12 ms·
Checked C
- colejohnson66 10y agomicrosoft.com discussion: https://news.ycombinator.com/item?id=11900009 https://news.ycombinator.com/item?id=11900009
- dogecoinbase 10y agoapplause
- ansgri 10y agoIt would be nice to merge these two submissions' comments.
- christogreeff 10y agoOoh, recursion.
- baq 10y agothe obvious question: how does this compare to rust? it looks like rust and this aim to solve a very similar set of issues in more or less similar way ('static and dynamic checking'). i'd be very interested in a table that compares capabilities of both. of course there's a gigantic advantage of this being C, so in theory valid checked C would be valid C with all benefits of that.
- pcwalton 10y agoWell, this isn't C: it's a different language that extends C. There's a big difference between that and just being C. In particular, valid checked C is not valid C, because checking requires using the language extensions. Regarding the comparison to Rust, Rust prevents use-after-free, while this doesn't seem to from a skim of the paper. Use after free is one of the most, if not the most, common remote code execution security issues in C and C++ code nowadays.
- jjnoakes 10y ago> Use after free is one of the most, if not the most, common remote code execution security issues in C and C++ code nowadays. I'd love to see a citation on this. My gut feeling tells me buffer overruns and integer overflows are seriously in the running.
- jerf 10y agoIt is certainly "one of the most", even if it is not "the most".
- jjnoakes 10y agoI'd love to see a citation on this, as I asked for previously. Repeating the comment I replied to isn't a citation.
- jerf 10y agoThat is somewhere around asking for a citation if the sky is sometimes cloudy. https://web.nvd.nist.gov/view/vuln/search-results?query=use-after-free&search_type=all&cves=on https://web.nvd.nist.gov/view/vuln/search-results?query=use-... Before getting too excited and claiming that it's only 1.3% of all CVEs or something, remember that it's 1.3% of all vulnerabilities. (Especially with the explosion of dynamic web languages, a lot of CVEs aren't really C/C++-related.) There's a power law to these things, so by the power law metric, it's not that far behind "buffer overflow" (6,500 entries), and ahead of the well-known "format string" (577), which is also certainly "one of" the most common C issues.
- jjnoakes 10y agoI'm looking specifically for remote code execution vulnerabilities, which is what the original comment was discussing, and which is a subset of what you posted. And no, this is not like asking for citations for the sky sometimes being cloudy because the original comment didn't say "use-after-free sometimes leads to remote code exploit". This is like asking for citations for a claim like "whenever the skies are cloudy it is due to acid rain more than any other reason". And a claim like that should be accompanied with some citations. Let's have an honest discussion here, or don't bother, please.
- bjourne 10y agoRust's safety comes at a cost as it is not as fast as plain C. If Checked C's checks are run at compile-time it would be as fast as C.
- Animats 10y agoThis seems to be a successor to CCured from 2005, a project partially funded by Microsoft. [1] The general idea is straightforward: "The unchecked C pointer type * is kept and three new checked pointer types are added: one for pointers that are never used in pointer arithmetic and do not need bounds checking (ptr), one for array pointer types that are involved in pointer arithmetic and need bounds checking (array ptr), and one for pointer types that carry their bounds with them dynamically (span)." So this is really a new language derived from C, to which programs can be converted. This is basically a good idea, but it's only useful if pushed hard by somebody like Microsoft. People won't convert without heavy pressure. [1] https://www.cs.virginia.edu/~weimer/p/p477-necula.pdf https://www.cs.virginia.edu/~weimer/p/p477-necula.pdf
- vintermann 10y agoI thought so too, but looking at their paper, they have an impressive survey of prior approaches, and they explain their differences from CCured quite well. CCured used fat pointers, and apparently modified the data pointed to by WILD pointers (something I didn't know). This seems interesting to me. I liked the way CCured did inference to document how you used and abused your pointers, but what it did with that information was maybe not ideal.
- haberman 10y agoA link to the paper you are mentioning would be helpful.
- jsingleton 10y agoThe github repo is the paper: https://github.com/Microsoft/checkedc/releases https://github.com/Microsoft/checkedc/releases
- dragandj 10y agoBeing pushed by Microsoft could be exactly the reason not to convert, for many people. Especially when there is no shortage of alternatives that are backed by a bit more benevolent entities (Rust, and many other less known variants).
