Skip to content

jsegitz/squilt

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

12 Commits
 
 
 
 
 
 

Repository files navigation

squilt

Wrapper to confine quilt with nsjail

Why?

Using quilt on untrusted spec files is not secure. For more see this posting by Matthias.

Matthias developed the original exploit, but as described in the posting, any command in %prep is run as the user calling quilt without any limitations. This was (at least to us) unexpected.

Usage

If you add an alias quilt=squilt or copy this script as 'quilt' to a directory that is earlier in $PATH you should be able to use it like you use quilt without noticying a difference.

About

Wrapper to confine quilt with nsjail

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages