C can be memory safe
blog.erratasec.com
blog.erratasec.com
I feel like the author misunderstands what a "core principle" is. This here is (at most) a bitter lesson learned from several decades of experience. It's not a principle, it's at best a conclusion following multiple stories of getting rid of legacy systems, but even as that this is highly dubious.
And a perfectly valid way of dealing with it might be to throw it away and rewrite it. That's not a choice to be taken lightly, to be sure, but it's complete nonsense for the article author to suggest it isn't an option.
https://learn.microsoft.com/en-us/cpp/code-quality/understan...
But yes, C can be memory safe. It’s just harder than the post makes it seem.
Also C & C++ are different languages. C++ is larger but accepts change more readily, C is much smaller but is much more resistant to change.
https://news.ycombinator.com/item?id=40732745 https://embeddedor.com/blog/2024/06/18/how-to-use-the-new-co...
This would if it could be applied to parameters and local variables would allow the expression of the same relation to the compiler as CHK_SIZE and CHK_INOUT_SIZE though they would be annotations applied to pointers and arrays that refer to count variables rather than an annotation applied to the count variable.
This is very much a "we have memory safety at home" situation.
Say what? The -singular- core principle? Of computer science? I've never seen this principle written down in any computer science book.
Compatibility is something that users -and therefore vendors- care a great deal about, but don't confuse that with computer science.
At any rate C is inherently unsafe for a lot of reasons that cannot be made to go away.
I mean sure, feel free to continue writing it, nobody else cares, but let’s not pretend it doesn’t have rampant issues.
And I do.
We have to stop the problem at the door, not let it in and try to pacify it after it has destroyed half the room.
What a nonsensical article. I mean yeah, guns with the safety off are perfectly safe if 100% of all users have perfect trigger discipline, right?
Basically, create a memory pool.
Then all memory operations such as malloc and free are associated with that memory pool.
When you were done, you could release the memory pool and everything, every allocation, would magically be cleaned up.
It probably makes more sense in the context of a web server request... the request gets a memory pool, all memory allocations/deallocations belong to it, and if there is some sort of error, everything is easily cleaned up.
It empowers programmers. At the cost of requiring careful programming.
It's like very sharp blades. Use them judiciously, and you'll get your job done fast and precise. Forget about checking everything and you'll start bleeding.
...wat
The conflating is no doubt coming from how many cs programs heavily comingle computer science with vocational training for becoming a programmer, but they're not the same thing.
"If you would only code in Rust, you wouldn't have to fix those bugs." To which Diogenes replied: "If you would only fix those bugs, you wouldn't have to code in Rust."
Of course, this argument is silly. The absolute number of knives are used safely and without issue in the overwhelming majority of cases.
Yes, there are times when someone was sloppy and sliced open their hand, but that doesn't make vigilance a failed solution to tool safety. The accidents that occur with them are in the realm of tolerable risk.
C is fundamentally no different. The simplicity comes with footguns that frequently go off when used by people that don't treat them with respect and sometimes even when they are being treated with ample respect.
Although, now that I think of it, bicycles are probably a better metaphor. It's a simple, unshielded vehicle designed not for safety but for getting you where you need to go. Accordingly, riding a bike without crashing requires understanding numerous edge cases that if not respected will end with you grievously injured and sometimes even with respect you won't escape crashing. This is such a truism in cycling communities that they say as a mantra "It's not a matter of if you crash, but when."
You also have the subset of cyclists that ignore laws when using them and endanger themselves and others. Should we then ban bikes because precaution is a "failed solution" to prevent crashing and responsible use? Probably not.
[0] https://www.jem-journal.com/article/S0736-4679(12)01624-1/ab...
It is not argument, it is analogy - made-up scenario.
The work safety world disagrees with that thinking. And several workers pay with very painful consequences when they override safety to make things easier.
And my advice for those who don't believe me is to go play and cut a tree with a chainsaw with a disabled kickback break and guards.
The Early performance results from the prototype Morello microarchitecture report [4] predicts the overhead between 1.8% and 3.0%. We don’t know what that overhead would be in production until such a commercial implementation is delivered but we have enough evidence it is worth the effort with the current estimates and given that CHERI can deterministically prevent around 2/3 of memory-safety-related vulnerabilities [5], not to mention benefits of mitigating future unknown vulnerabilities with compartmentalisation.
[1] https://github.com/riscv/riscv-cheri
[2] https://codasip.com/solutions/riscv-processor-safety-securit...
[3] https://www.sunburst-project.org/
[4] https://ctsrd-cheri.github.io/morello-early-performance-resu...
[5] https://msrc.microsoft.com/blog/2020/10/security-analysis-of...
Fil-C is more than just ideas though.
Sufficiently carefully written C can execute without memory errors, in exactly the same way that sufficiently carefully written assembly can be. That's not a memory safe language, it's a program which manages to not corrupt its own state.
There are compiler flags, sanitisers, static analysis, testing strategies and so forth to help one write something in C that doesn't fall over unexpectedly, but even with absolutely all of it implemented you still don't have a memory safe platform to build on.
https://producingoss.com/en/forks.html#:~:text=A%20hard%20fo....