3 ms·
No, you would be changing how the wasm module operates in its own address space. You aren't changing how the VM runs. As far as I know wasm never made any pro
by pravus 3y ago
No, you would be changing how the wasm module operates in its own address space. You aren't changing how the VM runs. As far as I know wasm never made any promise against self-modifying code and I don't even understand the threat model you think exists since everything is isolated.
If you have specific security concerns, you should be showing actual attacks against wasm runtimes or somehow show that the security model of wasm as a whole will always reduce to an insecure configuration. What you have shown is something that is "exploitable" on pretty much every architecture I know of.
- eyberg 3y agoWell no it is not. You can't run that on linux which I'd imagine most people who are wanting to do server-side wasm are coming from. This is another issue: #include <stdio.h> #include <stdlib.h> int main() { char *s = "world"; s[0] = 'o'; s[1] = 'w'; s[2] = 'n'; s[3] = 'e'; s[4] = 'd'; printf("Hello, %s\n", s); }