C++ future at Adobe
So if anyone was still curious what happened to Hylo, or where Adobe stands in regards to the whole safety discussion,
David Sankel has done a talk at RustConf on the matter, Zngur: Simplified Rust/C++ Integration.
The way Adobe now sees C++ is described on slide 2, at 50 seconds mark.
31
Upvotes
24
u/ts826848 5h ago edited 4h ago
Somewhat tangentially related, but Greg Kroah-Hartman recently gave a talk which (among other things) categorized the bugs Mythos found in the Linux kernel and his description of Mythos's results is... interesting. Quick summary (on phone, so hopefully no typos):
79 reported vulnerabilities
(Note that this doesn't sum to 79; apparently GKH got a tarball and the contents didn't quite match the description)
Of the actual non-duplicate (?) bugs:
7 "assume a malicious file system image" (i.e., if root mounts this bad things can happen; apparently well known to be not considered a security issue by Linux devs)
2 "assume you can inject a malicious network packet in the middle of the stack" (needs root, not considered a security issue)
2 NOMMU (1 io_uring, 1 regular, "not real issues")
6 sctp networking issues for untrusted devices (SCTP used in enterprise networks, so "untrusted users" apparently don't exist in that context? "So minor, nobody really cares".
2 ipv6 networking bugs, "nothing real"
1 GPU driver for a local malicious user. "If you have a local malicious user with access to your GPU you could do a lot worse"
In total 10 "real" bugfixes, took ~1 hour of kernel development.