Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Would the core team really be interested in that? The bytecode interpreter relies on implicit invariants from the codegen, re-checking these invariants on the bytecode means slowing down the interpreter for very little value.


Nope they wouldn't, making the patch is just for completeness sake I guess. Also the afl tool to narrow down segfaults seems to always result in the same fault, so maybe if I patch it it will narrow down some more interesting ones.


That's interesting, because bytecode verification is extremely well-defined for the JVM: https://docs.oracle.com/javase/specs/jvms/se8/html/jvms-4.ht...


The JVM is explicitly designed to run untrusted bytecode.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: