7 ms·
Pizlix: Memory Safe Linux from Scratch
- metadope 10mo ago> Pizlix requires you to set up your machine thusly: > You must have a /mnt/lfs partition mounted at /dev/sda4. should say > You must have a /dev/sda4 partition mounted at /mnt/lfs. Pedantic Sunday: Happy Hanukkah!
- pizlonator 10mo agoOf course you are right!
- kbr2000 10mo agoOr rather: > You must have a filesystem, located on the /dev/sda4 device, mounted at /mnt/lfs. The /dev/sda4 device represents the fourth (primary) partition on the /dev/sda block device, which represents the first SCSI disk.
- hulitu 10mo ago> Supported Systems Pizlix has been tested inside VMware and Hyper-V on X86_64. Any idea if it runs on real hardware ?
- pizlonator 10mo agoI am still just testing it in VMs. The only thing standing in the way of it working on real HW is just making sure the kernel is configured properly for it. Like right now the kernel config file is the result of enabling those things that work on the virtual devices that HyperV and VMware provide. The right answer is modular kernel and something like initramfs and modprobe or whatnot. That kind of work has nothing to do with Fil-C; it’s just distro engineering
- ndesaulniers 10mo ago> The kernel is compiled with Yolo-C. So that you can compile the kernel, a copy of GCC is installed in /yolo/bin/gcc. Fil, you can compile the Linux kernel will clang+lld. `make LLVM=1` https://docs.kernel.org/kbuild/llvm.html https://docs.kernel.org/kbuild/llvm.html
- pizlonator 10mo agoGotcha. I am using gcc for building yolo-glibc, and the version I'm building (2.40) requires gcc. So if I used clang, then I'd have three compilers (yolo-clang, gcc, fil-clang) instead of two (gcc, fil-clang).
- ndesaulniers 10mo agoDoes fil-clang have `-fno-` flag to control disabling fil-c stuff? Does the fil-c runtime depend on specifics from glibc, or is it that LFS doesn't support building with musl? > We need to retain the Yolo GCC for compiling the Linux kernel. Probably can replace that with s/the Linux kernel/glibc/. glibc maintainers have started upstreaming patches for building glibc with clang, but not sure yet what's the latest on that (large) patch series.
- pizlonator 10mo ago>Does fil-clang have `-fno-` flag to control disabling fil-c stuff? No. I could add a flag like that, but that would make my patch to clang larger, which would make rebasing to new clang versions harder. So I'm choosing not to add such a flag. For now. > Do you depend on glibc, or is it that LFS doesn't support building with musl? I support both glibc and musl. LFS is glibc-based.
- ndesaulniers 10mo agoIf you do get around to adding the flag, consider a suggestion for the color of bikeshed: `-fyolo`. (Can't find my April Fool's clang patch for adding `-feverything`; hard to search the phab archive)
- pizlonator 10mo agoLove it!!
- 0brad0 10mo ago
- jabedude 10mo agoFilip, do you plan to support building the kernel with fil-c? What's the limiting factor right now on supporting that?
- pizlonator 10mo agoI think the way to do that is via something like l4linux, so that the ultra low level bits of the Fil-C runtime aren't relying - circularly - upon kernel functionality compiled with Fil-C that rely on that runtime.
- ndesaulniers 10mo agoOr perhaps a `--target` flag that says "I'm targeting the linux kernel, not userspace, libcall these symbols (existing kernel functionality) rather than those (glibc interfaces)."
- pizlonator 10mo agoThat won't solve it. Fil-C's memory safety relies on the Fil-C runtime
- ndesaulniers 10mo agoJust as the sanitizers have a runtime, the linux kernel has a re-implementation of those runtimes (the linux kernel does not link libgcc/compiler_rt) and IIRC the compiler will work differently (I forget which flags control that). Prior art here.
