David Weston, vice president of Microsoft responsible for the security of the Windows operating system, shared information about the development of Windows protection mechanisms in his report at the BlueHat IL 2023 conference. Among other things, he mentioned the progress in employing Rust language to enhance the security of the Windows kernel. Furthermore, it was stated that code written in Rust could be added to the Windows 11 kernel possibly within a few months or even weeks.
Among the main motivations for using Rust are the means for safe memory handling and efforts to reduce errors in the code. The initial goal is to replace some internal data types in C++ with equivalent types provided in Rust. Currently, around 36 thousand lines of Rust code are prepared for inclusion in the kernel. Testing the system with the new code showed no negative impact on performance in the PCMark 10 suite (office applications test), and in some micro-tests, the new code turned out to be even faster.

The first area of Rust implementation became the DWriteCore code, which provides font parsing. Two developers were involved in the project, spending six months on the overhaul. The rewritten Rust implementation improved glyph generation performance for text by 5-15%. The second area of Rust application became the implementation of the REGION data type in Win32k GDI (Graphics Driver Interface). Rewritten Rust components of the GDI interface have already successfully passed all tests in use on Windows, and soon the new code is planned to be included by default in the Windows 11 Insider test builds. Among other achievements related to Rust, the translation of individual Windows system calls to this language is noted.


Sursa: opennet.ro