- ansgri 10y agoIt is a design goal to allow Checked C to be a subset of C++ too. Interesting. In times when many people advocate a safe C++ subset, Checked C grows the other way, adding C++-compatible notation to represent the most vital things like smart pointers.
- partycoder 10y agoReminds me of Cyclone: https://cyclone.thelanguage.org/ https://cyclone.thelanguage.org/ Many Cyclone ideas made it into Rust. I strongly prefer Rust.
- vintermann 10y agoYou should look at their paper. They have an impressive survey of prior approaches including Cyclone, and they claim that their approach (if I understand them correctly) could allow you to do some things outside of unsafe blocks if implemented in C# or Rust.
- pcwalton 10y agoI don't see any use-after-free prevention here from a skim of the paper, so this doesn't seem to address many of the most important benefits you get from C# or Rust. Use-after-free is not a theoretical problem. All of the Pwn2Own vulnerabilities this year were UAF, for example.
- kbart 10y agoThe idea is nice (although old and tried more than once), but I'm pessimistic as it doesn't seem to be backwards compatible and requires a specific, new compiler. For legacy projects it's hard/impossible to change a toolchain/compiler and for the new projects one can as well use Rust or other modern language.
- rdtsc 10y agoInteresting. I thought Microsoft has stopped liking C a while back. Remember complaining about C99 support in VS and getting a response about "Just use C++ compiler as a C compiler, you don't need C anymore". It took them until VS 2015 finally to support it.
- pjmlp 10y agoVS 2015 still doesn't fully support it as such. People apparently aren't aware that C++14 requires C99 libraries, hence the update. Even the new refactored C library was written in C++ with extern "C" for its entry points. The official wording is that those that still care about C compatibility on Windows should make use of the new clang frontend + Visual C++ backend. MSR and real Microsoft are different business units.
- linkregister 10y agoAlso the DDK (Windows Driver Development Kit) didn't support C++ in any meaningful way. If I remember correctly, all my drivers had to be written in C89.
- pjmlp 10y agoC++ is supported in kernel space since Windows 8.
- satysin 10y agoVS2015 only got support for C99 because of the C++14 requirements.
- deleted 10y ago[deleted]
- eggy 10y agoGood timing for me, since I have been falling back to C for some personal projects. I keep looking at Rust, but I just don't have the time. It would be nice to leverage the experience I already have, and see what Checked C offers.
- markokrajnc 10y agoThis clarifies the need for a more "rust-like" C. I hope something like this will flow into standard C...
- valarauca1 10y agoI wouldn't bet on it. Every safety feature added to the standard since C99 has been quietly dropped by compiler maintainers. People could write safe code in the 70's. The point of C was to write high level (kinda portable) assembly. Not safety.
- vardump 10y ago> Every safety feature added to the standard since C99 has been quietly dropped by compiler maintainers. Can you give one example of this, please?
- valarauca1 10y agoBounds checking interfaces in C99 Support: GCC: Nope, why? Performance concerns MSVC: Nope, why? Performance concerns Clang/LLVM: Nope, why? Performance concerns. [1] [1] LLVM has the op-codes to implement this, but Clang won't emit those op-codes with the c99 switch triggered.
- vardump 10y ago> Bounds checking interfaces in C99 ... are an optional part of C standard library. C11 Annex K. http://www.open-std.org/jtc1/sc22/wg14/www/docs/n1967.htm http://www.open-std.org/jtc1/sc22/wg14/www/docs/n1967.htm So just use a library for those and you get support in every compiler! > MSVC: Nope, why? Performance concerns MSVC runtime library does support an early version of that. Has supported for over 10 years. They contributed it to the standard, I think. Example, sprintf_s, present in MSVC2005: https://msdn.microsoft.com/en-us/library/ce3zzk1k(v=vs.80).aspx https://msdn.microsoft.com/en-us/library/ce3zzk1k(v=vs.80).a... Anything else?
- yitchelle 10y ago
- fithisux 10y agoI wish they supported namespaces.
- chj 10y ago+1
- EugeneOZ 10y agoMicrosoft style - be too closed to adopt existing solutions, always invent own ways/standards.
