacked when there is motive, and unit tests are >>>> easily gamed. >>>> >

Re: GNU Coding Standards, automake, and the recent xz-utils backdoor

2024-03-31 Thread Jose E. Marchesi
> [...] >> I agree that distcheck is good but not a cure all. Any static >> system can be attacked when there is motive, and unit tests are >> easily gamed. > > The issue seems to be releases containing binary data for unit tests, > instead of source or scripts to generate that data. In this