4 ms·
You would have to go out of your way to do so and handing out buffers that allow reading them without initialization would be a huge warning sign IMO. If you w
by eddyb 12y ago
You would have to go out of your way to do so and handing out buffers that allow reading them without initialization would be a huge warning sign IMO.
If you want performance, you don't have to worry about zeroing anything, just call `.clear()` on a `Vec`.
Nobody is saying you can't reproduce Heartbleed's effect in Rust, you just have to actually design for it, be it maliciously or out of misunderstanding of the language or a library construct.
The real question is how much harder Rust makes that which is often frustratingly trivial to sneak into C code.
- mikeash 12y agoYou would have to go out of your way to write your own custom allocator instead of just calling malloc and free, but that's what the OpenSSL folks did.
- grey-area 12y agoYou would have to go out of your way to do so and handing out buffers that allow reading them without initialization would be a huge warning sign IMO. So was doing that in the original C code, but no-one noticed.
- eridius 12y agoIn C, it's impossible to hand out buffers that have to be initialized before they're read. You have to go out of your way to initialize them first. In Rust, it's the other way around. You cannot hand out arbitrarily-sized buffers that allow for reading uninitialized memory without going out of your way to do so. Both languages can allow for writing bad code, but in C it's trivially easy to get the bad code by accident, and in Rust, you pretty much have to do it by design.
- Sanddancer 12y agoThere are mallocs that indeed do initialize memory before they're read. jemalloc, used in FreeBSD doesn't do it by default, but it's easy to set an option in /etc/malloc.conf so it does so, and ottomalloc in OpenBSD zeroes malloced memory because it uses mmap much more heavily. So yes, it is more than possible to have pre-initialized buffers in C, it's just that certain OSes use terrible memory allocation algorithms, with no way of even tuning them to be safe by default.