- vortico 10y agoI've written lots of C and never had problems with buffer overruns, bounds checking, double frees, and other memory issues. Typically at a glance in one's code, I can tell when behavior may be undefined, and once someone has a little experience, they can avoid undefined behavior altogether. Why does so much work go into fixing these problems? In other words, what are some examples of use cases of a stricter language like this, that would be too complicated for human eyes to quickly verify?
- comex 10y agoA constant stream of memory-safety related vulnerabilities get found in popular C and C++ programs, many exploited in real attacks. If you haven't "had problems", then either you're far better than most experienced programmers, or you just haven't had many people examine your code with the explicit intent to cause problems. :)
- vardump 10y agoCan we see some code you've written?
- dchest 10y agoHere you don't check the return value of calloc(): https://github.com/AndrewBelt/bored/blob/master/src/map.c#L33 https://github.com/AndrewBelt/bored/blob/master/src/map.c#L3... and then access it: https://github.com/AndrewBelt/bored/blob/master/src/map.c#L44 https://github.com/AndrewBelt/bored/blob/master/src/map.c#L4... Here if realloc() fails, you'll have a memory leak and, again, accessing NULL later: https://github.com/AndrewBelt/bored/blob/master/src/priq.c#L28 https://github.com/AndrewBelt/bored/blob/master/src/priq.c#L... There is also integer overflow: alloc is int, so if it becomes greater than 2^31-1, it may wrap around [I think signed int behaviour in C is undefined in this case], and you'll allocate fewer bytes than needed, leading to buffer overflow.
- dmytroi 10y agoWell, to be honest, very few programs are able to orchestrate >2GB allocations correctly when complied to 32 bit binary, like Visual Studio linker is not aware of >2GB sizes by default (one need to /LARGEADDRESSAWARE flag for it), which was a trouble for modern browsers because linker was unable to fit everything in limited virtual address space. And another to be honest, very few programs on desktops/mobile are actually checking return values of malloc/calloc, because of amount of data that program operates is usually much smaller than amount of RAM available. It's sure a case for embedded, but you simply usually don't use malloc for embedded.
- legulere 10y agoThis greatly lacks an overview as the specification[1] is very in-depth. I kind of wonder if they're working on automatic conversion tools between C and checked C. At least for ptr<> this should be trivial. If a function does no pointer arithmetic with a * pointer and only uses it in function calls that take ptr<>, can be converted to a function taking a ptr<>. [1] https://github.com/Microsoft/checkedc/releases/download/v0.5-final/checkedc-v0.5.pdf https://github.com/Microsoft/checkedc/releases/download/v0.5...
- stuaxo 10y agoAmazed at the amount of open source coming out of MS these days, very nice !
- fredmorcos 10y agoSo they couldn't be bothered to contribute that directly back to LLVM/Clang or am I missing something?
- notdonspaulding 10y agoBaby steps. The phrase "couldn't be bothered" is assuming a lot of bad faith on Microsoft's part. While I would agree that in times past MS didn't deserve the benefit of the doubt, these days they're a different company. With no special insight into their reasoning, I think the more likely answer to the question, "Why didn't they contribute this upstream?" is probably "Give it time."
- youdeserveit 10y agoDo you make these same kinds of comments about IBM or Oracle? Why do you think that Google made android? You don't seriously think that Google wanted phone's to be "free"? That's just naive. So what? Microsoft wants to make money. Did you think that open source was going to destroy the desire to make money? What about the companies that build computers? Can they make money? Integrated circuits and microprocessor research were funded by military spending. Is that a bigger deal than selling software? What about advertising? Is advertising OK if you use open source software to track people? You're just a d1ck with a boring opinion.
- dang 10y agoWe detached this comment from https://news.ycombinator.com/item?id=11900486 https://news.ycombinator.com/item?id=11900486 and marked it off-topic.
- known 10y agohttps://en.wikipedia.org/wiki/Smart_pointer https://en.wikipedia.org/wiki/Smart_pointer
- youdeserveit 10y agoTheir earlier goal was "make money for shareholders". Their current goal is "make money for shareholders". I know that doesn't fit peoples fever dreams about world domination but that's what they were doing in the 90's. That's what they are doing now. That's what Google is doing. That's what Apple is doing. All of the strategy stuff that you guys attribute to Microsoft, as if it were a single person, are childish naive views of how companies function. Why can't you guys accept "yes" for an answer. They are using Linux. They are contributing code to the Linux Kernel. They have developers contributing to Clang and Docker. They just announced support for FreeBSD on Azure and are supporting that project as well. ITS OVER. Open Source won. It's everywhere. It isn't going away. Maybe you could start hating something else?
