220 40264 <866660c0-4c90-4ce9-bd5c-16ff593d35d6@isocpp.org> article
Path: news.gmane.org!.POSTED!not-for-mail
From: florian.csdt@gmail.com
Newsgroups: gmane.comp.lang.c++.isocpp.proposals
Subject: Re: more security concerns
Date: Fri, 28 Sep 2018 15:33:55 -0700 (PDT)
Lines: 174
Approved: news@gmane.org
Message-ID: <866660c0-4c90-4ce9-bd5c-16ff593d35d6@isocpp.org>
References: <CAFdMc-0NqfbqeOhhH1YiVGxDRVPv7COKNqge3mLu8UE8SgcXNw@mail.gmail.com>
 <CAO8_tC4kNZ6s-xMXo69n1D3dbOMkqt0fjLU44Uq5TfABp17hQQ@mail.gmail.com>
 <CAFdMc-1DpAUkYDVyNmP5H49XyNVDq5_T6UkEVaQGMGA0YEhNGw@mail.gmail.com>
 <94d79dd7-ba3b-4bf8-91ed-e5dc02b33670@isocpp.org>
 <1442c15c-6a58-4f3e-83cf-9f5554fb9981@isocpp.org>
Reply-To: std-proposals@isocpp.org
NNTP-Posting-Host: blaine.gmane.org
Mime-Version: 1.0
Content-Type: multipart/mixed; 
	boundary="----=_Part_606_868251907.1538174035161"
X-Trace: blaine.gmane.org 1538173913 22563 195.159.176.226 (28 Sep 2018 22:31:53 GMT)
X-Complaints-To: usenet@blaine.gmane.org
NNTP-Posting-Date: Fri, 28 Sep 2018 22:31:53 +0000 (UTC)
To: ISO C++ Standard - Future Proposals <std-proposals@isocpp.org>
Original-X-From: std-proposals+bncBC26HM4V3MIRBVGYXLOQKGQEMEKUYMQ@isocpp.org Sat Sep 29 00:31:49 2018
Return-path: <std-proposals+bncBC26HM4V3MIRBVGYXLOQKGQEMEKUYMQ@isocpp.org>
Envelope-to: gclcip-std-proposals@m.gmane.org
Original-Received: from mail-yb1-f200.google.com ([209.85.219.200])
	by blaine.gmane.org with esmtp (Exim 4.84_2)
	(envelope-from <std-proposals+bncBC26HM4V3MIRBVGYXLOQKGQEMEKUYMQ@isocpp.org>)
	id 1g61IZ-0005jM-53
	for gclcip-std-proposals@m.gmane.org; Sat, 29 Sep 2018 00:31:47 +0200
Original-Received: by mail-yb1-f200.google.com with SMTP id y67-v6sf4191525ybe.21
        for <gclcip-std-proposals@m.gmane.org>; Fri, 28 Sep 2018 15:33:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=isocpp-org.20150623.gappssmtp.com; s=20150623;
        h=date:from:to:message-id:in-reply-to:references:subject:mime-version
         :x-original-sender:reply-to:precedence:mailing-list:list-id
         :list-post:list-help:list-archive:list-subscribe:list-unsubscribe;
        bh=Vp1hAdukhs8CXVadrRHg0z9GJb5U/hOl+xQ4BN0BdNE=;
        b=nxSmucl/j1IGKXQFSfqcBpIDUzRDsDG70Hzu6In8n9sa7DI3c7tyjDgKNQ2vILSjG8
         7Jam3imDoUcrrldkaPnaST9z9PV1+3N/LANXcoMHIo17QoMnrK6T9laBixKuKZ3iwrls
         TBJcptx+1IKmbK/+OPmoFbhSuWVeog/Cpq0tp/rW5HA+wBKU5Se1Su7CkhpWwZFlYfDu
         enP/sugfXp0UZZirvhJhc6hfkGaXH8cJs90PI6gpWzuiidEQLXrWDvI18kkYtZyXP3wv
         vv+qcqsnLPws2qy138nHVSo+vB+k52vDKJhRqEdPVk/q9+eyq90h/jUMTQ3eMnykmuOn
         0Arw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20161025;
        h=date:from:to:message-id:in-reply-to:references:subject:mime-version
         :x-original-sender:reply-to:precedence:mailing-list:list-id
         :list-post:list-help:list-archive:list-subscribe:list-unsubscribe;
        bh=Vp1hAdukhs8CXVadrRHg0z9GJb5U/hOl+xQ4BN0BdNE=;
