3 ms·
Can Wuffs provide stronger safety guarantees than techniques like WasmBoxC? My understanding is that compiling unsafe C to WASM and back would also guarantee s
by refibrillator 2y ago
Can Wuffs provide stronger safety guarantees than techniques like WasmBoxC?
My understanding is that compiling unsafe C to WASM and back would also guarantee safety with respect to buffer overflows, integer arithmetic overflows and null pointer dereferences.
It’s nice not annotating code to explicitly prove invariants to the compiler like you would in say Wuffs or Rust, but I suppose that’s what limits performance.
- klabb3 2y agoDoesn’t wasm have a memory model as well? So unless you sandbox certain parts of it you can still in theory have access across different C functions, within the same wasm module? What seems nice about wuffs is that it has no side effects and a clear project scope. Deserialization is so riddled with severe issues that it does kind of warrant its own DSL. OTOH, some legacy formats will probably never be ported.
- CJefferson 2y agoTechnically, while WASM promises you put data in and get data out, you can still have memory corruption (as it has a flat memory), so I could make a (for example) gif with some color palette, then later overflow and rewrite the palette. Not fatal, but perhaps annoying.
- azakai 2y agoYes, Wuffs can do better than WasmBoxC because it does more than sandboxing of the code. It also checks things like integer overflows which can lead to exploits that are technically not memory safety issues, but still potentially dangerous. But the tradeoff is that you need to rewrite your code for Wuffs, while WasmBoxC can sandbox anything that compiles to wasm and prevent it from corrupting the outside, including existing code in C, C++, Zig, unsafe Rust, etc. etc.