Report security issues through GitHub's private vulnerability reporting: open a draft advisory. That keeps the report private until a fix is available.
Please include what you observed, the recipe and host that produced it, and the
src2deb version (src2deb --version). Expect an acknowledgement within a week.
Issues in the sandbox itself belong to ferroday-cage, which src2deb builds on.
src2deb builds upstream source. Three properties of that are design decisions rather than defects, and each is documented in the guide.
A component that vendors its dependencies is built in two passes. The vendor
pass runs the component's own debian/rules clean — arbitrary upstream code —
in a sandbox whose filesystem is isolated but whose network is the host's, so
the vendoring step can fetch its crates. /etc/resolv.conf is bound read-only
into that sandbox, and it is the one host file a build sees.
The offline build pass, which is the one that produces the packages, runs with an isolated network. Building a recipe therefore means trusting the components it names to the extent of running their build scripts with host network access. See the trust boundary.
A run writes a Release and signs nothing, so a client reads the pool with
Trusted: yes — which installs packages without verifying a signature over the
archive. That is appropriate for a pool on the machine that built it, or one
served over a network you control to hosts you control. Sign the pool before
serving it to anyone else. See Signing a pool.
provider = "rustup" fetches the upstream installer from https://sh.rustup.rs
over pinned TLS and installs the version the recipe names. The installer script
carries no checksum pin, which is the standard rustup bootstrap, so that
toolchain rests on the fetch as well as on the archive. provider = "debian"
resolves rustc and cargo from the signed archive alone. See
Sources and the toolchain.
Reports that the sandbox fails to hold — a build reading or writing host state outside the source tree, the output directory, and the work directory; a build pass reaching the network; the host's environment, tooling, or keyring reaching a build — are in scope, as are recipe or archive inputs that lead to code execution outside a cage.
src2deb is at 0.1. Fixes land on main; there are no maintained release
branches yet.