Python bytecode is heavily trusted by CPython
utcc.utoronto.ca
utcc.utoronto.ca
The design of the Lua language and VM is almost unimaginably simpler than Python. If Lua gave up on this goal, I strongly suspect that no language VM will succeed at having safe bytecode unless the bytecode is specifically designed for security (and such a design would probably involve performance compromises to get this level of security).
For example, https://developer.chrome.com/native-client/community/securit... lists 20 holes. I think the actual number of explicitly discovered holes in CPython and Lua bytecodes are each less than 20, and that was enough for them to give up.
Even just mov or lea are Turing complete.
I thought the verifier had been removed last time I checked, but it looks I misremembered that.
Many holes have been found in the verifier over the years. More probably remain, although at this point JIT compiler bugs may be a more significant attack surface.
http://www.brendangregg.com/blog/2015-05-15/ebpf-one-small-s...
https://www.kernel.org/doc/Documentation/networking/filter.t...
"I wouldn't be surprised if hand-generating crazy instruction sequences could do things like crash CPython"
To me is the same as
"I wouldn't be surprised if hand-generating crazy instruction sequences could do things like crash an ELF executable"
Or, what happens if you feed bad code to a JVM?
Both the JVM and CLR have a verifier.
Useful verifiers exist. Coq is a state-of-the-art verifier for a large class of propositions. It hasn't been easy to create. Its design is not frozen.
We need to create a specification for safe remote code that is trustworthy. This seems difficult when permitting all the remote code capabilities that we want.
We need to demonstrate constructing specification-compliant code for a nontrivial algorithm with a proof of compliance. This seems costly but feasible.
If so, this bug report would be a lot more serious. I think no-trivial CMS app server is writting in python.
Obviously not, that would be the biggest security hole ever even without this issue.
> I think no-trivial CMS app server is writting in python.
There are plenty. And are you saying no CMS app should be written in Python because of this issue? Or are you suggesting everyone switch to PHP where it's 100x easier to shoot yourself in the foot (or head)?
1. http://blogs.msdn.com/b/oldnewthing/archive/2006/05/08/59235...