Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Astra for Law(openai.com ↗)
    389comments
  2. Bonsai 2 27B: Near-Lossless Compression in a 9x Smaller Footprint(prismml.com ↗)
    84comments
  3. Bend – A language that blocks AI mistakes via proof, on CPU and GPU(bend-lang.com ↗)
    169comments
  4. Hister: A private search engine for the pages you visit and the files you keep(github.com/asciimoo ↗)
    139comments
  5. Wax motor(wikipedia.org ↗)
    54comments
  6. Alibaba releases Qwen 3.8 Omni Flash(qwen.ai ↗)
    11comments
  7. Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA(global.fujitsu ↗)
    201comments
  8. Flet 1.0 – Build cross-platform apps in Python(flet.dev ↗)
    36comments
  9. Telstra outage: The night a network decided the year was 2006(netnod.se ↗)
    4comments
  10. Better Icon and Label Alignment(ishadeed.com ↗)
    2comments
  11. I Put Nam A2-Lite Inside an iRig HD X(playtaurus.com ↗)
    2comments
  12. Diplodocus, Long Thought Exclusively American, Turns Up in Spain(sci.news ↗)
    26comments
  13. The most important product decision is what you don't build(liamnugent.me ↗)
    19comments
  14. CrowdSec Source Code Leak(crowdsec.net ↗)
    42comments
  15. How Uber Protects Against Retry Storms(uber.com ↗)
    25comments
  16. Why I didn’t sign the Fields medallists’ letter(gowers.wordpress.com ↗)
    317comments
  17. Infinite-Parameter LLMs: Generating and Adapting Weights from Live Data(arxiv.org ↗)
    35comments
  18. Rate limits on GitLab.com are changing(about.gitlab.com ↗)
    107comments
  19. How do we prevent mathemathics from devolving into the Medieval Era of secrecy?(mathoverflow.net ↗)
    61comments
  20. Goose:experimental lang 1.16x faster than C++ and 1.12x than safe Rust, mem safe(github.com/aardappel ↗)
    41comments
  21. CCC invites all model citizens to 40C3(ccc.de ↗)
    181comments
  22. More than 100k people in Japan are now aged 100 or older(bbc.com ↗)
    141comments
  23. The American Religion of Self-Storage Facilities(newyorker.com ↗)
    349comments
  24. Zettascale (YC S24) Is Hiring ASIC/FPGA Engineers to Build Chips for ASI(zscc.ai ↗)
    discuss
  25. TSMC revealing details about next gen A14 node(mapyourshow.com ↗)
    37comments
  26. Landing the Space Shuttle – A Flying Machine and the Thrill of a Lifetime(eaa.org ↗)
    6comments
  27. Ask A Monk – A digital wilderness for thoughts with no immediate answer(askamonk.online ↗)
    discuss
  28. Show HN: Snapdrop: Instantly share files between devices. No setup, no signup(snapdrop.me ↗)
    22comments
  29. Show HN: Share your AI Setup, Learn from others(mysetup.ai ↗)
    108comments
  30. Launch HN: Skillsync (YC W26) – AI chat sessions made portable across agents
    51comments

Memory Sealing "Mseal" System Call Merged for Linux 6.10

6 pointsby 2y agophoronix.com
3 comments
2y agoHN ↗

The mseal patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...

Userspace API > System Calls: https://www.kernel.org/doc/html/next/userspace-api/index.htm...

kernel.org/doc/html/next/userspace-api/mseal.html: https://www.kernel.org/doc/html/next/userspace-api/mseal.htm... :

Modern CPUs support memory permissions such as RW and NX bits. The memory permission feature improves security stance on memory corruption bugs, i.e. the attacker can’t just write to arbitrary memory and point the code to it, the memory has to be marked with X bit, or else an exception will happen.

Memory sealing additionally protects the mapping itself against modifications. This is useful to mitigate memory corruption issues where a corrupted pointer is passed to a memory management system. For example, such an attacker primitive can break control-flow integrity guarantees since read-only memory that is supposed to be trusted can become writable or .text pages can get remapped. Memory sealing can automatically be applied by the runtime loader to seal .text and .rodata pages and applications can additionally seal security critical data at runtime.

A similar feature already exists in the XNU kernel with the VM_FLAGS_PERMANENT flag [1] and on OpenBSD with the mimmutable syscall [2].

NX bit, Memory tagging, Modified Harvard architecture: https://news.ycombinator.com/item?id=36726077#36740262

TEE, SGX, .data, .code: https://news.ycombinator.com/item?id=33584502

2y agoHN ↗

Thanks! Another important bit:

sealing changes the lifetime of a mapping, i.e. the sealed mapping won’t be unmapped till the process terminates or the exec system call is invoked. Applications can apply sealing to any virtual memory region from userspace, but it is crucial to thoroughly analyze the mapping’s lifetime prior to apply the sealing.

2y agoHN ↗

Why is the sealed mapping unmapped on exec*()? What about spawn and fork?

Are there libraries for handling this yet?

IIRC, with CPython the NX bit doesn't work when any imported C extension has nested functions / trampolines

How should CPython support the mseal() syscall?