3 ms·
Related, hardbool, it seems gcc can automatically handle this soon. https://blog.adacore.com/adacore-enhances-gcc-security-with-innovative-features https://blo
by stressinduktion 3y ago
Related, hardbool, it seems gcc can automatically handle this soon.
https://blog.adacore.com/adacore-enhances-gcc-security-with-innovative-features https://blog.adacore.com/adacore-enhances-gcc-security-with-... and https://gcc.gnu.org/onlinedocs/gcc/Common-Type-Attributes.html#index-hardbool-type-attribute https://gcc.gnu.org/onlinedocs/gcc/Common-Type-Attributes.ht...
- loeg 3y agoNot exactly; these constants in sudo are an enum of sorts (actually preprocessor macros). It's not just bool (and won't just be bool in many situations). It is cool to see GCC exploring automatic protection in this space; I just don't think it is relevant to what sudo did here.
- IshKebab 3y agoHardbool lets you use custom true and false representations with higher hamming distances. The sudo patch uses custom representations for their enum that have higher hamming distances. The only difference is that hardbool is for true/false and this patch is for AUTH_SUCCESS/AUTH_FAILURE/AUTH_ERROR etc. But that's irrelevant. It's the exact same technique.
- loeg 3y ago> The only difference is that hardbool is for true/false and this patch is for AUTH_SUCCESS/AUTH_FAILURE/AUTH_ERROR etc. But that's irrelevant. It's very relevant! The problematic comparison in this code isn't true/false! A feature that only protects true/false does not help here.