6 ms·
United States White House Report on Memory Safe Programming [pdf]
- javier_e06 3y agoA technical report. Page 9: C and C++ are not memory safe. Oh no!
- Infinity315 3y agoThe target audience is not you. It seems to be aimed mostly at C-level execs with less technical knowhow which have less than a CS undergrad's understanding of these issues.
- jvanderbot 3y ago> Rust, one example of a memory safe programming language, has the three requisite properties above, but has not yet been proven in space systems. Sure, but we did run Rust scheduling algorithms on the ISS when I was at JPL. It was a proof of concept, not an actual system, though.
- ahmedfromtunis 3y agoBefore reading the report, I never thought about languages needing to be proven for space. I thought this was only a thing for hardware components.
- steveklabnik 3y agoIn the sense they're talking about, they don't mean "formal proof," they mean "existence proof." It's not like it's a mature choice in the space, is what they mean.
- AceJohnny2 3y agoYeah, MISRA C [1] is a set of rules for writing C for safety-critical environments, originally targeting the automotive environment. If you're used to vanilla C, it can feel very constraining! In the Rust world, there's the Ferrocene project [2], which aims to provide a similar kind of safety-critical level of functionality. [1] https://en.wikipedia.org/wiki/MISRA_C https://en.wikipedia.org/wiki/MISRA_C [2] https://ferrous-systems.com/ferrocene/ https://ferrous-systems.com/ferrocene/
- steveklabnik 3y agoMISRA and Ferrocene are not really related other than both being vaguely in the safety space. MISRA is, as you say, a set of rules for writing C code, that restrict what you can do. Ferrocene is a qualified compiler. You write any normal Rust code you want: it's still the upstream Rust compiler. There are no restrictions. Incidentally, someone has compared what MISRA does to what Rust does: https://github.com/PolySync/misra-rust/blob/master/MISRA-Rules.md https://github.com/PolySync/misra-rust/blob/master/MISRA-Rul... Given that they can't repeat the MISRA stuff there, it's a bit disjoined, but it sure is interesting!
- AceJohnny2 3y agoThanks for the clarification Steve!
- TaylorAlexander 3y agoMy friend at SpaceX told me (rough memory from a chat) that they almost made the flight control software for Starship in Rust but at the last minute someone got cold feet and they went with C or C++.
- appplication 3y agoIt’s probs my the right call in all honesty. Rust is nest but it is very new still. You don’t need that in space critical systems.
- FreakLegion 3y ago> we did run Rust scheduling algorithms on the ISS Actually on the ISS? It's been a while but if I remember right e.g. SACE (EUROPA) planning for the solar arrays happens down here. Transmission time is a fraction of a second, so there was no compelling reason to do the planning station-side. I'm only familiar with that use case, though.
- jvanderbot 3y agoYep right up there. It was a demo of some hardware/software combos for scheduling large numbers of things in situ.
- mikece 3y ago[flagged]
- acdha 3y agoThis seems very odd: shouldn’t you be praising areas where it’s working well and calling for other areas to be more like that?
- nh23423fefe 3y agoThis makes no sense because the legislature sets and spends budgets, while this a document from the ONCD. Why are you pretending "the government" has agency or manages anything. Address the advice instead of posting low effort hate.
- j-j-j-j 3y agoDo you apply the same reasoning when government tells you something else that is obviously true and good advise, e.g. to wash your hands after you used a restroom?
- mrguyorama 3y agoAmerica only seems to work on cash incentives, so they should make some hundred million dollars in grants or so for businesses to "invest" in rebuilding important infrastructure in memory safe languages. I'm not convinced of the memory safe language hype train honestly. Every single application could be 100% bulletproof and we would still live in a world where the CFO downloads a random exe from a phishing email and runs it with admin privileges. That still seems to be the main way institutions and people are compromised. We make jokes about "you can't defend yourself from a nation-state actor" but half the time the primary infection point for everything from North Korea to 15 year old Kevin playing with MyFirstRansomeware is to just put it in an email and let people do the work for you, or copy a log in page and let the user give you their credentials. Edit: lol people very very very angry that I dared to say "hey maybe rust ain't gonna save our world". Jesus guys. Have some nuance.
- acdha 3y ago> I'm not convinced of the memory safe language hype train honestly. Every single application could be 100% bulletproof and we would still live in a world where the CFO downloads a random exe from a phishing email and runs it with admin privileges. Well, if the CFO has admin you’ve already failed several audits but in general, yes, there are multiple categories of risk which you have to protect against. That doesn’t mean it’s not valuable to reduce one of them, however – in addition to the direct risk reduction, it also frees up time to work on the others.
