logoalt Hacker News

The NX bit is not just about security

35 pointsby torutofulast Friday at 1:47 PM21 commentsview on HN

Comments

asveikautoday at 2:54 AM

On this theme of it not being just about security: if you have a bug like a use after free and it happens to cover a function pointer, the nx bit can ensure that when you follow that pointer through a call, you get a clean trap as close to the failure point as possible. If it blindly executed stale bytes as code, maybe the crash and stack trace doesn't look as nice.

But then, a lot of correctness bugs like that are also security problems.

achieriustoday at 3:49 AM

> while ARM does provide a reference implementation of the architecture, vendors are free to customize it at will, or even roll their own implementations

A nitpick, but this is only true for some vendors, depending on their license, and is very much company-by-company. Many vendors, even big names like Meta, don't have the ability to roll their own. And even for the ones who do, 'customize at will' is a bit strong, as ARM very much does want to maintain uniformity across userspace implementations. E.g. Nvidia shouldn't add new traps for architecturally-legal behavior, since then code compiled for Apple hardware wouldn't work on Grace. Or worse, not trap for architecturally-illegal behavior, since then code compiled for Grace might not work for anyone else at all!

show 1 reply
mubbiclestoday at 3:18 AM

I appreciated this article. I've asked our CSP guy the difference, but this helps me better understand device vs ns. I also appreciate that this doesn't appear AI written.

tripdouttoday at 2:43 AM

I really wish I understood this, it hits a bunch of topics that I've heard of and are/sound interesting, but I don't know enough to follow it. I don't get the link between the NX bit (which I get) and speculative access.

show 3 replies
dmitrygrtoday at 3:45 AM

This is doubly weird because actually purposefully executing from device memory is not allowed: “Trying to execute code from a region marked as Device is UNPREDICTABLE.” So: can’t reliably execute from there but can speculatively instruction fetch from there. Funsies!

https://support.arm.com/documentation/100941/0101/Memory-typ...

eqvinoxtoday at 3:29 AM

Honestly feels like a misdesign in ARM. Where does it ever make sense for Device memory to not be data prefetchable, but allow instruction prefetch? It should IMHO disable all prefetch…

show 1 reply
crazy1_today at 2:49 AM

this is so amazing

Nail2680today at 2:45 AM

Hot take: NX bit is shit W^X is shit. proper JIT is having objects written as needed, and cache line flushing is full bullshit, we need self modifying code as a first class citizen and with modern techiques we can have it work and not be crazy slow, it is currently cuz shits fucked, but we can do better.

show 3 replies