        b=feWy/5NcYBEd320LADaBxlrkxEDQZSC8t/TCJkXIvAbZxstMWZ+j67C/TNnfccvErO
         ALVQf9OXf2aZ4abmohQFoybI3BkhqLvyq9liEZZfc5cNb2Hl++9cfSW56pt+IFxJFrt2
         4gDMHqgEYm8BhSAhTfOXPgN+aq9XowZuFtllKnbQNPbcbIdmOwgN6jG3s7mSbvdDzG+P
         e/YRY4cFTIqjYQFLWqkKkLaPS5ppV4+QfFCy3xhGsjJU2jf+XhZKx3hUa49NMXLkVhet
         QL5/6gjy5rCFc23CKRoIGKHkPdwWkFl4Igm9syvGPUqur7DCg83ibIfp6ckeVd7kQOw7
         Bn1A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20161025;
        h=x-gm-message-state:date:from:to:message-id:in-reply-to:references
         :subject:mime-version:x-original-sender:reply-to:precedence
         :mailing-list:list-id:x-spam-checked-in-group:list-post:list-help
         :list-archive:list-subscribe:list-unsubscribe;
        bh=Vp1hAdukhs8CXVadrRHg0z9GJb5U/hOl+xQ4BN0BdNE=;
        b=DjYUSjCKhZiIxFpFln0lkFRaakOm7HoY0cOB2ScoxAWt8t679Os6U8y2wl0AK4xXZp
         u74XzcdtIhofpWW2d/UnzR2SUnSAHNBnKR5kjvIB47S0PdCu9KYrfWH/Ey/OJB/muF7h
         MeM9dm5SPh1i44zDpStOmjs0aeDfjZsO7KJU/K02KoeOz6AAPkZQu737rUJUCThbSwgM
         d8TdEO0WOrSSHYhIXkwtUUuhJOZwZCAerc5LszcNyce3buSpPQD8sIxr4IZ+xuog++na
         r+eLirOS64YOrLaKssVGW8fmbmlVcM0AJu0SOBQA2Gyd8cszKOgijLPWfmenLULUbLMq
         Y1pA==
X-Gm-Message-State: ABuFfojko1NlzD3PIFKXze5Nv9Ko5ey3cy3hT1rWAyI5sdjmp5IaPLvE
	uEcBNML6LU6JL94HsNOZO8j8KQ==
X-Google-Smtp-Source: ACcGV60T1LSb60v/h+s30VB0JmBm5v+H6hpugnjydsKNTA8w542VZzTosjNwp2d2s6YviIpyzu7QKA==
X-Received: by 2002:a25:606:: with SMTP id 6-v6mr534187ybg.75.1538174037297;
        Fri, 28 Sep 2018 15:33:57 -0700 (PDT)
X-BeenThere: std-proposals@isocpp.org
Original-Received: by 2002:a81:38c6:: with SMTP id f189-v6ls2995536ywa.0.gmail; Fri, 28
 Sep 2018 15:33:55 -0700 (PDT)
X-Received: by 2002:a81:78c6:: with SMTP id t189-v6mr4786ywc.7.1538174035702;
        Fri, 28 Sep 2018 15:33:55 -0700 (PDT)
In-Reply-To: <1442c15c-6a58-4f3e-83cf-9f5554fb9981@isocpp.org>
X-Original-Sender: florian.csdt@gmail.com
Precedence: list
Mailing-list: list std-proposals@isocpp.org; contact std-proposals+owners@isocpp.org
List-ID: <std-proposals.isocpp.org>
X-Spam-Checked-In-Group: std-proposals@isocpp.org
X-Google-Group-Id: 399137483710
List-Post: <https://groups.google.com/a/isocpp.org/group/std-proposals/post>, <mailto:std-proposals@isocpp.org>
List-Help: <https://support.google.com/a/isocpp.org/bin/topic.py?topic=25838>, <mailto:std-proposals+help@isocpp.org>
List-Archive: <https://groups.google.com/a/isocpp.org/group/std-proposals/>
List-Subscribe: <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>,
 <mailto:std-proposals+subscribe@isocpp.org>
List-Unsubscribe: <mailto:googlegroups-manage+399137483710+unsubscribe@googlegroups.com>,
 <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>
Xref: news.gmane.org gmane.comp.lang.c++.isocpp.proposals:40264
Archived-At: <http://permalink.gmane.org/gmane.comp.lang.c++.isocpp.proposals/40264>

