Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
comesee
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
31.
▲
by
comesee
8y ago
Theres nothing you can do. Just accept what management wants and do your job as best as you can
32.
▲
by
comesee
8y ago
Google is clearly evil now. Will anyone do anything about it?
33.
▲
by
comesee
8y ago
Your anecdote is valid but so is wil Wheaton's http://wilwheaton.net/2018/08/the-world-is-a-terrible-place-...
34.
▲
by
comesee
8y ago
This is super cool. For what are you using it?
35.
▲
by
comesee
8y ago
I've authentically made the front page 3 times in the past two weeks. No help from my friends.
36.
▲
by
comesee
8y ago
jcs is pretty good
37.
▲
by
comesee
8y ago
Fwiw Dbxfs seems to be a lot faster than rclone
38.
▲
by
comesee
8y ago
Good point on the MMU performance advantage and trade offs involved. When everyone's heads were on fire, made sense to indiscriminately mask off user controlled pointers. Now that the dust has settled a bit I imagine we'll see mor
39.
▲
by
comesee
8y ago
I'm still not sure how this is relevant to wasmjit? Your criticism is for another layer. If you don't like C, use Rust or Go. They also compile to wasm.
40.
▲
by
comesee
8y ago
I never argued that it shouldn't, just that the issues you're raising aren't relevant to the security of running wasm in kernel space.
41.
▲
by
comesee
8y ago
Again, not in any way that can cause instability to the kernel differently from running the same program in user space.
42.
▲
by
comesee
8y ago
You can do masking in the same way Linux does it. It prevents "branch code bypass" without using an explicit size: cmp %bound, %ptr jae bad_ptr sbb %mask, %mask and %mask, %ptr Just two extra instructions. No
43.
▲
by
comesee
8y ago
How is this relevant to wasmjit? User space programs written in C can already corrupt themselves. As far as I can tell there is no new inherent risk to kernel stability by running wasm code in kernel space as long as the wasm spec is follow
44.
▲
by
comesee
8y ago
Performing operations using the segmented registers is no faster than using the 32-bit analogues. Benchmark an add of eax,edx vs Al,dl in a loop.
45.
▲
by
comesee
8y ago
This is a moot point, the entire kernel is written in C. Since all code running on your computer involves kernel code running in ring 0, by your logic that would imply something is wrong, but it's not. System calls verify all input bef
46.
▲
by
comesee
8y ago
WebAssembly protects the host from memory corruption by the user module. To do this it does a bounds check before executing the load. It does not protect a user module from itself. It does not change the semantics of C. Relevant documentati
47.
▲
by
comesee
8y ago
Wasm has efficient 16/8 byte load/store instructions. 16/8 bit data types are irrelevant on x86 since it internally uses 32 bit registers anyway.
48.
▲
by
comesee
8y ago
The load8_s instruction will check that the computed offset into the memory of size 64KB (1 wasm page) does not index past the bounds of 64KB. If it does, the program will trap.
49.
▲
by
comesee
8y ago
It does
50.
▲
by
comesee
8y ago
I read through it and this is indeed how it works. Wasm as a language provides the restrictions that the MMU provides for machine code. You can't read from/write to arbitrary pointers in wasm.
51.
▲
by
comesee
8y ago
From looking at high_level.h it can instantiate any wasm file, but it seems to need the host code specially integrated. There is a function to instantiate the emscripten runtime, probably code can be added to instantiate the go or rust runt
52.
▲
by
comesee
8y ago
Emscripten seems like a good start, the tooling already exists.
53.
▲
by
comesee
8y ago
Aren't those side channels dependent on addressing kernel memory that you don't have permissions for? You can't address kernel memory in WebAssembly, therefore you can't provoke the speculator into caching those pages.
54.
▲
by
comesee
8y ago
How so? WebAssembly can't address memory outside of its sandbox
55.
▲
by
comesee
8y ago
Upon inspection of the code, it seems like this is something that could be used by browsers as well...
56.
▲
by
comesee
8y ago
Yeah the education category is alright https://www.fairtrending.com/?lang=en&fc=cat&cat=27&tag=&msc...
57.
▲
by
comesee
8y ago
I used the filter on the site and I watched a view of these videos https://www.fairtrending.com/?lang=en&fc=cat&cat=28&tag=&msc...
58.
▲
by
comesee
8y ago
The default feed is pretty clickbaity but I filtered to only show the technology category and it's not terrible https://www.fairtrending.com/?lang=en&fc=cat&cat=28&tag=&msc...
59.
▲
by
comesee
8y ago
Though it seems to be a different list of clickbaity garbage from https://m.youtube.com/feed/trending which is sort of interesting.
60.
▲
by
comesee
8y ago
I think the "preying on fish" part is key here not "scientifically observed." A captive mantis eating a fish placed in front of it is different from a wild mantis specifically hunting fish.
More ›