Skip to content

Archive

Memory Safety

2 articles
Cybersecurity 19 Sep 2026 6 min read

memfd Seals Turn Shared Memory into a Kernel-Enforced Immutable Payload

Shared memory is efficient partly because two processes can observe the same storage without copying it. That property becomes a security problem when one side validates bytes and later consumes them while another side still holds authority to mutate the same object. Linux memfd sealing can narrow that race by making selected mutations fail in the kernel before the file descriptor crosses a trust boundary. memfd_create() creates an anonymous file and returns an ordinary file descriptor. The object can be sized, written, mapped, and transferred over a UNIX domain socket. With MFD_ALLOW_SEALING, the inode starts with an empty seal set, allowing the producer to add irreversible restrictions after population.

Rust 03 Sep 2026 9 min read

Understand Pin and Unpin in Rust

Most Rust values can move freely. Assign a value to another variable, pass it by value, return it from a function, or replace it inside a container, and the value may end up at a different memory address. Usually that is exactly what you want. Rust’s ownership model tracks who owns a value, not where that value must remain in memory. A smaller class of types is different. Some values become address-sensitive: code relies on the value continuing to exist at the same memory location. Compiler-generated futures and carefully designed self-referential structures are common examples.