Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

54,417 Aufrufe • vor 11 Monaten •via X (Twitter)

30 Kommentare

Profilbild von Igor Klopov
Igor Klopovvor 11 Monaten

Awesome! I wonder if it's easy for you to compile a vulnerable version of some software with regular C, run an exploit agaist it, get an RCE or so, and then do the same but compile that software with FilC first. This way you show the practical purpose of your memory safety

Profilbild von Filip Jerzy Pizło
Filip Jerzy Pizłovor 11 Monaten

Like this?

Profilbild von Igor Klopov
Igor Klopovvor 11 Monaten

Yeah right! Missed that

Profilbild von 𝒫𝑒𝓇 𝒜𝓇𝓃𝑒𝓃𝑔 【🐧λ🦀⎈】
𝒫𝑒𝓇 𝒜𝓇𝓃𝑒𝓃𝑔 【🐧λ🦀⎈】vor 11 Monaten

Nice work 💪 interesting to see it action 🤩 what would you estimate on average in % slower than C and memory usage compared to C? This could initially be very interesting for security critical systems.

Profilbild von Filip Jerzy Pizło
Filip Jerzy Pizłovor 11 Monaten

It’s measurably slower and uses measurably more memory. But like my demo shows, you won’t notice it as a user

Profilbild von molleweide
molleweidevor 11 Monaten

@per_arneng Are there any user domains where it would be noticeable assuming FilC would become more widespread?

Profilbild von Filip Jerzy Pizło
Filip Jerzy Pizłovor 11 Monaten

@per_arneng Yeah. Games for example

Profilbild von Slendi
Slendivor 11 Monaten

Is this also memory safe with things like data races?

Profilbild von Filip Jerzy Pizło
Filip Jerzy Pizłovor 11 Monaten

@xslendix Yes

Profilbild von Nyx
Nyxvor 11 Monaten

Very nice demo, and this looks great. I’m curious what the output of that stack traces is when you don’t include debug information, or does fil-c always embed debug information?

Profilbild von Filip Jerzy Pizło
Filip Jerzy Pizłovor 11 Monaten

The file name and line number become “<somewhere>” Inline frames are collapsed. But at least currently, I still keep function names. I might add an option to strip those (folks wanting minimum footprint will appreciate that)

Profilbild von Nyx
Nyxvor 11 Monaten

I do have a concern though that it would open the executable up to easier reverse engineering. But that is a different issue and the goal is memory safety.

Profilbild von muxcore
muxcorevor 11 Monaten

Very cool!

Profilbild von iru@localhot
iru@localhotvor 11 Monaten

> mfw I heard SystemV. > mfw I have no face

Profilbild von spacemonkey
spacemonkeyvor 11 Monaten

Awesome

Profilbild von Darren Shepherd
Darren Shepherdvor 11 Monaten

@awesomekling I'm gonna be the guy that ignores all this incredible work that clearly took an immense amount of time to create and only comment on the squeaky chair.

Profilbild von t
tvor 11 Monaten

why does rust even exist XD

Profilbild von Richard L ✈
Richard L ✈vor 11 Monaten

@chromatic_x @xorloser

Profilbild von Daniel Cook
Daniel Cookvor 11 Monaten

Probably would be even more useful to have a fil-c user space in a docker container

Profilbild von Filip Jerzy Pizło
Filip Jerzy Pizłovor 11 Monaten

What would be the value of having the memory safe stuff inside a container? I imagine you might want the opposite: - Your host OS has a memory safe userland - If you want to run unsafe code (for perf reasons) you do it in a container

Profilbild von Daniel Cook
Daniel Cookvor 11 Monaten

To make it easier to cross compile stuff when you need access to a bunch of system packages through pkg-config

Profilbild von 2disbetter
2disbettervor 11 Monaten

Excellent work and thanks for sharing! Any chance you wanna take on another DE / composter and push further into userland? If that is a silly question, let me rephrase: what is the next step?

Profilbild von Filip Jerzy Pizło
Filip Jerzy Pizłovor 11 Monaten

Next step is web browser

Profilbild von 𝒢𝒾𝒷𝓇𝒶𝓃 😈 🏴‍☠️@geebee@bsd.network
𝒢𝒾𝒷𝓇𝒶𝓃 😈 🏴‍☠️@[email protected]vor 11 Monaten

@awesomekling Great work 👏

Profilbild von Max Kupriianov
Max Kupriianovvor 11 Monaten

Awesome background!! but, with all seriousness thanks for the rundown, really provides very useful context for understanding.

Profilbild von John Doe
John Doevor 11 Monaten

👀

Profilbild von 𝐃𝐫. 𝐀𝐛𝐢𝐢𝐫𝐚 𝐍𝐚𝐭𝐡𝐚𝐧
𝐃𝐫. 𝐀𝐛𝐢𝐢𝐫𝐚 𝐍𝐚𝐭𝐡𝐚𝐧vor 11 Monaten

Video quality too low.

Profilbild von Sal ꙮ
Sal ꙮvor 11 Monaten

This is great! Is there a write up somewhere describing how invisicaps are actually implemented? IIUC, they are created/used at runtime, not compile time.

Profilbild von Shantanu Gadgil
Shantanu Gadgilvor 11 Monaten

Would you consider uploading this to YouTube as well? (easier to share a "here, watch this" link with folks) 🙂

Profilbild von Richard L ✈
Richard L ✈vor 11 Monaten

@ooPo

Ähnliche Videos