4 ms·
Large parts of the OS and services like binder DEFINE memory safety. They twiddle the bits to setup the MMU, as well as the functions and data structures for th
by vitiral 2y ago
Large parts of the OS and services like binder DEFINE memory safety. They twiddle the bits to setup the MMU, as well as the functions and data structures for the allocator/etc. Binder, as I understand, is an interface that accepts internal pointers.
There is no automatic memory safety from a language like Rust here. It's not so simple.
Now, perhaps some part of the system could be defined in a memory safe language. That might be good. But not this part.
- chc4 2y agoWell, sort of. There definitely have been bugs in Binder related to it incorrectly mapping physical pages, which it needs to be doing as part of its core behavior, and is essentially a logic bug with memory safety implications that Rust fundementally can't defend against. The bug highlighted in the article, and the vast majority of other historical Binder bugs, aren't that though: they are "normal" object lifecycle bugs, related to improper locking, resource cleanup, and error handling. Those bugs very much could be prevented almost entirely with Rust or any other memory safe resource management. In fact, they have rewritten Binder in Rust, with it being the example driver usecase for the Rust-in-Linux push.