------=_Part_606_868251907.1538174035161
Content-Type: multipart/alternative; 
	boundary="----=_Part_607_936912246.1538174035161"

------=_Part_607_936912246.1538174035161
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable



Le samedi 29 septembre 2018 00:22:25 UTC+2, Arthur O'Dwyer a =C3=A9crit :
>
> On Friday, September 28, 2018 at 7:14:20 AM UTC-7, floria...@gmail.com=20
> wrote:
>>
>> I want to highlight that [[nodiscard]] on functions is not about forcing=
=20
>> the compiler to keep the value, but instead to emit a warning if the use=
r=20
>> doesn't use the value.
>> So meaning would be different.
>> In that respect, another attribute name might be better.
>>
>
> Right. The standard attribute [[nodiscard]] goes in a *library* and=20
> instructs the compiler to kick* the user* if the user has *forgotten to=
=20
> use* the result of some *library call*.
>
> Daniel, what you are asking for is an attribute that goes in *user code*=
=20
> and instructs the compiler to kick *itself?* if the user has *forgotten=
=20
> to use* the result of some *assignment expression*.
>
>
> Also, it is already possible (but cumbersome) to implement already withou=
t=20
>> volatile:
>> void f() {
>>   int secret_int;
>>   float secret_float;
>>   /* ... */
>>   secret_int =3D 0;
>>   secret_float =3D 0
>>   asm volatile ("" ::"irm"(secret_int), "xm"(secret_float));
>> }
>>
>
> This certainly seems to make sure that the write reaches L1 cache, but do=
=20
> you know whether the write is guaranteed to have reached and overwritten=
=20
> any copies of the data that might remain in L2 and main memory?
> What about the swap partition? Are you worried that a copy of the secret=
=20
> may have been swapped out to disk?  (Reductio ad absurdum: What if it was=
=20
> swapped out to removable media that has since been ejected?)
>
> Before you can start talking meaningfully about preventing the compiler=
=20
> from eliminating your dead "=3D0" statements, you need to have a mental m=
odel=20
> that explains what good those "=3D0" statements are supposed to do in the=
=20
> first place.
>

That's why I introduced the [[undead]] attribute: to let the compiler do=20
what is necessary to propagate the value where it is meaningful, and=20
flushing the according cacheline might be part of this process (I assume=20
user code can flush a specific cache line).
Because you don't care about the assignment per se, but you care about the=
=20
value that is visible afterwards.

--=20
You received this message because you are subscribed to the Google Groups "=
ISO C++ Standard - Future Proposals" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to std-proposals+unsubscribe@isocpp.org.
To post to this group, send email to std-proposals@isocpp.org.
To view this discussion on the web visit https://groups.google.com/a/isocpp=
..org/d/msgid/std-proposals/866660c0-4c90-4ce9-bd5c-16ff593d35d6%40isocpp.or=
g.

