4 ms·
but if sudo was written in java we'd have other problems ;)
by thr0wnawaytod4y 4y ago
but if sudo was written in java we'd have other problems ;)
- jerf 4y agoYes, I agree. I did not mean to imply that literally any other language would have been better for sudo, which I see is a viable reading of my original post. Go, for instance, would be a terrible choice, because the way the runtime deeply assumes you're running in a multithread environment, even before it gets to your "main" function, means that exactly the sort of UNIX hackery sudo is designed to do is effectively impossible. I have a system myself that is otherwise entirely in Go, but we have a very small C-based wrapper whose job it is to be setuid, open a few files with the escalated privileges, do some user verification, then change its uid and gid and exec the "real" Go program, because Go just can't do those things. Dynamically typed languages as a whole would be a bad idea. Java's startup time for such a small executable would be a problem. I'm just saying this problem is unique to C, and in my opinion, sufficiently endemic to security software to disqualify it entirely. Mind you, you might well end up at Rust in the end anyhow. Perhaps D. It isn't necessarily a long list for a sudo replacement. But... C delenda est.
- pjmlp 4y agoIn a way it is kind of an ironic tragedy, that the followers of C church worship UNIX and Plan 9, while ignoring the end station from the priesters, Inferno and Limbo, where C was confined to the minimal trust base of the kernel and a couple of drivers, with everything else in userspace mostly written in Limbo. Here is "runas" in Limbo, https://bitbucket.org/inferno-os/inferno-os/src/master/appl/cmd/runas.b https://bitbucket.org/inferno-os/inferno-os/src/master/appl/...
- pjmlp 4y agoDo you know one of the reasons why Multics had a better security score than UNIX on DoD assement? PL/I does bounds checking by default.
- titzer 4y agoFor reals. The fact that C toolchains have never even offered a bullet-proof bounds-checked (no UB) mode, no matter what the slowdown, boggles the mind. For something like sudo, literally running 100x slower would not be an issue. Its highest priority should be security.
- encryptluks2 4y ago100x slower would definitely be an issue. I am prompted for my sudo password probably 30x daily.
- bee_rider 4y agoHow long does sudo take to load on your system. Multiply that by 3000, is it really a noticeable number?
- Izkata 4y agoSeems to float around 0.005s (using "time sudo -k" to avoid timing user input), so yeah, x3000 = 15 seconds. Very noticeable. Or even the x100 from (G)GP, that's a half second. Sometimes spiking to a full second.
- titzer 4y agoI am seeing an average of 0.0008 over 100 runs on Linux (i.e. less than a millisecond).
- tmtvl 4y agoCareful, admiral Hopper will give you an earful if you disrespect milliseconds.
- dathinab 4y agoI have once seen a proposal to make any sudo call wait for 10 seconds before doing anything so that the person running it has a moment to thing about what they just did do (and have ~10 seconds to ^C cancel it). The person arguing also brought up that normally anything needing sudo should be automatized so that should be fine. I'm not doing enough system administration to judge if that is a sane idea or not ;=)
- deleted 4y ago[deleted]
- kaba0 4y agoLike what? It would be written once correctly and work as is intended pretty much forever.