Received: by 2002:a05:6359:c8b:b0:c7:702f:21d4 with SMTP id go11csp597716rwb; Thu, 22 Sep 2022 04:08:17 -0700 (PDT) X-Google-Smtp-Source: AMsMyM75dn35Z/RuUZucWH59bLqSlxPNVxsbBvR/aW0199FkK+jS1Sb4BGdL7BzQtcKOgesBaaJM X-Received: by 2002:a05:6402:538f:b0:444:c17b:1665 with SMTP id ew15-20020a056402538f00b00444c17b1665mr2739433edb.98.1663844896872; Thu, 22 Sep 2022 04:08:16 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1663844896; cv=none; d=google.com; s=arc-20160816; b=h7wtmhcSIfE9m6rrAyS/NPBsEaxkWvMzesRqH2lpU034HGRmsg103q7xstlHbG31I1 nTbduB1HouEFvVsYx1jReR89cKNGohzQDW8ike8Q+ibGoilkEqmT3CWX8NaJJn6vkZTn 71Um5GggUQYZU1nYTqvqLnAzEn4xygJRSZ5dDaxV/5Q3IIdmmlG3Ye5CV6sbUjvj2U6F 6ACa2JotrNynp3YHiPeMfsfusx4l7ahC6HU9fTmXGTbxTdTxm29XA0njQyeUh5IDBGNE J0kZSjbTeLa6Nu4h3PcYdSKPBo1wlI6NLX0KCNAd+dVBahr1EXDdurkaSqM/klNv2R2T mkIw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:dkim-signature; bh=+8RVBpvMoPFWmhGcL4H8dYuUDziDEsgkdhPy3XBz2I4=; b=Ilo4/odNEnZGe6RFMQPZg+mlTqm/Q8Ooqipnx26RBC1LocAXvDAn1SKpdxs8KBpym4 zSienew+p6f0MlBLJZ9HmWsEgWFGgdZk297FTH2R1T5tDTzsivNxYWd6BQCnnKCEZwrG lDUJuIlHfhPnOFPnO9N6Xi+hDYG0SF7XE1VBlJBW50VKtsi4luHmDyiT0mTBTQlff+x2 6gnsp8iGYdEq5fstp/aK52masK6ZSIlN/dV/QADQhBUJZ/P12N1P1MDxes29luR8jLRE RVi5QW58s2H7O7kggcalQOX2CqiTm0o+aB9gUDQh06D/oAf9BZ+01N263b61nGNgtmQX 5AlA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=ALXZwDuV; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id hz5-20020a1709072ce500b007707eb353eesi5206386ejc.305.2022.09.22.04.07.50; Thu, 22 Sep 2022 04:08:16 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=ALXZwDuV; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229787AbiIVKvO (ORCPT + 99 others); Thu, 22 Sep 2022 06:51:14 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:51310 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229886AbiIVKvM (ORCPT ); Thu, 22 Sep 2022 06:51:12 -0400 Received: from mail-vs1-xe2a.google.com (mail-vs1-xe2a.google.com [IPv6:2607:f8b0:4864:20::e2a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 6337BD01F6 for ; Thu, 22 Sep 2022 03:51:11 -0700 (PDT) Received: by mail-vs1-xe2a.google.com with SMTP id q26so9818916vsr.7 for ; Thu, 22 Sep 2022 03:51:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date; bh=+8RVBpvMoPFWmhGcL4H8dYuUDziDEsgkdhPy3XBz2I4=; b=ALXZwDuV3TsTjfRdY2r0nlIayYwKQkpAssa3cAxmHzh9FzEHyxGQJoM8/rFAa0rjWq pjnAg5AUJb2jZRCc0XBK5lc/K3e4n58QS7EfbIApkoV2lHESNKqvd9TaFEzQrfc48vbd wlSVh2GkkPC2rmyZsR3UPcfCIYTgN5JVeLlv2RX6V5tIqo6hugIJAd3e1erxwLljHY7j 5yRf4vMzMttEiQAFCpG1mZeB2WQf8tSaPlgUeLsFIlcm8ALSevfBh+oDCj3FH3/u5xcO M/uwg+9E2b8LN1MeN6YJma7VTwCVcZo7L8PggzNdqcKu4py2kew8N3TnAgkeS/8W6ujF