4 ms·
Sure, I get it. Perhaps I phrased my response poorly. This comment: > What needs to die is the belief that you can rely on just software (i.e. memory safety)
by twtw 8y ago
Sure, I get it. Perhaps I phrased my response poorly.
This comment:
> What needs to die is the belief that you can rely on just software (i.e. memory safety) for isolation between trusted and untrusted code
is an argument that doubting if statements should be acceptable, and that the assumption that only B has architecturally visible side effects when A is true is not sound. I disagree strongly with that.
You should be able to rely on software checks for some things. Going forward, the solution is not to rewrite software to not depend on software mechanisms (e.g. bounds checks) for protection (unclear what would be used instead...) but to fix the hardware so these software mechanisms work.
What needs to "die" is not "belief that you can rely on just software," but hardware that violates fundamental guarantees.
It sounds like we agree on this, I just wanted to make my point clear since I see now that my original comment was not clear.
FWIW, this is essentially the argument Torvalds made when Intel tried to add feature flags for non-broken speculation.
- gpderetta 8y agoI don't think Linus has any expectation that spectre v1 will ever be fixed in hardware.
- loup-vaillant 8y agoThere's a difference between what you expect, and how you think things should be. Linus was probably making a normative statement, not a prediction.