@fd_ripateli
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Joined June 2024
- Tweets141
- Following92
- Followers330
- Likes31.2K
Linux 7.0 still does not support Intel CET indirect branch tracking (IBT) in usermode.
Intel CPUs supporting IBT first appeared in 2021.
Here's my patch series: lore.kernel.org/lkml/2026051…
IBT enforces that indirect calls and jumps can't land on any arbitrary instruction, but one of these:
[f3 0f 1e fa] endbr64
"jmp rax" to elsewhere causes a segfault SEGV_CPERR, defending against control flow hijacking (e.g. corrupt function pointer).
This came up while adding control flow integrity to Firedancer's sandbox.
One of the best Linux x86 jails out there, enforcing process isolation, namespaces, strict seccomp, landlock, MPK (user protection keys), CFI, and soon more.
github.com/firedancer-io/fir…
ripatel retweeted
Today we revived Richie's old blog, bpf.wtf. We'll be pushing a few PRs to add the new syscalls and keep it up to date. To this day, it's still one of the best resources for learning sBPF Assembly. No more Wayback Machine! Compiler disrespecters rejoice!
ripatel retweeted
In the last 24 hours @triton_one has served nearly 24 PETABYTES of Solana history via Old Faithful.