- photonios 10y ago> All of the strategy stuff that you guys attribute to Microsoft, as if it were a single person, are childish naive views of how companies function. Exactly this. What's the deal? They open-source cool things, community benefits, they earn money. So what? It's become a crime to earn money?
- darpa_escapee 10y agoSometimes the profit motive incentivizes behavior that is bad for developers and consumers. Shareholders and executives made a lot of money from abusive behavior on Microsoft's behalf in the 90's. It can be argued that behavior wasn't ideal for profits in the long-run, hence their change in tactics. Unfortunately, there isn't much evidence that Microsoft won't return to those highly profitable methods once they're more competitive.
- coredog64 10y agosystemd? (Just kidding)
- dang 10y agoWe've banned this account for being a pro-Microsoft astroturfer who has plagued HN for years. This person (or persons) is an accomplished if not professional pro-Microsoft astroturfer whose "contributions" to Hacker News consist of shilling for Microsoft, slagging Microsoft competitors, and covering their tracks. They've made networks of accounts to reply to each other and create the false impression of conversation. At one point they even created fake female identities to make it look like when we banned them, we were banning women. We ban any account that evidence suggests is part of this campaign or anything similar. Users who think they see signs of this are invited to email us at hn@ycombinator.com so we can investigate. Please don't level accusations of astroturfing at other users in threads, though. For every case like this one that really is astroturfing, there are dozens more of legit users simply holding divergent views. We don't want a culture of accusing others lightly. We detached this subthread from https://news.ycombinator.com/item?id=11900781 https://news.ycombinator.com/item?id=11900781 and marked it off-topic.
- youdeserveit 10y agoMS is using and contributing to Linux, FreeBSD, Docker, Mesos, Hadoop, Clang, LLVM, Java, Eclipse, and C++. They have open sourced .Net and Xamarin. TAKE YES FOR AN ANSWER. It's over. Open Source won. Have a party and wear a little hat. Open source is everywhere and it isn't going away. Yay!!!! What's your problem? Did you just want Microsoft to die? To disappear? You can't always get what you want. But if you try sometimes, you just might find, that...everything you wanted to happen has really happened. Open source has never been stronger.
- NetStrikeForce 10y ago> Linux, FreeBSD, Docker, Mesos, Hadoop, Clang, LLVM, Java, Eclipse, and C++. Sounds like some zealots should keep that list handy, so they can keep their pristine paws far from anything that Microsoft touches.
- dang 10y agoWe detached this subthread from https://news.ycombinator.com/item?id=11900819 https://news.ycombinator.com/item?id=11900819 and marked it off-topic.
- youdeserveit 10y agoHe was disagree with you. I wonder. Are you an unreconstructed Marxist or something? Money isn't incompatible with open source. There are lots of companies making money from Linux and MySQL and you name it. I guess what I'm wondering is, what would the world you want to see look like? Would MS be a non-profit? That's a stance that's arguable. I also think that non-profit companies should play a bigger role in the economy. I don't think that's it though. I have a feeling that you really just don't like the fact that the Windows desktop isn't as configurable as gnome. So eff those guys...and I heard that they are listening to my key strokes...and did you read the Halloween memo?...etc
- dang 10y agoWe detached this comment from https://news.ycombinator.com/item?id=11900806 https://news.ycombinator.com/item?id=11900806 and marked it off-topic.
- c3833174 10y agoDoes it include telemetry calls?
- vasilipupkin 10y agowhy? I mean if you think you really need checked C, then why not just use C++?
