TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

A Kernel Hacker Meets Fuchsia OS

349 pointsby chrisdinnalmost 3 years ago

14 comments

native_samplesalmost 3 years ago
I think the more interesting thing here is the fact that so much code in their repository appears to be bit-rotted or half baked, despite being documented. KASLR is mentioned all over the place but doesn&#x27;t work and the answer is &quot;we know, it&#x27;s there only to stop it bit-rotting&quot;. You need to patch the system to do kernel debugging because otherwise the toolchain hangs. Syscalls are documented as enforcing security rules yet the actual checks are &#x2F;&#x2F;TODO comments (and they are still willing to assign CVEs so apparently they just forgot?!). The syzcaller tool is advertised as working with Fuschia, yet despite trying multiple different versions he can&#x27;t even compile them due to API churn. Apparently downloading and executed a binary isn&#x27;t even an option, despite their vision being that Fuschia is a sea of components downloaded and run from the internet.<p>It&#x27;s hard not to feel like maybe Google has lost the ability to develop operating systems. Fuschia has been in development for years now, it has no users outside of Google yet if you flick through their docs you&#x27;ll notice a whole bunch of pages talking about deprecated components, migrations, etc. When I last looked at their docs, they read like it&#x27;s been around for 20 years and has millions of apps, even though that&#x27;s not true. Oh yeah and of course the giant BLM banners everywhere they have&#x2F;used to have. Just checked, now those banners are replaced with &quot;Honoring Asian Pacific American Heritage Month&quot;, lol. Apparently their vision of a futuristic OS is one in which every page in the docs has some random totally US centric bit of virtue signalling in it. No wonder they somehow can&#x27;t even finish a <i>microkernel</i>, a design that reduces performance in return for a much smaller syscall surface area.
评论 #31502822 未加载
评论 #31503818 未加载
评论 #31506351 未加载
评论 #31502950 未加载
nine_kalmost 3 years ago
My takeaway from the article is that Fuchsia exposes a capability-based interface externally, but uses the old kind of privilege-checking inside the kernel. Once a single sloppy check was found, the game was over: a privilege escalation and planting of arbitrary code into the kernel followed.<p>Did I miss anything?
评论 #31503751 未加载
评论 #31502879 未加载
jcranmeralmost 3 years ago
Something that I haven&#x27;t seen brought up yet is the &quot;weird C++ vtable layout.&quot; This is actually the &quot;relative vtable layout&quot; that&#x27;s first described here: <a href="https:&#x2F;&#x2F;bugs.llvm.org&#x2F;show_bug.cgi?id=26723" rel="nofollow">https:&#x2F;&#x2F;bugs.llvm.org&#x2F;show_bug.cgi?id=26723</a>, and is usable in clang via the -fexperimental-relative-c++-abi-vtables option.<p>The basic idea is that you don&#x27;t need to waste a whole 64 bits for vtable entry, especially since you can usually assume that code within the same DSO will be within 32 bits of each other. So, instead, you do a 32-bit offset from a known address (the vtable&#x27;s address) to get the function pointer, and in the rare case you need a cross-DSO entry, just emit a thunk for the symbol that&#x27;s in the same DSO to get an address within 32 bits.
评论 #31510704 未加载
vander_elstalmost 3 years ago
Disclaimer: I made some contributions to Fuchsia and I am clearly biased.<p>I am not sure why there&#x27;s so much negativity around Fuchsia. From a technical point of view it&#x27;s finally a serious attempt to do something new in the OS space. It might not be the right and perfect answer, but it might introduce new paradigms and maybe some fork of the project might be able to provide additional benefits for end users down the road. I know that there are lots of hobby&#x2F;research projects trying out new stuff, but i think Fuchsia stands out because it might be able to land the innovation and make it accessible for a larger user base.
