|
|
|
|
|
by tgma
344 days ago
|
|
> I have personally found several fuckups in gRPC and protobuf code resulting in application crashes or risks of remote code execution. Would be great if you report such remote code executions to the authors/Google. I am sure they handle CVEs etc. There has been a security audit like https://github.com/grpc/grpc/tree/master/doc/grpc_security_a... > there aren't sanitizer builds nor fuzzing regime nor static analysis running against new commits last time I checked. Are you making shit up as you go? I randomly picked a recently merged commit and this is the list of test suites ran on the pull request. As far as I recall, this has been the practice for at least 8 years+ (note the MSAN, ASAN, TSAN etc.) I can see various fuzzers in the code base so that claim is also unsubstantiated https://github.com/grpc/grpc/tree/f5c26aec2904fddffb70471cbc... Android (Internal CI) Kokoro build finished
Basic Tests C Windows Kokoro build finished
Basic Tests C# Linux Kokoro build finished
Basic Tests C# MacOS Kokoro build finished
Basic Tests C# Windows Kokoro build finished
Basic Tests C++ iOS Kokoro build finished
Basic Tests C/C++ Linux [Build Only] Kokoro build finished
Basic Tests ObjC Examples Kokoro build finished
Basic Tests ObjC iOS Kokoro build finished
Basic Tests PHP Linux Kokoro build finished
Basic Tests PHP MacOS Kokoro build finished
Basic Tests Python Linux Kokoro build finished
Basic Tests Python MacOS Kokoro build finished
Bazel Basic Tests for Python (Local) Kokoro build finished
Bazel Basic build for C/C++ Kokoro build finished
Bazel C/C++ Opt MacOS Kokoro build finished
Bazel RBE ASAN C/C++ Kokoro build finished
Bazel RBE Build Tests Kokoro build finished
Bazel RBE Debug C/C++ Kokoro build finished
Bazel RBE MSAN C/C++ Kokoro build finished
Bazel RBE Opt C/C++ Kokoro build finished
Bazel RBE TSAN C/C++ Kokoro build finished
Bazel RBE Thready-TSAN C/C++ Kokoro build finished
Bazel RBE UBSAN C/C++ Kokoro build finished
Bazel RBE Windows Opt C/C++ Kokoro build finished
Bloat Diff Kokoro build finished
Bloat Difference Bloat Difference
Clang Tidy (internal CI) Kokoro build finished
Distribution Tests C# Linux Kokoro build finished
Distribution Tests C# MacOS Kokoro build finished
Distribution Tests C# Windows Kokoro build finished
Distribution Tests Linux (standalone subset) Kokoro build finished
Distribution Tests PHP Linux Kokoro build finished
Distribution Tests PHP MacOS Kokoro build finished
Distribution Tests Python Linux Arm64 Kokoro build finished
Distribution Tests Ruby MacOS Kokoro build finished
Distribution Tests Windows (standalone subset) Kokoro build finished
EasyCLA EasyCLA check passed. You are authorized to contribute.
Grpc Examples Tests CPP Kokoro build finished
Memory Difference Memory Difference
Memory Usage Diff Kokoro build finished
Mergeable Mergeable Run has been Completed!
Migration Test MacOS Sonoma Kokoro build finished
ObjC Bazel Test Kokoro build finished
Portability Tests Linux [Build Only] (internal CI) Kokoro build finished
Portability Tests Windows [Build Only] (internal CI) Kokoro build finished
Sanity Checks (internal CI) Kokoro build finished
Tooling Tests Python Linux Kokoro build finished
Windows clang-cl with strict warnings [Build Only] Kokoro build finished
|
|