------=_Part_607_936912246.1538174035161
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><br>Le samedi 29 septembre 2018 00:22:25 UTC+2, Arthur=
 O&#39;Dwyer a =C3=A9crit=C2=A0:<blockquote class=3D"gmail_quote" style=3D"=
margin: 0;margin-left: 0.8ex;border-left: 1px #ccc solid;padding-left: 1ex;=
"><div dir=3D"ltr">On Friday, September 28, 2018 at 7:14:20 AM UTC-7, <a>fl=
oria...@gmail.com</a> wrote:<blockquote class=3D"gmail_quote" style=3D"marg=
in:0;margin-left:0.8ex;border-left:1px #ccc solid;padding-left:1ex"><div di=
r=3D"ltr">I want to highlight that [[nodiscard]] on functions is not about =
forcing the compiler to keep the value, but instead to emit a warning if th=
e user doesn&#39;t use the value.<br>So meaning would be different.<br>In t=
hat respect, another attribute name might be better.<br></div></blockquote>=
<div><br></div><div>Right. The standard attribute [[nodiscard]] goes in a <=
i>library</i> and instructs the compiler to kick<i>=C2=A0the user</i> if th=
e user has=C2=A0<i>forgotten to use</i>=C2=A0the result of some <i>library =
call</i>.</div><div><br></div><div>Daniel, what you are asking for is an at=
tribute that goes in <i>user code</i> and instructs the compiler to kick <i=
>itself?</i>=C2=A0if the user has <i>forgotten to use</i>=C2=A0the result o=
f some <i>assignment expression</i>.</div><div><br></div><div><br></div><bl=
ockquote class=3D"gmail_quote" style=3D"margin:0;margin-left:0.8ex;border-l=
eft:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Also, it is already p=
ossible (but cumbersome) to implement already without volatile:<br><div sty=
le=3D"background-color:rgb(250,250,250);border-color:rgb(187,187,187);borde=
r-style:solid;border-width:1px"><code><div><span style=3D"color:#008">void<=
/span><span style=3D"color:#000"> </span><span style=3D"color:#000">f</span=
><span style=3D"color:#660">()</span><span style=3D"color:#000"> </span><sp=
an style=3D"color:#660">{</span><span style=3D"color:#000"><br>=C2=A0 </spa=
n><span style=3D"color:#008">int</span><span style=3D"color:#000"> secret_i=
nt</span><span style=3D"color:#660">;</span><span style=3D"color:#000"><br>=
=C2=A0 </span><span style=3D"color:#008">float</span><span style=3D"color:#=
000"> secret_float</span><span style=3D"color:#660">;</span><span style=3D"=
color:#000"><br>=C2=A0 </span><span style=3D"color:#800">/* ... */</span><s=
pan style=3D"color:#000"><br>=C2=A0 secret_int </span><span style=3D"color:=
#660">=3D</span><span style=3D"color:#000"> </span><span style=3D"color:#06=
6">0</span><span style=3D"color:#660">;</span><span style=3D"color:#000"><b=
r>=C2=A0 secret_float </span><span style=3D"color:#660">=3D</span><span sty=
le=3D"color:#000"> </span><span style=3D"color:#066">0</span><span style=3D=
"color:#000"><br>=C2=A0 </span><span style=3D"color:#008">asm</span><span s=
tyle=3D"color:#000"> </span><span style=3D"color:#008">volatile</span><span=
 style=3D"color:#000"> </span><span style=3D"color:#660">(</span><span styl=
e=3D"color:#080">&quot;&quot;</span><span style=3D"color:#000"> </span><spa=
n style=3D"color:#660">::</span><span style=3D"color:#080">&quot;irm&quot;<=
/span><span style=3D"color:#660">(</span><span style=3D"color:#000">secret_=
int</span><span style=3D"color:#660">),</span><span style=3D"color:#000"> <=
/span><span style=3D"color:#080">&quot;xm&quot;</span><span style=3D"color:=
#660">(</span><span style=3D"color:#000">secret_float</span><span style=3D"=
color:#660">));</span><span style=3D"color:#000"><br></span><span style=3D"=
color:#660">}</span></div></code></div></div></blockquote><div><br></div><d=
iv>This certainly seems to make sure that the write reaches L1 cache, but d=
o you know whether the write is guaranteed to have reached and overwritten =
any copies of the data that might remain in L2 and main memory?</div><div>W=
hat about the swap partition? Are you worried that a copy of the secret may=
 have been swapped out to disk? =C2=A0(Reductio ad absurdum: What if it was=
 swapped out to removable media that has since been ejected?)</div><div><br=
></div><div>Before you can start talking meaningfully about preventing the =
compiler from eliminating your dead &quot;=3D0&quot; statements, you need t=
o have a mental model that explains what good those &quot;=3D0&quot; statem=
ents are supposed to do in the first place.</div></div></blockquote><div><b=
r></div><div>That&#39;s why I introduced the [[undead]] attribute: to let t=
he compiler do what is necessary to propagate the value where it is meaning=
ful, and flushing the according cacheline might be part of this process (I =
assume user code can flush a specific cache line).</div><div>Because you do=
n&#39;t care about the assignment per se, but you care about the value that=
 is visible afterwards.<br></div></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;ISO C++ Standard - Future Proposals&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:std-proposals+unsubscribe@isocpp.org">std-proposa=
ls+unsubscribe@isocpp.org</a>.<br />
To post to this group, send email to <a href=3D"mailto:std-proposals@isocpp=
..org">std-proposals@isocpp.org</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/isocpp.org/d/msgid/std-proposals/866660c0-4c90-4ce9-bd5c-16ff593d35d6%=
40isocpp.org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.=
com/a/isocpp.org/d/msgid/std-proposals/866660c0-4c90-4ce9-bd5c-16ff593d35d6=
%40isocpp.org</a>.<br />

------=_Part_607_936912246.1538174035161--

------=_Part_606_868251907.1538174035161--

.