- Keyframe 10y agoYou know, some people seem to scoff at replacement Cs. I'm kind of one of them. I know my reason(s) though. It's not about other languages as much as C itself. I've been with it for awful long time now and I used to think I kind of know my way around it. I've changed that line of thinking, because I know it's not true. I make a lot of mistakes, especially considering memory. At least (almost all of) my code isn't public-facing. Since I thought I knew C very well, I came to realisation (due to many memory bugs/leaks) that maybe that's not the case after all. What is it then? I can get performance out of it, lots of it (that's one thing I know to do, somewhat at least). That's when I questioned myself and started thinking that it's not that I know C (I don't, after 20 years or so), but that I am very comfortable with it and I don't want to change that comfort. C++ and 90's traumas and post 90's (STL) traumas had a lot to do with it. Now, I'm fishing out for newer languages that would replace C for me, Rust namely, but I'm still falling back to C all the time. Now, I'm thinking that that's just the way it is. I'm a C programmer and that's how it will stay. At least for a long while. I do and have used a lot (A LOT) of languages in my past, but my core is always C (also first language I've learned). I don't program anymore for a living (I do "creative stuff" in film and tv now), so that is now more prominent than any other time in the past. I do stuff for me only and I can pick and choose whatever I want to - yet, it's always C. Sorry for the "rant".
- kazinator 10y agoAll of the things which the C-like replacements for C are competely missing the point. All their goals can be achieved by using a decent high level language (not "C like"), together with using C for just those parts that have to run fast, or interact with the hardware. "Let's make an improved C, and then write millions of codes in nothing but that" is a myopic non-starter.
- kbenson 10y agoHow does this apply towards library creation, where the code is meant to be consumed by other programs languages? While the total lines of code in libraries is less than that in applications, I would say the relative importance is more. That zlib has a fast and correct implementation matters to a lot of people.
- silent90 10y agoLanguage extension for maintenance of legacy application sounds a little bullsh1t to me. 0) If the application needs checks on anything (at the cost of performance) then higher level language (like C++) should be chosen at design time. No use for new application. 1) Existing applications will NOT port directly. Real-life applications are tightly coupled with supported compiler(s), so the compiler would need the update. Errors/exceptions (like overflows) would need handling and changes in logic. It could only deny read/write from illegal area, but without the feedback. The speed is also a major thing. Boundary check could possible prevent some bugs, but the performance will drop dramatically (example: commonly used libs like OpenSSL). One use case I see is to add an extension (like GCC's for instance) for an existing compiler which does this. User could build a slower debug application and spot the silent errors during testing. An implementation thing, not the language extension.
- Animats 10y agoI had a go at this problem, backwards-compatible safe C, back in 2012.[1] It was discussed on the C standards mailing list, and the consensus was that it would work technically, but was politically infeasible. What I proposed was not too far from "Checked C", but the syntax was different. I'd defined a "strict mode" for C. The first step was to add C++ references to C. The second step was to make arrays first-class objects, instead of reducing them to pointers on every function call. When passing arrays around, you'd usually use references to arrays, which wouldn't lose the size information as reduction to a pointer does. Array size information for array function parameters was required, but could be computed from other parameters. For example, UNIX/Linux "read" is usually defined as int read(int fd, char buf[], size_t len); The safe version would be int read(int fd, &char buf[len], size_t len); In both cases, all that's passed at run time is a pointer, but the compiler now knows that the size of the array is "len" and has something to check it against. The check can be made at both call and entry, and in many cases, can be optimized out. In general, in all the places in C where you'd describe an array with a pointer with empty brackets, as with "buf[]", you'd now have to put in a size expression. You could do pointer arithmetic, but only if the pointer had been initialized from an array, and was attached to that array for the life of the pointer. char s[100]; char* p = s; ... char ch = *p++; Because p is associated only with s, the compiler knows what to check it against. There was more, but that's the general idea. A key point was that the run-time representation didn't change; there were no "fat pointers". Thus, you could intermix strict and non-strict compilation units, and gradually convert a working program to strict mode. This took less new syntax and fewer new keywords than "Checked C". I was trying to keep C style, adding just enough that you could talk about arrays properly in C. [1] http://www.animats.com/papers/languages/safearraysforc43.pdf http://www.animats.com/papers/languages/safearraysforc43.pdf
- peterwwillis 10y agoPerl introduced a "strict" mode a long time ago. Although it doesn't force it on you, virtually all modern Perl programmers use it by default. As an extra security feature Perl also supports "taint" mode, which "taints" all user-supplied data as potentially hazardous to the program. This was used more for CGI, but it's still a simple and powerful security feature. Unfortunately, it was never adopted like 'use strict' was because it would more often get in the way of the programmer.
- ArkyBeagle 10y agoSo databases and browsers are "system software" now?