Tag: Memory Safety
-
Formal Invariant Verification: Mathematical Proofs for Rust vs Modern C++ Memory Safety Bounds
Evaluating affine type systems against RAII smart pointers via mathematical state invariants, compiler proofs, and Hoare logic preconditions.
By Read Investigation → -
Memory Allocation Overhead: Quantitative Evaluation of jemalloc vs mimalloc Under Severe Cache Contention
Quantitative evaluation of jemalloc versus mimalloc under high-concurrency cache contention, analyzing fragmentation, RSS footprints, and CPU cycles.
By Read Investigation → -
The Naked Compiler — Experiment 5: Quantitative Measurement of Branch Mispredictions in Binary Analysis
Empirical evaluation of branch predictor saturation under path explosion during symbolic execution, measuring cycle latencies and state divergence across x86_64, AArch64, and RV64GC.
By Read Investigation → -
The Naked Compiler: Every C/C++ Safety Net You Trust Is Already Gone
A foundational quantitative investigation disassembling binaries compiled 28 different ways across Clang and GCC, demonstrating how optimizer passes silently strip assertions, sanitizers, and defensive boundaries in release builds.
By Read Investigation → -
The Naked Compiler — Experiment 4: 9,712 Stripped Safety Guards Across 3 Major Codebases
Cross-codebase automated binary audit quantifying 9,712 stripped safety guards across FRRouting, GCC 15.2, and the Linux kernel 6.8 with empirical reachability proofs.
By Read Investigation → -
The Naked Compiler — Experiment 3: Binary-Level Scanning on Enterprise Firmware
Firmware-level binary scanning across 27 enterprise firewall CVEs (Cisco, Palo Alto, Fortinet, Juniper), measuring measurable divergence between source security invariants and stripped production machine code.
By Read Investigation → -
The Naked Compiler — Experiment 2: FRRouting Case Study — Two ASAN-Confirmed PoCs
Vulnerability mapping and address sanitizer verification on FRRouting (1,359 files, ~100K lines of C), confirming two production heap-buffer-overflows resulting from stripped VTY parser assertions.
By Read Investigation → -
The Naked Compiler — Experiment 1: When `assert()` Lies to You
Empirical disassembly analysis compiling the same C benchmark under -O0 through -O3, proving that assert() diagnostics evaporate in optimized builds while explicit boundary checks survive.
By Read Investigation → -
Debt Collector Series: §9 Compilers and Interpreters: The Silent Amplifiers of Information Debt
Empirical binary analysis and systems evaluation: Debt Collector Series: §9 Compilers and Interpreters: The Silent Amplifiers of Information Debt. Analyzing compiler optimization artifacts, memory bounds, and software security…
By Read Investigation → -
GCC Strips assert() at -O2 — Even With NDEBUG=0
Empirical binary analysis and systems evaluation: GCC Strips assert() at -O2 — Even With NDEBUG=0. Analyzing compiler optimization artifacts, memory bounds, and software security invariants.
By Read Investigation →