[php-src] Issue #11218: Implement CHERI framework
| From: | hexydec | Date: | Wed, 10 May 2023 10:45:36 +0000 |
| Subject: | [php-src] Issue #11218: Implement CHERI framework | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-244420@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/11218
Author: hexydec
### Description
Recently at the CYBERUK23 conference, I went to a session about secure computing. A very interesting
talk highlighting that 70% of all software vulnerabilities are rooted in buffer overflows.
Rust is a language that was developed with memory management built in to prevent this class of
vulnerabilities, but that does not address the huge corpus of C and C++ code out there. Most
solutions currently are a bit cumbersome, and either require big code changes or have a detrimental
effect on performance.
Over the last 10 years, the University of Cambridge with support from Arm, Microsoft, Google and
others have developed Capability Hardware Enhanced RISC Instructions (CHERI), a framework for
preventing buffer overflows on C and C++. It requires minimal code changes (In the talk they said
around 0.03%), and has a very small performance penalty, as the underlying code is implemented in
around 300 instructions all together.
Interestingly whilst there are around 40m+ lines of open source Rust code, there is actually now
around 100m+ lines of open source C and C++ code adapted to be compiled with CHERI.
Owing to the popularity of PHP, I thought this might be a useful tool to make it more secure. Read
more here:
[CHERI Frequently Asked
Questions](https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/cheri-faq.html)