- pizlonator 10mo agoThe sanitizer runtime is not nearly as complex as the Fil-C runtime. Sanitizers don't have to deal with: - https://fil-c.org/fugc https://fil-c.org/fugc - https://fil-c.org/safepoints https://fil-c.org/safepoints Oh and it's not clear if the current revision of the capability model would work with memory mapped IO: https://fil-c.org/invisicaps https://fil-c.org/invisicaps
- CerryuDu 10mo agoI find the repeated "yolo" qualifications very tiresome, yawn-inducing. At least in this article: https://fil-c.org/runtime https://fil-c.org/runtime the term "classic C" is still used. I don't expect for a moment that Fil-C might supplant normal C under normal circumstances. Calling normal C "yolo-C" is dishearteningly pompous. Just because you've invented a C environment with a different tradeoff, people not interested in it are not automatically irresponsible (which is what you are suggesting with "yolo", of course).
- reactordev 10mo agoYolo - You only live once. Perfectly describes what happens when you have a segfault in C. It dies.
- wmf 10mo agoThe point of Fil-C is that it converts silent errors into crashes. Paradoxically, Fil-C increases crashes.
- pizlonator 10mo agoYes
- reactordev 10mo agoI’m here for it. Best of luck. This is the biggest issue we have with old C/C++ (besides the neckbeards not wanting change) is no one wants to go and update that old code so making it just work (with minimal intervention) is exactly what we need. Now, guarantees… I’d love to see Rust level intrinsics in gcc now that we have a rust gcc frontend. Improve upon the “RVALUE” crap and actually generate meaningful “oopsies” messages and errors with tips on how to fix. I’d even be ok with gcc + LLM to perform Rust level checking but I digress. Even just making sure footguns become errors is a start and making sure pointer trash is cleaned up is paramount. Even after 30 years I still sometimes forget to include a member variable in the move constructor…
- 10mo ago
- johnisgood 10mo agoIt is so confusing to me. Yolo-C, Yolo Land, Fil-C... For example > Fil-C supports both musl and glibc. Because of the coupling between the loader, libc, and runtime, Fil-C always uses the same libc in Yolo Land as in User Land. So, when running with musl, we use two versions of musl (one compiled with Yolo-C and another compiled with Fil-C). > And when running with glibc, we use two versions of glibc (one compiled with Yolo-C and another compiled with Fil-C). The rest of this page documents how the runtime looks with musl. If you build with glibc, you'll see minor differences. Why do you need a libc compiled with both Yolo-C and Fil-C, and what are the differences? What exactly is Yolo-C? This project says "The kernel is compiled with Yolo-C."... so is that a good thing? And why not Fil-C? I see Yolo being mentioned a lot everywhere. What exactly is that, how does it relate to Fil-C, and what are the differences? There is such a thing as Yolo toolchain (and Yolo Land (userland)), too!
- johnisgood 10mo agoNo need to downvote me, these are legitimate questions and I am sure I am not alone. It would be nice to have this cleared up somewhere (accessible). ... or maybe I should just ask an LLM at this point. --- So I did. If anyone is interested in the answer (provided by an LLM), then see: https://chatgpt.com/share/6943df8f-2cbc-8011-9e65-afbcaf19874a https://chatgpt.com/share/6943df8f-2cbc-8011-9e65-afbcaf1987...
- cryptonector 9mo agoI believe in u/pizlonator's parlance Yolo-C is any C compiler that isn't Fil-C. Some parts of Pizlix are built with Yolo-C, including the kernel. My guess is that Fil-C is not yet able to build a Linux kernel and have it run well, or maybe it's only a bootstrapping issue (as u/pizlonator notes in another sub-thread). Fil-C _itself_ needs two C libraries: one for Fil-C's run-time, and one for the program you've compiled with Fil-C. The C library for the program built with Fil-C has to be built with Fil-C, while the one for Fil-C's run-time can't itself be compiled with Fil-C and must be built with Yolo-C. Lastly, YOLO is an acronym meaning "you only live once". It's something one says right before doing something dangerous, such as bungee jumping. The joke here is that any C compiler that is not the Fil-C C compiler is dangerous, thus "YOLO!".