4 ms·
Rust helps, but isnt immune (e.g. stack overflows). Also, when you're dealing with embedded code, you're very likely going to be using unsafe code (e.g. driver
by TickleSteve 5y ago
Rust helps, but isnt immune (e.g. stack overflows).
Also, when you're dealing with embedded code, you're very likely going to be using unsafe code (e.g. driver level).
With no other protection, incorrectly programming a DMA transfer to trample over code-space is not unknown... and Rust cannot protect you from that.
(Having said that... an MPU window will also not necessarilly catch a bad DMA transfer either).
- zozbot234 5y ago> Rust helps, but isnt immune (e.g. stack overflows). This is a good point but isn't Hubris designed to use statically bounded amounts of memory anyway, like much embedded software? AIUI, this was a key reason for keeping their design focused on synchronized requests, avoiding the hard-to-predict buffering that's needed for supporting 'async' models.
- steveklabnik 5y agoDefense in depth matters. The blog post shows an example of Hubris correctly killing a task that's touching memory it's not supposed to. That "supposed to" was due to a configuration error, but configuration errors can and do happen, and maybe would not be as benign as this one was.