4 ms·
This is yet another unsafe language bug. I know it's no easy task, but the sooner Apple gets iOS rewritten in Swift the better.
by zionic 6y ago
This is yet another unsafe language bug. I know it's no easy task, but the sooner Apple gets iOS rewritten in Swift the better.
- jangoolie 6y agoThis bug is just as easy to express in Swift. To eliminate this class of bug you need to eliminate statements, such as in Haskell.
- NotSammyHagar 6y agoyou'll have to explain for that to mean anything. The associated web page doesn't give any information. Also what do you mean by removing statements.
- warkdarrior 6y agoNot sure how an Out-of-Bounds write (used in this exploit) could happen in Swift.
- RubenSandwich 6y agoI'm sorry but that is likely never going to happen. iOS is a custom version of OS X, which is a fork of FreeBSD. That C is likely never going to be completely replaced. I love Swift, it's a great language, but we shouldn't rewrite our stacks every time a better language comes out. This is where the engineering trade-offs come in. Maybe over time, but over a long period of time.
- xvector 6y agoI think you are correct in saying that iOS will never get rewritten. But I think that you are incorrect in saying that it shouldn’t get re-written. Memory-safety is a compelling reason to re-write something. It’s not just a flavor of the month thing, there are real and large security benefits to rewriting your shit in a memory safe language. Honestly for any large projects (ie scale of iOS) it is amusing to see people think that they can forego a memory safe language and still be “secure.” Subscribe to the iOS discloses vulnerability mailing list and take a look at how many of those vulnerabilities are because of the lack of memory safety. Hint: it’s often the vast majority of them.
- resist_futility 6y agoWhat does not checking a syscall error have to do with the language?
- a_t48 6y agoNot sure if Swift has the mechanisms to do it, but for example, you could wrap your syscalls in something that requires an error to be checked. In C++ it can only be a runtime check (outside of extensions?). I _think_ Rust might allow a compile time check but I don't remember which mechanism you'd do it from. Don't know about Swift. Edit: of course you're always allowed to check and discard the error. No language can stop people from purposefully shoot themselves in the foot, but at least safeties can be installed.
- fools 6y agoRust has compile-time warnings for when you don't use the result of a function whose return type is marked as #[must_use]. You can easily silence such a warning by writing `let _ = f(...)`, though, but I don't think that's a bad thing.
- detaro 6y agoC++ has the nodiscard attribute for this now.
- saagarjha 6y agoFunctions in Swift must be annotated to allow discarding their results without a warning.
- cozzyd 6y agoAt least on on my system, ftruncate is annotated with __wur, so a simple -D_FORTIFY_SOURCE would suffice to produce a warning in this case.