1,120 karma · joined June 7, 2009
See Vec::into_raw_parts or Box::into_raw for an stdlib analogy.
Yeah, no. This is a coup and they are all in. They would not be this blatant about taking control illegally and fast if they expected to leave any institutions to still enforce the law against them.
I would like to see at least in-process environment modification discouraged. Rust is dealing with the issue by considering getenv unsafe when coming through C, but getting rid of the read side is much harder than the write side.
I'd be interested in a way to do static binary analysis to get from those symbols to a call tree, as well.
I don't see a way to check for **environ usage though, the compiler could turn this one into anything.
I don't know how he hasn't been removed after this.
On the other hand, while I haven't used it for /, dipping my toes in bcachefs with recoverable data has been a pleasant experience. Compression, encryption, checksumming, deduplication, easy filesystem resizing, SSD acceleration, ease of adding devices… it's good to have it all in one place.
fclones group |fclones dedupe
That's been implemented; in Linux 6.11 bcachefs will correct errors on read. See
> - Self healing on read IO/checksum error
in https://lore.kernel.org/linux-bcachefs/73rweeabpoypzqwyxa7hl...
Making it possible to scrub from userspace by walking and reading everything (tar -c /mnt/bcachefs >/dev/null).
Span::add_with_reference(&self, other: &Span, reference: impl Into<SpanRelativeTo>)You may have a mutex on getenv/setenv, like the Rust stdlib does, but when libc doesn't look at that mutex, even on the read side, you run into UB.
So the next step is never calling into seemingly innocent libc functions in safe code (which you have to enforce on your dependencies as well), implementing safe alternatives to a good chunk of libc (and making sure your dependencies use those), to cordon off anything that looks at the environment. This makes a good chunk of POSIX functionality useless.
Quoting an example from https://bcachefs.org/GettingStarted/
bcachefs format /dev/sd[ab]1 \
--foreground_target /dev/sda1 \
--promote_target /dev/sda1 \
--background_target /dev/sdb1
mount -t bcachefs /dev/sda1:/dev/sdb1 /mnt
This will configure the filesystem so that writes will be buffered to /dev/sda1 before being written back to /dev/sdb1 in the background, and that hot data will be promoted to /dev/sda1 for faster access. bcachefs format --help
--promote_target=(target)
Device or label to promote data to on readhttps://hacks.mozilla.org/2021/12/webassembly-and-back-again...
https://web.archive.org/web/20190328010454/https://plus.goog... (via explainkcd)
Any other fun easter eggs in the XKCD counter?
- https://xkcd.com/404/ 404s (obviously)
- https://xkcd.com/1337/ is about hackingThere's also a format string vulnerability that wouldn't exist in Rust and which C turns into privilege escalation instead of aborting.