- bongodongobob 3y agoYou have to remember that most businesses don't perform any kind of security auditing whatsoever. Any non-tech business with 50 or less people has gaping security holes. I say that with absolute certainty.
- b112 3y agoI saw someone running win98se 5 years ago, the box seething, writhing in pain with highly apparent malware, as a controller for industry grade, niche market machinery. It was network connected for "the IT company to log in and fix things", had software that would only work in win98se, and because the machine was "in the room", its browser was used because "convenient". No one cared. This is normalcy for most people. Even if the "it only works on bare metal" thing was true, and its hardware key device may make that a reality, there's zero reason to let people browse on it. Or leave it online 24x7, one could bring a switch port up/down when needed. Ah well. As you say, this is normal.
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- odyssey7 3y ago“While formal methods have been studied for decades, their deployment remains limited; further innovation in approaches to make formal methods widely accessible is vital to accelerate their broad adoption.” — White House Well gosh. I applied to US research programs with an interest in formal methods and was rejected absolutely across the board. Good luck to you.
- pizlonator 3y agoThe report gets it wrong. C and C++ can both be made memory safe with small changes. The cost of doing that is likely to be lower than the cost of either deploying CHERI or rewriting in Rust. And, the protections are likely to be stronger than what CHERI offers (CHERI tries really hard to just let existing C code do whatever the heck it does). There's a ton of literature on ways to make C/C++ safe. I think that the only reason why that path isn't being explored more is that it's the "less fun" option - it doesn't involve blue sky thoughts about new hardware or new languages.
- ptx 3y agoWhat kind of small changes? It seems strange to me that other languages would bother implementing complicated garbage collectors and borrow checkers if all you need is a small change from C.
- pizlonator 3y agoSee here: https://github.com/pizlonator/llvm-project-deluge/blob/deluge/Manifesto.md https://github.com/pizlonator/llvm-project-deluge/blob/delug... I just got the OpenSSH client to work last night. Here's an example of the kinds of changes you have to make: https://github.com/pizlonator/deluded-openssh-portable/commit/2362aefc340097af426cde8bcffa466d61b8eaaf https://github.com/pizlonator/deluded-openssh-portable/commi... Most of the changes are just using zalloc and friends instead of malloc and friends. If I reaaaallly wanted to, I could have made it automatic (like, `malloc(sizeof(Foo))` could be interpreted by the compiler as being just `zalloc(Foo, 1)` ... I didn't do that because I sorta think it's too magical and C programmers don't like too much magic).
- ptx 3y agoAttaching capabilities to pointers is sort of what CHERI does, isn't it? And the presumably CHERI can have better performance thanks to the direct hardware support. (Your manifesto mentions a 200x performance impact currently.)
- 3y ago
- _benj 3y agoThis reminds me of a video I watched years ago with uncle Bob talking on a Clean Code talk mentioning that clean code was more than just a method to write code but also a strategy, a guideline if you will for when policymakers wake-up to the fact that the world is run with software and start making policy. It’d most certainly be better if those guidelines come from the industry itself as opposed to being imposed with little notion of how the industry works
- RudyStone 3y agoThis is a duplicate. https://news.ycombinator.com/item?id=39514844 https://news.ycombinator.com/item?id=39514844
- univacky 3y ago<Ada has entered the chat>
- ajdude 3y agoI'm very surprised to see that Ada was not mentioned in this article despite the fact that they brought up rust noting that it hasn't been proven in space while Ada actually has. They already had a incredibly readable memory safe language since the 80s.
- javier_e06 3y agoMy first job was in Ada and by then our customer put a clause allowing C to be introduced where it Ada was difficult to introduced. In our case the Issues with Ada was the poor support of the Ada compiler vendor. The kind of granularity on type definitions in Ada is superb. The type checking was slow. A type can be defined with the number of bits and the range during declaration which makes compilation slow.
- mikewarot 3y agoWe don't have operating systems that limit possible side effects at the discretion of the user at run time. This is the root cause of computer insecurity in the US, and the rest of the world. --- Background --- If I owe you $5.00, I can hand you an $5.00 bill, and that's the maximum I can lose. It's all down to my discretion at the time of the transaction. If I owe you $5.00, and can't use cash, then I have to put a bank account at risk, to make a transaction. There are rules about it, but the risks are far less constrained. The bank enforces my choices, most of the time. If you run a DOS program on an IBM XT with only 2 floppy disks, the only thing it can alter is the contents of any non-write-protected disks that happen to be mounted. It's possible to completely protect the operating system, and run almost any software you want, because the side effects are limited at the discretion of the user.