p//w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date; bh=+8RVBpvMoPFWmhGcL4H8dYuUDziDEsgkdhPy3XBz2I4=; b=rbe0Hz7kc1mQ9Wwvi9MTixfCywi1v3+4g7KrWEjwPG5QRn6WHvmoRobh4cleO1XbVp XqGpSllNO1Qxs8jvNSrmp49zZz7V3JpiPqM2v1/4bMydIehrb2CqE6FH2QOvN9MaVkuA elnC/QWRd/ov67CHzgf8FjHoM8op38ZGia0KDvDJDKveNfNM8/5Ejsgxy0NZYXqQa8z9 XrM/1IpSaRYA7yhNelpr5pU13UnfDp7v23l4+CUINekbPHat6r8d0nwlXc8gNbfIJb7f abcXe00G5sbs2BHiZh1a0xU5B1RmHIjphy9p1E6ItEGNucVsifSjLdJFagIcqowldjsn DGZw== X-Gm-Message-State: ACrzQf0ZmjKoyA71fDhpEGSw5kJbo55zvNjvfhxkb4OXD9/P2eMUop3m BMFwy+yzQuzAvX3IS+uGvQFD92P3qCOMuDHTo7iezg== X-Received: by 2002:a67:d211:0:b0:398:3cfd:5a34 with SMTP id y17-20020a67d211000000b003983cfd5a34mr899669vsi.35.1663843870401; Thu, 22 Sep 2022 03:51:10 -0700 (PDT) MIME-Version: 1.0 References: <20220922083610.235936-1-xu.panda@zte.com.cn> In-Reply-To: From: David Gow Date: Thu, 22 Sep 2022 18:50:59 +0800 Message-ID: Subject: Re: [PATCH linux-next] kunit: tool: use absolute path for wget To: Greg KH Cc: cgel.zte@gmail.com, Brendan Higgins , paul.walmsley@sifive.com, palmer@dabbelt.com, aou@eecs.berkeley.edu, Shuah Khan , Daniel Latypov , "open list:KERNEL SELFTEST FRAMEWORK" , KUnit Development , linux-riscv , Linux Kernel Mailing List , Xu Panda , Zeal Robot Content-Type: text/plain; charset="UTF-8" X-Spam-Status: No, score=-17.6 required=5.0 tests=BAYES_00,DKIMWL_WL_MED, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF, ENV_AND_HDR_SPF_MATCH,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS, USER_IN_DEF_DKIM_WL,USER_IN_DEF_SPF_WL autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu, Sep 22, 2022 at 6:20 PM Greg KH wrote: > > On Thu, Sep 22, 2022 at 06:09:28PM +0800, David Gow wrote: > > On Thu, Sep 22, 2022 at 4:36 PM wrote: > > > > > > From: Xu Panda > > > > > > Not using absolute path when invoking wget can lead to serious > > > security issues. > > > > > > Reported-by: Zeal Robot > > > Signed-off-by: Xu Panda > > > --- > > > > This seems mostly okay to me -- we'd be abandoning people who have > > wget in an unusual location, but I don't think there are many people > > who want to run KUnit under RISC-V, have wget in a non-standard > > location, and can't acquire the bios file themselves. > > > > So this is: > > Reviewed-by: David Gow > > Please no, at this point in time, submissions from this gmail "alias" > are going to have to be rejected from the kernel. > Good to know, thanks. This isn't queued anyway, as I think that getting rid of the code to download the BIOS (and instead relying on the user's distro to provide it) is probably a better solution. Cheers, -- David