Concernant les buffer overflow ce papier de 2002 http://www.acsac.org/2002/papers/classic-multics.pdf indique
"However, when you look at the published history of Multics security problems
[20, 28-30], you find essentially no buffer overflows.
Multics generally did not suffer from buffer overflows, both because of the choice of implementation language and because of the use of several hardware features.
These hardware and software features did not make buffer overflows impossible, but they did make such errors much less likely."
et plus loin
"In the case of the x86 processors, although the necessary segmentation features are
present, they are almost never used, except for operating systems specifically designed for security, such as GEMSOS[32]."
Donc j'ai franchement tendance à penser que tout est là pour "faire de la sécurité" et qu'il faut réinventer la roue (donc multics -> unix -> linux -> ? pour remplacer ce ? je propose linics mais je ne suis pas sûr cela plairait à Linus ... ça sonne trop minix)
[^] # Re: SMEP et la segmentation
Posté par dominique dechamps . En réponse à la dépêche Le noyau Linux est disponible en version 3.0. Évalué à 1.
Il semble que les X86 aient une instruction into qui permet de lever des exceptions sur bit d'overflow (voir http://www.gamedev.net/topic/310538-integer-overflow-exception/)
Concernant les buffer overflow ce papier de 2002 http://www.acsac.org/2002/papers/classic-multics.pdf indique
"However, when you look at the published history of Multics security problems
[20, 28-30], you find essentially no buffer overflows.
Multics generally did not suffer from buffer overflows, both because of the choice of implementation language and because of the use of several hardware features.
These hardware and software features did not make buffer overflows impossible, but they did make such errors much less likely."
et plus loin
"In the case of the x86 processors, although the necessary segmentation features are
present, they are almost never used, except for operating systems specifically designed for security, such as GEMSOS[32]."
Donc j'ai franchement tendance à penser que tout est là pour "faire de la sécurité" et qu'il faut réinventer la roue (donc multics -> unix -> linux -> ? pour remplacer ce ? je propose linics mais je ne suis pas sûr cela plairait à Linus ... ça sonne trop minix)