r/ProgrammerHumor 1d ago

Meme iReplacedItWithABuiltinFunction

Post image
3.2k Upvotes

51 comments sorted by

View all comments

108

u/evilwizzardofcoding 1d ago

People laugh at this, but remember, someone caught a malicious PR to CURL during optimization 'cus the malicious code made a function take longer than it should.

61

u/Bright-Historian-216 1d ago

to curl? i've heard about xz-lib (i think it was xz-lib?), but not to curl. can you link that?

42

u/evilwizzardofcoding 1d ago

Oh you right, it was XZ. The curl one was a hypothetical, someone pointed out there was a way you could do some unicode wizardry to make a specific line vulnerable without it being really noticeable, but it was just a concept, no one tried to push it to the actual repo.

1

u/CelestialFury 23h ago

Like this?

// Safe-looking code, but with homoglyph trickery

int safe_flag = 0;      // uses normal Latin 'a' in "safe"
int sаfe_flag = 1;      // the 'a' in "sаfe" is Cyrillic U+0430

if (safe_flag) {
    // Reviewer thinks this block runs only when safe_flag == 1
    do_safe_thing();
} else {
    do_other_thing();
}

// Somewhere else in the patch:
log_status(sаfe_flag);  // Looks like "safe_flag", but it's the Cyrillic one

1

u/evilwizzardofcoding 16h ago

Basically, but the specific implementation apparently had some very clever trick that made the change basically invisible, so there was no need for do_other_thing();