logoalt Hacker News

kccqzytoday at 4:21 PM0 repliesview on HN

No MTE and AddressSanitizer are implemented completely differently under the hood and catch different kinds of memory bugs.

MTE tracks provenance of pointers which means it catches bugs where a valid pointer derived from one allocation is used to access another allocation. Provenance is indicated by a fixed number of tags available. So there’s a 7% chance of not detecting an occurrence of a memory bug.

ASan is implemented differently: it adds red zones next to allocations. In theory it could have a false negative if a pointer jumps over the poisoned region. But it works well for stack memory in addition to heap memory. MTE doesn’t protect your stack allocated objects.