评论 #31507936 未加载
评论 #31509578 未加载
评论 #31507939 未加载
评论 #31507902 未加载
评论 #31509890 未加载
评论 #31507709 未加载
评论 #31507980 未加载
azalemethalmost 3 years ago
Fuchsia still makes me deeply nervous inside. I get that linux has plenty of problems, but it really feels like Google have started to write an OS for the purposes of (a) having better remote control over the software that users run, and (b) being able to be free of the GPL. Security is the panacea that lets this happen, but I&#x27;m really not sure that it will inherently be better: iOS has effectively this model and it hasn&#x27;t stopped a large number of nation-state actors effectively abusing it for hiding rootkits on victim&#x27;s phones. The trade off for this is flexibility: the only reason I use an Android phone is because I can, with the right 3rd party OS, actually have a linux-based pocket computer that trusts <i>me</i> rather than its vendor.
评论 #31505361 未加载
评论 #31512262 未加载
评论 #31516693 未加载
评论 #31505327 未加载
dmitrygralmost 3 years ago
The people who work on fuchsia are very good engineers - I’ve worked with many of them in person. But the project itself has always been a staff retention project. It only existed to keep said engineers from going to a competitor. I don’t know how any understanding of fuchsia is possible without this crucial fact
评论 #31503394 未加载
评论 #31537069 未加载
评论 #31516274 未加载
评论 #31504973 未加载
评论 #31510518 未加载
评论 #31503406 未加载
评论 #31506846 未加载
评论 #31502763 未加载
binkHNalmost 3 years ago
Very nice right up on how unfinished and insecure Fuchsia is as a result of it being so unfinished.
评论 #31502269 未加载
评论 #31505723 未加载
评论 #31501375 未加载
评论 #31500240 未加载
评论 #31500160 未加载
评论 #31502797 未加载
评论 #31501029 未加载
评论 #31504084 未加载
maverick74almost 3 years ago
Would be nice to see something like this on seL4 (in some OS like Sculpt, for example)
评论 #31502666 未加载
ouidalmost 3 years ago
The objective of computer security seems to have shifted from preventing someone else from running unauthoirzed software on your computer to preventing you from running unauthorized software on your computer. I would not describe this as security.
评论 #31504498 未加载
评论 #31504562 未加载
评论 #31504642 未加载
评论 #31507069 未加载
评论 #31504380 未加载
评论 #31504792 未加载
评论 #31506405 未加载
评论 #31504468 未加载
评论 #31504989 未加载
评论 #31504574 未加载
Ruqalmost 3 years ago
It sounds like a <i>really</i> bad idea to have all software &quot;components&quot; be resolved, downloaded, and executed from over the internet. Seems like a supply chain&#x2F;waterhole attack just waiting to happen.<p>Not to mention it would seem to sign away the devices ability to act autonomously or offline. Of course, with my views of Google, it seems very like them to design everything to constantly rely on them to even function.<p>Correct me if I&#x27;m wrong on any of this.
评论 #31504771 未加载
评论 #31504813 未加载
评论 #31504763 未加载
评论 #31506624 未加载
评论 #31507929 未加载
bitwizealmost 3 years ago
The great thing about Fuchsia is it&#x27;s like a Google version of Plan 9.<p>The bad thing about Fuchsia is it&#x27;s like a <i>Google</i> version of Plan 9.
评论 #31506282 未加载
评论 #31507987 未加载
评论 #31502761 未加载
dangalmost 3 years ago
Url changed from <a href="https:&#x2F;&#x2F;swarm.ptsecurity.com&#x2F;a-kernel-hacker-meets-fuchsia-os&#x2F;" rel="nofollow">https:&#x2F;&#x2F;swarm.ptsecurity.com&#x2F;a-kernel-hacker-meets-fuchsia-o...</a>, which points to this.
dvhalmost 3 years ago
You see, this is how you do job interview, not waiting for some HR schmuck to ask you leetcode questions over the span of 6 months.
评论 #31504972 未加载
评论 #31504579 未加载
ncmncmalmost 3 years ago
Wow, it is surprising how awful every last bit of Zircon code reproduced here is. I have to guess the rest is about as bad.<p>This dreck would never pass code review at my shop.
评论 #31503949 未加载
评论 #31503552 未加载
评论 #31504209 未加载