4 ms·
True, and False. You're projecting your own experience. I have a pretty good idea what decent C looks like, as does anyone else who spent 30 years using it.
by sifoobar 8y ago
True, and False.
You're projecting your own experience.
I have a pretty good idea what decent C looks like, as does anyone else who spent 30 years using it.
- pjmlp 8y agoIn spite of all those quality gates before a C patch lands in the Linux kernel, the CVE reports just keep increasing. Source, the Linux Kernel Summit 2018 and the Google sessions on kernel security.
- sifoobar 8y agoProgramming is difficult, writing kernels even more so; hence there will be bugs. It's not a language issue.
- baby 8y agoit is a language issue
- pjmlp 8y agoGoogle and a large majority of Linux kernel developers think otherwise hence Kernel Self Protection Project. According to Google 68% of 2018 CVE's were caused by C's lack of bounds checking. Google is also collaborating with ARM on their memory tagging extensions to tame C. Like everyone else you can go watch the Linux Kernel Summit 2018 talks. Oracle also thinks otherwise, hence Solaris with SPARC ADI memory tagging turned on by default. DoD has a report where UNIX typical exploits weren't possible in Multics thanks to PL/I instead of C. https://multicians.org/b2.html https://multicians.org/b2.html