[Bug debuginfod/27758] security idea: DEBUGINFOD_VERIFY mode

2021-05-19 Thread fche at redhat dot com via Elfutils-devel
https://sourceware.org/bugzilla/show_bug.cgi?id=27758 Frank Ch. Eigler changed: What|Removed |Added Status|NEW |RESOLVED Resolution|---

[Bug debuginfod/27758] security idea: DEBUGINFOD_VERIFY mode

2021-04-21 Thread fche at redhat dot com via Elfutils-devel
https://sourceware.org/bugzilla/show_bug.cgi?id=27758 --- Comment #5 from Frank Ch. Eigler --- (In reply to Vitaly Chikunov from comment #3) > Instead of `X-Debuginfod-Hash` you can use `ETag` where you can put anything > including sha256 (can be prescribed in webapi description), then GET reques

[Bug debuginfod/27758] security idea: DEBUGINFOD_VERIFY mode

2021-04-21 Thread fweimer at redhat dot com via Elfutils-devel
https://sourceware.org/bugzilla/show_bug.cgi?id=27758 Florian Weimer changed: What|Removed |Added CC||fweimer at redhat dot com --- Commen

[Bug debuginfod/27758] security idea: DEBUGINFOD_VERIFY mode

2021-04-20 Thread vt at altlinux dot org via Elfutils-devel
https://sourceware.org/bugzilla/show_bug.cgi?id=27758 Vitaly Chikunov changed: What|Removed |Added CC||vt at altlinux dot org --- Comment

[Bug debuginfod/27758] security idea: DEBUGINFOD_VERIFY mode

2021-04-20 Thread fche at redhat dot com via Elfutils-devel
https://sourceware.org/bugzilla/show_bug.cgi?id=27758 --- Comment #2 from Frank Ch. Eigler --- Yeah. It may comfort those who are worried about the integrity of their previously downloaded cached files, but is not robust against local attacker who currently has control over the filesystem or pro

[Bug debuginfod/27758] security idea: DEBUGINFOD_VERIFY mode

2021-04-20 Thread zbyszek at in dot waw.pl via Elfutils-devel
https://sourceware.org/bugzilla/show_bug.cgi?id=27758 Zbigniew Jędrzejewski-Szmek changed: What|Removed |Added CC||zbyszek at in dot waw.pl