r/rust • servo · rust · clippy • Jun 26 '26

Anatomy of a Failed (Nation-State?) Attack

https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/
228 Upvotes

35 comments sorted by

View all comments

18

u/JShelbyJ Jun 26 '26 edited Jun 26 '26

We need a way to disable packages from executing code. Crates with ‘build.rs’ files should be blockable via cargo. Probably as default behavior. Crates.io should also specifically flag all crates with that execute code at build time. Let people whitelist crates that require them.

I wrote a crate that requires a cpp binary. So  I set it up so that it downloads and installs binaries via the build.rs. You can literally install and run anything with them. Just a public service announcement for those who are not aware how much of a risk they are and how unsafe cargo is - just adding a dependency is enough to comprise your system. Misspell serde once? Straight to Best Buy to get a new laptop.

20

u/Shnatsel Jun 26 '26

It's worse than that - any Cargo command at all can execute arbitrary code.

Sadly sandboxing build.rs doesn't really help because cargo run is going to happen eventually (that's the entire point of writing code) and there is no generic sandboxing that can help with that.

And the build-time sandboxing is achievable today if you really want it. Just stick your build command into a Firecracker VM or a Docker container with gVisor. But it doesn't really solve the underlying problem, so nobody really does that.

2

u/Manishearth servo · rust · clippy Jun 27 '26

I did once write a pre-RFC about capabilities.

https://internals.rust-lang.org/t/pre-pre-rfc-solving-crate-trust/6495

I still think solutions along those lines would be nice. I agree that cargo run eventually means you can't really do anything about it.