| ▲ | pizlonator 3 hours ago | |||||||||||||||||||||||||||||||
It’s cool that this mentions Fil-C but it also undersells it. TFA also undersells CHERI. Fil-C doesn’t just “find a lot of temporal-safety” bugs. It closes off memory safety bugs (special and temporal) for exploit writers and ascribes a tight semantics to the whole language. CHERI makes some different trade offs but also gives a tight enough semantics that memory safety exploits aren’t going to work. Both CHERI and Fil-C are more comprehensive than Rust, since they attack the problem at the ABI level (and so you don’t get the problem that the protection only applies to the parts that were rewritten in the safe subset of a new language). Rust could be claimed to be better in that its compile time, but that doesn’t make a significant difference if you’re worried about the definedness of semantics or exploitability. | ||||||||||||||||||||||||||||||||
| ▲ | afdbcreid 3 hours ago | parent [-] | |||||||||||||||||||||||||||||||
Both only attach provenance to allocations. The common example is:
Where a buffer overflow can still overwrite `is_admin`.Both also require recompilation of everything, which might be possible for CHERI but not for Fil-C - which is why, for example, there cannot be Fil-C support for Windows or macOS. | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||