5 ms·
Third party crates can include malicious safe code that doesn't exploit any soundness bugs, so I'm not sure how exploiting soundness bugs could make the situati
by devit 7y ago
Third party crates can include malicious safe code that doesn't exploit any soundness bugs, so I'm not sure how exploiting soundness bugs could make the situation worse.
It's only a problem if you try to restrict I/O APIs and use the Rust type system as a security boundary, which is something that I don't think anyone does and that should not be done since the surface area is too vast to secure without formal proofs of the whole Rust stack, which are too time-consuming to produce with current technologies.
- __s 7y agohttps://www.tockos.org https://www.tockos.org does what you think nobody does
- dethinking 7y agoTIL, and since it’s buried a bit: > A capsule is a Rust struct and associated functions. Capsules interact with each other directly, accessing exposed fields and calling functions in other capsules. Trusted platform configuration code initializes them, giving them access to any other capsules or kernel resources they need. Capsules can protect internal state by not exporting certain functions or fields. > ... > Rust’s language protection offers strong safety guarantees. Unless a capsule is able to subvert the Rust type system, it can only access resources explicitly granted to it, and only in ways permitted by the interfaces those resources expose. However, because capsules are cooperatively scheduled in the same single-threaded event loop as the kernel, they must be trusted for system liveness. If a capsule panics, or does not yield back to the event handler, the system can only recover by restarting. I take it from the present discussion that that might not be as good of an idea as they think. Worth noting that they also have process isolation on top, but it doesn’t seem to be motivated by any potential insecurity of the type system.
- staticassertion 7y agoI don't get how that's ever possible, regardless of soundness issues. Can you not simply use unsafe in a capsule, and violate this constraint? The only way isolates in V8 manage to provide any isolation is because the runtime/ language forbid such things entirely. I suspect it is not so simple as "Rust's safety ensures malicious rust code can't access data".
- __s 7y agoCapsules aren't allowed to use unsafe. The target of tock is not generally going to be out of order, so spectre things shouldn't occur
- staticassertion 7y agoIs there a doc about that? Can they also not use external crates? Very curious.
- __s 7y agoThere's a blog post https://www.tockos.org/blog/2017/crates-are-not-safe https://www.tockos.org/blog/2017/crates-are-not-safe Lots of example code https://github.com/tock/tock/tree/master/capsules https://github.com/tock/tock/tree/master/capsules
- staticassertion 7y agoThank you.