From 7b081f59be3b28dc95bd0eea594fcca7e960017b Mon Sep 17 00:00:00 2001 From: Joshua Bell Date: Thu, 11 Jul 2024 11:28:15 -0700 Subject: [PATCH 1/2] Add security consideration for computation control-flow attacks As noted in #443 if constants aren't actually constant then bad things can happen. Add a note to mention that implementations should mitigate this. Purely editorial change. Fixes #443 --- index.bs | 2 ++ 1 file changed, 2 insertions(+) diff --git a/index.bs b/index.bs index 74efe262..0ce49764 100644 --- a/index.bs +++ b/index.bs @@ -574,6 +574,8 @@ Once the graph is fully constructed and compiled, the input shapes into each of Issue: Document operations susceptible to out-of-bounds access as a guidance to implementers. +Implementations must defend against control-flow attacks based on changes to data considered to be constant. For example, optimizations in the underlying plaform may assume that a weight remains unchanged throughout a computation. If the API allowed the contents of buffers holding weights to change during a computation then those optimization assumptions would be invalidated, causing undefined behavior in the underlying platform. The API mitigates this category of attacks from script by always copying or transferring buffers, but implementations should consider additional defenses such as process isolation of data assumed to be constant. + As a future-proofing measure, the API design allows certain operations that can be generically emulated to be deprecated for security, performance, or other reasons without breaking compatibility. This is made possible by high-level functions that are defined in terms of smaller primitive operations defined in this specifications. This enables a native implementation of a high-level function to be replaced with a polyfill implementation. Issue: Investigate side channel attack feasibility considering the current state where CPU is shared between processes running renderers. From cb5b8de0d1b42fa82f61891de90984fefb944e0f Mon Sep 17 00:00:00 2001 From: Dwayne Robinson Date: Tue, 16 Jul 2024 23:53:07 -0700 Subject: [PATCH 2/2] typo platform --- index.bs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/index.bs b/index.bs index 0ce49764..7cddba5d 100644 --- a/index.bs +++ b/index.bs @@ -574,7 +574,7 @@ Once the graph is fully constructed and compiled, the input shapes into each of Issue: Document operations susceptible to out-of-bounds access as a guidance to implementers. -Implementations must defend against control-flow attacks based on changes to data considered to be constant. For example, optimizations in the underlying plaform may assume that a weight remains unchanged throughout a computation. If the API allowed the contents of buffers holding weights to change during a computation then those optimization assumptions would be invalidated, causing undefined behavior in the underlying platform. The API mitigates this category of attacks from script by always copying or transferring buffers, but implementations should consider additional defenses such as process isolation of data assumed to be constant. +Implementations must defend against control-flow attacks based on changes to data considered to be constant. For example, optimizations in the underlying platform may assume that a weight remains unchanged throughout a computation. If the API allowed the contents of buffers holding weights to change during a computation then those optimization assumptions would be invalidated, causing undefined behavior in the underlying platform. The API mitigates this category of attacks from script by always copying or transferring buffers, but implementations should consider additional defenses such as process isolation of data assumed to be constant. As a future-proofing measure, the API design allows certain operations that can be generically emulated to be deprecated for security, performance, or other reasons without breaking compatibility. This is made possible by high-level functions that are defined in terms of smaller primitive operations defined in this specifications. This enables a native implementation of a high-level function to be replaced with a polyfill implementation.