Dan Zhou
767 posts


@MrZhouDan 昨天还有qemu虚拟机逃逸的漏洞, 那好像就不是 setuid 了:
触发前提:QEMUtiny 漏洞的触发条件是 QEMU 实例配置并启用了 CXL(Compute Express Link)设备的模拟。如果您的 QEMU 虚拟机在启动时没有挂载或使用任何 CXL 相关的设备参数,则天生免疫此漏洞。
中文
Dan Zhou retweetledi

Rust devs are gonna hate this but it's true....
Every memory safety bug you’ve ever seen in C use after-free, buffer overflow, whatever is a skill issue, not a language issue.
the computer does exactly what you told it to do, you just told it to do something stupid. malloc() gives you memory. free() gives it back. If you use it after free(), that's on you.
that's like blaming the knife when you cut yourself.
C assumes you're not an idiot. modern languages assume you are. that's the difference.
C built trillion-dollar infrastructure. your OS. your browser. your database. all of it. Linux has been running the internet for 30 years. It's fine.
If you can't handle managing your own memory, that's valid. Use Python. Use Rust. Use whatever. but don't pretend C is broken because you dereferenced a null pointer one time.
> The language isn't unsafe. You are.
English

中国人到现在还在享受朝鲜战争的和平红利
而世界从来都是黑暗森林,
一直没有改变,
伊朗的问题就是没有棋手的命却得了棋手的病,
在这个大争之世,伊朗还想首鼠两端是很难的
wsjack 🇭🇰 |𝟎𝐱𝐔@wsjack
太疯狂了,这个世界已经是到这种地步了 一个中等国家的领袖可以在一天之内被外国斩首,太冷酷无情了。真不敢相信我们这个世界已经黑暗森林到了这种地步。 说实话,这个时候能生活在中国、美国这样的世界大国,是最幸福的事。 未来 20 年绝对是人类史上的乱纪元,AI、地缘政治不稳定、反全球化、极端思潮盛行。这些都是可以预见的。我感觉塔勒布的《反脆弱》这本书价值还在提升,我们可能得习惯一个逐渐癫狂的世界。
中文

China is moving rapidly to a solar/electric future with very little need for oil or gas
World of Statistics@stats_feed
🇨🇳 Official data reports that 12% of China's vehicles are now EVs, with fuel sales plunging 5.7% in 2025
English




