Skip to content

Evaluate SES and frozen intrinsics against the worker threat model #3

Description

@mcollina

@naugtur suggested evaluating SES because intrinsics need repairs before freezing, and freezing could reduce the amount of defensive code. The follow-up discussion also clarified that freezing is not automatically required to isolate mutually distrustful components if the entire guest program belongs to a single threat actor.

Document whether the security model treats each guest program as one principal or also promises isolation between components within that program, and what capability granularity is intended. Compare the current captured-intrinsic approach with SES repair/lockdown in the worker realm, including compatibility with native module loading and explicitly granted host functions.

Measure startup and steady-state performance before deciding: the feedback raised possible V8 optimization costs from modifying/freezing prototypes, which should be validated rather than assumed. Record an adoption or non-adoption decision and the defensive responsibilities that remain either way.

Reference: SES intrinsic handling.

Based on review feedback from @naugtur, shared in a discussion with the maintainer.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions