5 ms·
Favorite bit: "What if the 432 had won? Computing would be very different. Many security problems wouldn't exist. You can't have a buffer overflow because every
by Zanni 3y ago
Favorite bit: "What if the 432 had won? Computing would be very different. Many security problems wouldn't exist. You can't have a buffer overflow because every data structure is a separate object with memory segment size enforced in hardware. You can't smash the stack or make bad pointers."
In the early 80s, speed was everything and security a non-issue. LANs hadn't even taken off yet, let alone the internet. But that's almost flip-flopped today.
- WorldMaker 3y agoI'm really curious at this point what would happen if someone tried to resurrect a design like the 432. Maybe not the 432 exactly because things like bit-aligned instructions are still awkward/weird and didn't turn out to be as useful as the designers hoped. (It seems like an obvious compromise because object-tagging taking so much RAM in an era where RAM was so expensive it is an easy bet that they felt a need to nickel and dime/golf program code size, if they could.) But even just reusing the architecture as-was, it would certainly be cheaper and need fewer chips today. It might be fun to have a cheap Raspberry Pi-like board with a 432 to experiment coding against.
- kens 3y agoThe ironic thing is that the performance analysis paper [*] found that the weird bit-aligned instructions iAPX 432 didn't actually help code size. "Although the 432 has bit-variable length instructions, it requires more space than either the 68000 in Pascal or the VAX in C. Reasons include the lack of immediates and the inability to refer to a local variable or constant using fewer than 16 bits of address." (From a modern perspective, the test programs are absurdly small: 120-2900 bytes. Nowadays, you probably couldn't even create a program that small.) [*] https://archive.org/details/PerformanceEvaluationOfTheIntelAPX432/page/n3/mode/2up https://archive.org/details/PerformanceEvaluationOfTheIntelA...
- bbatha 3y agoThe CHERI extension for ARM does this: https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/ https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/. The Rust language is experimenting with adding language level pointer provenance apis that provide the same info to the compiler, and would presumably compile to the instructions if available, https://doc.rust-lang.org/nightly/std/ptr/index.html#strict-provenance https://doc.rust-lang.org/nightly/std/ptr/index.html#strict-...
- Joker_vD 3y agoWell, I can make a guess: the experience of porting existing C code to it would be a horrible experience so it would never take off the ground because, you know, nobody ain't got time to rewrite the whole world from scratch.
- WorldMaker 3y agoMy curiosity has nothing to do with running existing C code. The reference to Raspberry Pi should have made that obvious, I think. The idea would be to have something to play with as a hobbyist. Something to develop new compilers for to see what you can build and if what you can build is fun/interesting, even if it doesn't have commercial aspirations or "productive" uses and is only ever a "toy". You know, hobbyist fun.
- Joker_vD 3y agoAh, well, that you can do this with FPGA prototyping even today, you know.
- WorldMaker 3y agoThat is something that I know. That is why I suggested it might be cheap to explore the concept (at the bottom of my post) and part of why I'm curious to see others try. I personally have college experience in FPGA prototyping but primarily have focused my efforts on software development then and since, I wouldn't have much fun myself building an FPGA prototype of something like the 432 by myself. But if someone sent me a cute RPi-like board and an okay (doesn't have to be great) assembler/debugger for it, I'd certainly give it a try seeing if I could assemble something interesting like a compiler for a next higher-level language. If that same someone were to build enough of the boards to build an entire community of hobbyist developers more than just me, that would be even better and really interesting and the biggest reason to mention it as a curiosity on a site like this, not to do a one-off thing to scratch a personal itch but to wonder what a community of hobbyists could do together as a group.
- sounds 3y ago
- helf 3y agoI have wondered the same thing. I would adore to have the knowledge to resurrect stuff like this. Something I’ve always wanted to do is revamp ISAs like the 432 or DEC J-11 etc. on modern process nodes and see what kind of performance could be eked out.
- rwmj 3y agoWhat would have actually happened is once the first programmer realised you could get a speed bump by putting all your objects inside a single segment, we'd have been back to where we are now. Which is roughly what happened to the 286 which borrowed some of the 432 concepts -- every practical OS ignored the call gates, segments, and all but two of the rings.
- pjmlp 3y agoThat is what happens without liability, finally cybersecurity laws are fixing this.
- AnimalMuppet 3y agoThey are? In what jurisdictions?
- pjmlp 3y agoUS and EU,slowly getting there. https://www.sonatype.com/national-cybersecurity-strategy-what-you-should-know https://www.sonatype.com/national-cybersecurity-strategy-wha... https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act https://digital-strategy.ec.europa.eu/en/library/cyber-resil... The rest will follow.
- AnimalMuppet 3y agoThat doesn't seem to point me to any actual laws in the US...
- pjmlp 3y agohttps://www.whitehouse.gov/briefing-room/statements-releases/2023/03/02/fact-sheet-biden-harris-administration-announces-national-cybersecurity-strategy/ https://www.whitehouse.gov/briefing-room/statements-releases... > Shifting liability for software products and services to promote secure development practices; and,
- pjmlp 3y agoReally? "A consequence of this principle is that every occurrence of every subscript of every subscripted variable was on every occasion checked at run time against both the upper and the lower declared bounds of the array. Many years later we asked our customers whether they wished us to provide an option to switch off these checks in the interests of efficiency on production runs. Unanimously, they urged us not to--they already knew how frequently subscript errors occur on production runs where failure to detect them could be disastrous. I note with fear and horror that even in 1980 language designers and users have not learned this lesson. In any respectable branch of engineering, failure to observe such elementary precautions would have long been against the law." C.A.R. Hoare in his 1980's Turing Award speech. In 1988, Morris Worm takes over UNIX https://en.m.wikipedia.org/wiki/Morris_worm https://en.m.wikipedia.org/wiki/Morris_worm
- aidenn0 3y agoOn a side note, my dad observed that when he was getting his Master's degree in CS, they had to read Hoare's CSP paper. He said the class was divided into two groups: those who didn't understand it, and those who thought the problems with mutable-by-default multithreading could be solved with proper programmer discipline.
- kps 3y agoI might argue that those who thought the problems with mutable-by-default multithreading could be solved with proper programmer discipline also didn't understand it.
- gonzo 3y agoI think this was the joke..
- Someone 3y agoBut it can be solved trivially with proper discipline. ‘Mutable by default’ implies there’s a way to make things immutable, and proper discipline can make everything immutable. The problem is that no human can maintain proper discipline at all times, and it takes only one slip to create a bug. And yes, programmers doing that would soon realize that ‘immutable by default’ leads to a better UX of a programming language. It’s way easier to be alerted by a warning ‘mutable’ keyword than by a missing ‘immutable’ one) That’s why we should have linters that flag all missing ‘immutable’ annotations or incorrect usage of ‘mutable’ ones. Rust even adds something like that to the language.