A toy HTTP server in development Goals: secure, scalable (vertically and horizontally), not excessively slow, separation of privilege (and knowledge: HTTP code doesn't have to know TLS key) ...

Ariadne Devos a93c558d1c Generalise sHT_X_to_u32's overflow criterium to other bases 5 years ago
arch 68087dc6d0 Optimise sHT_index_nospec for ARM 5 years ago
buffer d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
doc 29e1e18973 Model speculation 5 years ago
fd d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
generic d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
http d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
lex a93c558d1c Generalise sHT_X_to_u32's overflow criterium to other bases 5 years ago
sHT a93c558d1c Generalise sHT_X_to_u32's overflow criterium to other bases 5 years ago
string be0ae9854a Specify sHT_merge16 in ACSL 5 years ago
stuff d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
task d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
tests ab644289c7 Add missing tests concering sHHT_failif 5 years ago
tools b7c181380a Remove non-functional helper script 5 years ago
worker d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
.gitignore d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
CFLAGS d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
COPYING 5248a3d7de Declare some functions and structures for workers 6 years ago
Makefile.am 3ae4c3f57f Run <tests/bitvec> 5 years ago
README d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
configure.ac d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
control.h d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
fd.h d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago
worker.h d5d303cc2c Allow only GPL-2 and GPL-3 5 years ago

README

.. SPDX-License-Identifier: GPL-2.0 or GPL-3.0
.. Copyright © 2018-2019 Ariadne Devos

# s^2 Web Stuff

s^2 is -- so far -- a personal project to write secure and sandboxed software
for doing things on the web. E.g. a web server and mail server and client.
In contrast to seemingly wide-held opinion, except perhaps by Intel,
it doesn't view speculative execution as an evil (*).

(*)
Except Meltdown and perhaps some others ... The model of Spectre I
address is: all branches may temporarily be ignored or falsily taken and all
indirect branch must be retpolined. Checking the page bits may be speculated.

s^2 should be safe against Speculative Store Bypass, Bounds Check Bypass,
Branch Target Injection. Foreshadow is not relevant. Lazy FP State Restore
is a bug of the kernel.

As an extension to what nginx supports, s^2 will allow migration to
different versions and machines. The source code is intended to be readable.

There is some architecture-specific code for Spectre mitigation.
Linux is supported, and the BSDs will be. W32 might be possible.

Do `autoreconf` && `./configure` && `make` to compile.
A CFLAGS argument of "$(sed '/^[*/#]/d' CFLAGS |tr '\n' ' ')"
is recommended, although compiler support may vary.

## Stuff

- [ ] apps/website.md: for static web sites, may be extended
- [ ] apps/torrent.md (TODO: bittorrent, webtorrent, Dat, IPFS, gnunet?)
- [ ] apps/mail.md: e-mail client and server, encrypted, signed, image support)
- [ ] apps/blog.md (TODO)
- [ ] apps/git.md (TODO)
- [ ] apps/ci.md (TODO)

## Some design details

OO is used, except that inheritance isn't really used. Nothing is overridden.
Generics may be used sparely. SMP may be used for efficiency (power-efficiency
according to Intel?), but is not mandatory. Tasks of the same type are batched
to reduce cache pressure and branch misprediction.

## Contact

Do NOT send a mail to Ariadne Devos , as I can't login anymore.
Instead, open a bug at . Patches, ideas and
general discussion are welcome.

## Licensing

The license is GPL-2.0 and GPL-3.0, see `doc/people/license-copyright.rst`
for details. The texts are respectively in `doc/people/gpl-2.rst` and
`doc/people/gpl-3.rst`.