Same, and they can be some truly baffling typos.
This seems quite serious, I'll definitely be reading the CVE once it's published. Luckily, I noticed the github notification of the release after only a couple of hours.
edit: I read the advisory and it wasn't too bad in terms of attacker access:
Impact
An attacker can use any non-existent username to bypass the authentication system and gain access to various read-only data in Navidrome, such as user playlists. However, any attempt to modify data fails due to insufficient permissions, limiting the impact to unauthorized viewing of information.
It works great and the config is simple. It doesn't handle triggering things from those keypresses, but you've probably already got something running that does that.
Proximity #95
โ
149 Guesses
๐ก 0 Hints
Relieved to finally get it. I think I hate this game!
A little disappointing that this isn't mechanophilia. Anyone see David Cronenberg's film Crash?
Some great rugby today with some beautiful offloads. NZL RZA game was particularly fun.
There's not been enough of that filmed to get tired of it. Everything out's been good to great, but there's so much more there that'd work well on-screen.
The article mentions two bugs and the first is a use-after-free. The article spends most of the time discussing the second issue (the one you nicely explained).
There was a post about it a few days ago: https://lemmy.sdf.org/post/9116867
I decided to use string comparison for some reason, which meant part two wasn't as quick as it would have been.
use std::{cmp, fs, iter};
fn transpose(rows: &[&str]) -> Vec {
(0..rows[0].len())
.map(|i| {
let bytes: Vec<_> = (0..rows.len()).map(|j| rows[j].as_bytes()[i]).collect();
String::from_utf8(bytes).unwrap()
})
.collect()
}
fn reflection_value(rows: &[&str]) -> Option {
'row_loop: for i in 0..(rows.len() - 1) {
if rows[i] != rows[i + 1] {
continue;
}
// we have an initial match
let other_matches = cmp::min(i, rows.len() - 2 - i);
for j in 1..=other_matches {
if rows[i - j] != rows[i + 1 + j] {
continue 'row_loop;
}
}
return Some(i as u32 + 1);
}
None
}
fn summary(file_path: &str) -> u32 {
fs::read_to_string(file_path)
.expect("Can't read input file")
.split("\n\n")
.map(|s| {
let rows: Vec<&str> = s.split('\n').collect();
if let Some(v) = reflection_value(&rows) {
v * 100
} else {
let cols_owned: Vec = transpose(&rows);
let cols: Vec<&str> = cols_owned.iter().map(|s| s.as_str()).collect();
reflection_value(&cols).expect("No reflections found")
}
})
.sum()
}
fn str_diff(str1: &str, str2: &str) -> u32 {
iter::zip(str1.chars(), str2.chars())
.map(|(s1, s2)| if s1 == s2 { 0 } else { 1 })
.sum()
}
fn smudged_reflection_value(rows: &[&str]) -> Option {
for i in 0..(rows.len() - 1) {
let num_cmps = cmp::min(i, rows.len() - 2 - i);
let errs: u32 = (0..=num_cmps)
.map(|j| str_diff(rows[i - j], rows[i + 1 + j]))
.sum();
if errs != 1 {
continue;
}
return Some(i as u32 + 1);
}
None
}
fn smudged_summary(file_path: &str) -> u32 {
fs::read_to_string(file_path)
.expect("Can't read input file")
.split("\n\n")
.map(|s| {
let rows: Vec<&str> = s.split('\n').collect();
if let Some(v) = smudged_reflection_value(&rows) {
v * 100
} else {
let cols_owned: Vec = transpose(&rows);
let cols: Vec<&str> = cols_owned.iter().map(|s| s.as_str()).collect();
smudged_reflection_value(&cols).expect("No reflections found")
}
})
.sum()
}
fn main() {
println!(" normal: {}", summary("d13/input.txt"));
println!("smudged: {}", smudged_summary("d13/input.txt"));
}
Deebster
0 post score0 comment score
Does this mean for the (ab)users, or for the repo? If it's for the bandwidth hogs, then the brownouts are properly a good thing, as it'll force people to pay attention to these otherwise unmonitored systems.
Also, if it makes the upstream service seem flaky and unreliable, it could convince users to set up the proper caching proxy just for self-interested availability reasons.
I can see some companies happily paying for access, as they'll think it's easier than paying someone internally to manage a proxy/mirror, especially as on-prem is unfashionable lately.