3 ms·
Doesn't look like it works any more. In any case, Matt Godbolt has spoken a bit about the architecture of Compiler Explorer. Seems like he's given some thought
by foxrob92 8y ago
Doesn't look like it works any more.
In any case, Matt Godbolt has spoken a bit about the architecture of Compiler Explorer. Seems like he's given some thought to security.
https://www.youtube.com/watch?v=bSkpMdDe4g4 https://www.youtube.com/watch?v=bSkpMdDe4g4
https://www.youtube.com/watch?v=nAbCKa0FzjQ https://www.youtube.com/watch?v=nAbCKa0FzjQ
- wyldfire 8y agoIIRC the main sandboxing comes from a wrapper around libc that restricts pathnames used in open() and friends. It seems reasonably well designed for its intent but probably not super difficult to escape. Certainly if the C library adds another entry point, it won't be obvious that there's a new way around. What the Compiler Explorer has going for it in this regard is that there's very little treasure to be found once you escape. No user accounts, no passwords, no security questions, no financial transactions, etc. Compiler Explorer doesn't execute the programs it builds, so the risk is limited to what you can convince the compiler/assembler to do on your behalf.
- twic 8y ago> limited to what you can convince the compiler/assembler to do on your behalf C++ is a not a language where i would have a lot of confidence in that limitation!
- echeese 8y agoWorks for me, you just gotta pass -E in the args. Also need to spell include right.