Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chc4
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
chc4
2y ago
pahole gives you compilable C header files from ELF DWARF information. LLMs seems irrelevant here: either your header files have all the types exported from the executable correctly so they are usable with the original values, or they aren&
92.
▲
by
chc4
2y ago
This reminds me of one of the tweets that live inside my head and makes itself known every once in a while, about the Lion King movie: https://twitter.com/glowcoil/status/1204511618769588225 ("when the gc sou
93.
▲
by
chc4
2y ago
See also: the discussion on the LMAX disruptor github documentation https://news.ycombinator.com/item?id=38313457
94.
▲
by
chc4
2y ago
I have negative desire to get a phone billing itself around AI and LLM features. I turn off every AI assistant feature on my existing devices, I actively don't want a phone that ties Gemini and AI photoshop even tighter into it. If G
95.
▲
by
chc4
2y ago
"Is Parallel Programming Hard, And, If So, What Can You Do About It?" is one of the best books about atomics and concurrency, and my #2 recommendation. https://mirrors.edge.kernel.org/pub/linux/kernel
96.
▲
by
chc4
2y ago
Use ghost_cell/qcell, and put the QCellOwner in a mutex. Acquiring the cell owner grants the ability to access the data, but doesn't tie ownership.
97.
▲
by
chc4
2y ago
Chrome has the most vulnerabilities because it's the largest browser by market share by a mile, and so has the greatest number of eyes on it. You also can't extrapolate "it was never really secure" from that: practically
98.
▲
by
chc4
2y ago
> There's obviously no lock What? The threadpool has a shared mutex accessed by each worker thread, which is used for pushing work on heartbeat and for dequeuing work. https://github.com/judofyr/spice/blob&
99.
▲
by
chc4
2y ago
LMAO Ok that's fair. check_seccomp_filter actually has a more restrictive list than just "BPF with no backwards jumps", and in particular doesn't allow BPF_IND in the BPF_LDX, so you can't read out of bounds because
100.
▲
by
chc4
2y ago
Oh, TIL. I was under the impression they were both removed , and didn't know AMD had it either.
101.
▲
by
chc4
2y ago
The PoC uses eBPF maps as their out-of-bounds pointer, but it sounds like it would also be exploitable via non-extended BPF programs loadable via seccomp since it's just improper scalar value range tracking, which doesn't require
102.
▲
by
chc4
2y ago
Intel MPX had both hardware support for "bounds tables" and bounds checks[0], along with a "memory key" system[1] more similar to CHERI for memory tagging (only at page granularity, however). Both were massive failures a
103.
▲
by
chc4
2y ago
The Cornucopia Reloaded link in the OP is actually to the paper implementing this, I think, which I hadn't seen before.
104.
▲
by
chc4
2y ago
CHERI is a research project currently. It has a number of large outstanding issues - CHERI essentially needs to do a whole-system stop-the-world garbage collection phase for precise tag revocation in order to avoid non-stochiastic temporal
105.
▲
by
chc4
2y ago
Mark and sweep doesn't stop you from holding references across GC. If you write e.g. ``` let obj = some_object(); let len : &mut usize = &mut obj.len; // deref_mut trigger_gc(); use(*len); ``` then you held a referenc
106.
▲
by
chc4
2y ago
The other major issue with the Deref implementation is that `&mut` needs to be an exclusive reference, and if you're doing mark/sweep of GC objects via references you break that invariant if you hold any `&mut` across a GC
107.
▲
by
chc4
2y ago
What? There is no "the" instance of abstract interpretation, because different uses of it will have different abstract domains they are interpreting over and different transfer functions. There's no reason to choose types as
108.
▲
by
chc4
2y ago
Right, I'm not saying that learning software engineering wouldn't help. I'm specifically pushing back against "it's significantly harder without some engineering background", since a lot of good reverse enginee
109.
▲
by
chc4
2y ago
Most people used a cracked old version of IDA. I actually just used the freeware version, which was ancient and didn't come with any decompiler. Which was definitely difficult, and people having access to Ghidra for free these days is
110.
▲
by
chc4
2y ago
I don't think this is true, or at least I'm not convinced by a single anecdote. The majority of good reverse engineers I know picked up reverse engineering first and programming second (and a lot of them are still frankly not grea
111.
▲
by
chc4
2y ago
Same. I learned reverse engineering by staring at CE/IDA for entirely too many hours as a kid, which means whenever someone asks me for advice on how to learn reverse engineering I don't really have any good answers :) I think in
112.
▲
by
chc4
2y ago
This sparsemap uses essentially run-length encoding so it might still have slightly better performance. I think RoaringBitmap only uses the list of set bits below <1024 before it uses the compressed representation which you'd be ove
113.
▲
by
chc4
2y ago
LMDB uses https://git.burd.me/greg/sparsemap for storing compressed ranges of bitmaps for their page allocator, similar to RoaringBitmap or Linux's fdarray, which might be applicable here. With compressed bitmaps
114.
▲
by
chc4
2y ago
Windows doesn't use the Linux eBPF verifier, they have their own implementation named PREVAIL[0] that is based on an abstract interpretation model that has formal small step semantics. The actual implementation isn't formally prov
115.
▲
by
chc4
2y ago
Template JITs aren't new. Copy and patch is a specific scheme for automatically creating a template JIT by using relocations in order to generate templates from normal C++ code. That wikipedia page is just very bad.
116.
▲
by
chc4
2y ago
When I read https://marcan.st/2017/12/debugging-an-evil-go-runtime-bug/ and saw the hash bisection trick for the first time I was super impressed, it really does sound incredibly slick :) I imagine that'
117.
▲
by
chc4
2y ago
I got my first job through Who Wants To Be Hired in 2019. An engineer at the company reached out to refer me based on my resume. It was very good for allowing me to break into the industry, and it was a great place.
118.
▲
by
chc4
2y ago
Losing updates to the atomic counter is thread safe behavior, it's just a logic bug.
119.
▲
by
chc4
2y ago
Yup. I'm the one who did the Roblox bytecode exploit that lead to it being disabled: the specific attack there was that getmetatable internally leaves the metatable value on the Lua value stack even if it ends up returning the __metata
120.
▲
by
chc4
2y ago
You should never assume any method of executing any attacker controlled code is safe, unless something explicitly calls that out and also has put Google-level amounts of effort into supporting that.
More ›