5 ms·
I find this fascinating and am a big supporter of FSF and GNU. All that said, I am not an expert so would like to learn more. Can somebody let me know why one
by math-dev 5y ago
I find this fascinating and am a big supporter of FSF and GNU.
All that said, I am not an expert so would like to learn more. Can somebody let me know why one cannot just take the assembly version of an existing compiler and carefully review its code to be happy with it and then build everything from that verified compiler? Why does it need so many steps?
- 1MachineElf 5y agoI think you might find an answer for that question in the GCC 4.7 step. They target that version because all GCC versions afterwards include a C++ compiler in addition to the C one. Each successive step is a greater level of complexity. By starting small in the beginning, they have a codebase that is easier to audit than a full blown "modern" GCC or LLVM. That's the idea, at least.
- apaprocki 5y ago> all GCC versions afterwards include a C++ compiler in addition to the C one GCC 4.7 is the last version that can be built from source using only a C compiler. GCC has long included the C++ compiler inside, but didn’t require one to build until 4.8.
- 1MachineElf 5y agoThank you for the clarification.
- pabs3 5y agoHow do you know the Linux kernel you are running that verified compiler on isn't subverting the compiler? The only way to do bootstrapping sanely is to start from some manually written machine code (not assembler) and eventually reach Linux/GCC/etc. This is the approach being taken by Bootstrappable Builds.
- fatcow 5y ago> Can somebody let me know why one cannot just take the assembly version of an existing compiler and carefully review its code to be happy with it and then build everything from that verified compiler? Why does it need so many steps? Because your current OS to load the assembly code may have been poisoned to present you with a sanitized version on the compiler.
- selfhoster11 5y agoIt's worth noting that the above comment, while it might sound paranoid to some, is IMO entirely justified. I'm 50/50 on whether someone at some point hasn't executed a successful Trusting Trust attack (see Ken Thompson). With modern machines that have megabytes of binary blobs, different co-processors that have access to the RAM while they can't be reprogrammed to be on the user's side, and techniques that can actually tell when sensitive operations are happening, such attacks are becoming more feasible.
- pabs3 5y agoThere definitely have been compromised build toolchains before: https://en.wikipedia.org/wiki/XcodeGhost https://en.wikipedia.org/wiki/XcodeGhost
- selfhoster11 5y agoThank you, I wasn't familiar with this case.
- tremon 5y agoThat's only half of the trusting trust-attack though; the other half is being able to make the compiler compromise propagate itself, i.e. not just inserting any backdoor in compiled code, but inserting itself in any compiler built using the compromised tool.
- selfhoster11 5y agoMobile and Electron apps often weight hundreds of megs. That's enough data to hide an entire classic-style OS in the spaces between the data. While I don't know whether someone did insert such a recursive compiler, they certainly can do it unobtrusively enough that it doesn't raise any suspicion.