[graalvm-users] Polyglot API memory allocation for malicious code

Sarah Brown sarah at transposit.com
Mon Nov 12 16:10:10 PST 2018


Hello all!

I see in the embed documentation for timeouts
<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.graalvm.org_docs_graalvm-2Das-2Da-2Dplatform_embed_-23reliable-2Dtimeouts-2Dfor-2Dmalicious-2Dcode&d=DwIBaQ&c=RoP1YumCXCgaWHvlZYR8PZh8Bv7qIrMUB65eapI_JnE&r=CUkXBxBNT_D5N6HMJ5T9Z6rmvNKYsqupcbk72K0lcoQ&m=Ztc2TjpZW8DEIgIQN7NGQSu1re-6s7Qn3Lhd9sdVmW8&s=Fgujfl8I8v6-dC5HaxmWpQ9l2nEPDc6JyW2WKqiKPJ4&e=>
:

"Note: A similar security feature for memory allocation is planned for a
future version of the Polyglot API."

Is this indeed on the roadmap? When could it be expected? Is there an
associated ticket for it?

This is a key feature in whether or not my team will be able to move to
graalvm. If the feature won't be implemented for a while, do folks have any
ideas on how to implement workarounds in java? Maybe using ThreadMXBean to
see how much memory the thread is consuming?

Thanks in advance,
Sarah
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://oss.oracle.com/pipermail/graalvm-users/attachments/20181112/a21b6014/attachment.html 


More information about the GraalVM-Users mailing list