←back to thread

132 points fractalbits | 3 comments | | HN request time: 0s | source
Show context
whinvik ◴[] No.46254931[source]
Interesting. Have you seen any benefits of using io-uring. It seems io-uring is constatly talked about but no one seems to be really using it in anger.
replies(1): >>46254993 #
1. 6r17 ◴[] No.46254993[source]
Io-uring has it's fair amount of CVEs ; I'm wondering if people are checking these out ; because the goal is not to just make something fast ; but fast & secure. It's a little bit of a grey area in my opinion for prod on public machines. Anyone has a counter view on this I'm genuinely curious maybe i'm over cautious ?

ps : there are actually other faster and more secure options than io-uring but I won't spoil ;)

replies(1): >>46255104 #
2. hansvm ◴[] No.46255104[source]
My understanding is that the iouring CVEs are about local privilege escalation, not being appropriately sandboxed, etc. If you're only running code you trust on machines with iouring enabled then you're fine (give or take "defense in depth").

Is that not accurate?

replies(1): >>46255965 #
3. 6r17 ◴[] No.46255965[source]
I really need to properly study the CVEs instead of making some surface judgement tbh - might have to take a look at it again