Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jagger11
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
31.
▲
by
jagger11
9y ago
I'm not sure how that'd be possible. It uses blocks (^) so it requires blocks with clang, no? I've changed my macro to yours, and compiled with clang (3.9) CC=clang-3.9 make clean indent depend all clang-3.9 -c -O3 -D_
32.
▲
by
jagger11
9y ago
Tho, in C++ I guess almost everybody would use a scoped variable with its desctructor using lambda.
33.
▲
by
jagger11
9y ago
The clang code requires -fblocks/-lBlocksRuntime too, and I was a bit quicker :) https://github.com/google/honggfuzz/commit/a9db9ddc2e24d157a...
34.
▲
Go-style defer() implementation for C
(github.com)
20 points
by
jagger11
9y ago
|
7 comments
35.
▲
by
jagger11
9y ago
Given that we're talking about telescopes under construction, the largest one will be EELT, no?
36.
▲
by
jagger11
9y ago
You can run it as root, and specifiy users/groups to switch to before executing an app. Though, CLONE_NEWUSER was meant for exactly that - using namespaced without euid==0. Some systems like Debian have a sysctl flag: kernel.unprivileg
37.
▲
by
jagger11
9y ago
I haven't been looking at systemd-nspawn for some time, but judging from its man page: - ability to use config files (in nsjail in protobuf format) - 3 operational modes: one of them allows to listen on a TCP port and run processes on-
38.
▲
by
jagger11
9y ago
Re kernel versions: Depending on when CLONE_NEWUSER and seccomp-bpf were added to the kernel for different CPU architectures. For x86-64 it was probably around 3.16, for some others it might be even 4.3 (e.g. ppc64). It might even work with
39.
▲
by
jagger11
9y ago
Yes, SECCOMP_RET_TRACE works, but nsjail doesn't have code to support that - it didn't seem that useful when mount namespaces can police access to files. Otherwise, it's possible to make it support that. Though, a word of cau
40.
▲
by
jagger11
9y ago
author here: Not exactly, you can technically overwrite a file with bind mounts, e.g. use nsjail --chroot / -R /dev/null:/etc/passwd -- /bin/sh -i This will make /etc/passwd empty, but nsjail doe
41.
▲
by
jagger11
9y ago
author here: Yup, nsjail doesn't have X hacks (I should work on that), though it offers some profiles for Apache-like type of applications: https://github.com/google/nsjail/tree/master/configs I bel
42.
▲
by
jagger11
9y ago
> I'm trying to get them to say "czypy" You can try to interest "Rada Języka Polskiego" (Polish Language Council) into this topic. Just because we all know, every Polish speaker will follow their advice diligentl
43.
▲
by
jagger11
9y ago
I'm not sure if it's required (to know the exit code). inputs, both valid and invalid, will activate various paths in djpeg/libjpeg, and that's the basic goal here. In case you'd like to test persistent fuzzing (sh
44.
▲
by
jagger11
9y ago
honggfuzz ( http://honggfuzz.com ) will run under cygwin - it uses similar algorithms (feedback driven by code coverage metrics), and last time I checked it under CygWin it worked with clang's -fsanitize-coverage=trace-pc mod
45.
▲
by
jagger11
9y ago
Here's your cool, lightweight and easily configurable sandbox - https://github.com/google/nsjail
46.
▲
by
jagger11
10y ago
> All are highly secure and Not really, those systems get much less attention from sec folk than the Linux kernel (apps aside). Finding a priv escalation in the Linux kernel takes time (most of low hanging fruits have been already found
47.
▲
by
jagger11
10y ago
Are you maybe thinking about adding more things on this one card? Ethernet, USB, memory (e.g. 1GB by default)... Maybe even emulation of a faster CPU in FPGA (a'la the Vampire for A600).. though, it'd probably use the CPU slot ins
48.
▲
by
jagger11
10y ago
security software doesn't mean secure software
49.
▲
by
jagger11
10y ago
With the use of defer http://pastebin.com/EXZuRAdT you could create it w/o the need to use array_free.
50.
▲
by
jagger11
10y ago
FYI - here's defer implementation for both gcc/clang - http://pastebin.com/EXZuRAdT
51.
▲
by
jagger11
10y ago
I wonder if this is in any way inspired by this - https://github.com/google/honggfuzz/blob/master/common.h ? I use there defer for both gcc/clang, countof(arr) -> ARRAYSIZE(array) In any case, ye
52.
▲
by
jagger11
11y ago
You can try https://github.com/google/honggfuzz - The basic idea is pretty much the same as with afl-fuzz - maximization of code coverage (more or less). Some old write-up on the technique can be found here: https:&#x