Chat Logs

  1. pr3d4t0r:: yawn ::
  2. pr3d4t0rGood morning.
  3. pr3d4t0rdreamreal!! Come to #cime or the other channel when you have a moment?
  4. dreamrealaaaaand nevet should be back. Still finding transaction leaks. :/
  5. dreamrealstill muted HERE, though. :D
  6. dreamrealhttps://bytecode.news/posts/2026/04/boilerplate-three-ways
  7. javabotdreamreal's title: "Boilerplate Three Ways | bytecode.news"
  8. mawkhi
  9. mawkis this calling 'new' under the hood? byte[] a = {1, 2, 3};
  10. mawki.e. is this equivalent to byte[] a = new byte[3]; a[0] = 1; a[1] = 2; a[2] = 3;
  11. DoofusCanadensisdoubt it
  12. DoofusCanadensisbyte != Byte
  13. mawkI'm writing JavaCard and need to avoid 'new' as much as possible
  14. jbosmansif implementation details like that matter a lot i'd suggest investigating how to validate answers to such questions, i'm thinking it'll lead to reading bytecode (aka jvm assembly)
  15. jbosmanswhich i never do because i don't work at that level of detail
  16. Chronosmawk: Yes, as far as I know, it's identical to: byte[] a = new byte[]{1, 2, 3};
  17. ChronosSo I believe it does indeed call "new".
  18. Chronos(Corrections welcome.)
  19. ernimrilChronos, compile it and then check with javap
  20. ChronosIn Java, every array is a full-fledged object.
  21. mawkhmmm
  22. jbosmanswhat ernimril said
  23. mawkthanks
  24. sonOfRamawk: byte[] a = {1, 2, 3};
  25. sonOfRaoops
  26. sonOfRamawk: https://javap.yawk.at/#lnBjVV
  27. nevetjavap pastebin
  28. jbosmansalso, https://godbolt.org ftw
  29. nevetCompiler Explorer
  30. sonOfRatrue, but javap.yawk.at is made by (former) channel regular yawkat!
  31. jbosmanskudos for that ^
  32. mawkah yes indeed sonOfRa , thanks!
  33. jbosmansas far as i can see creating a new array doesn't create a new object
  34. jbosmansstatic int[] square() { return new int[]{9999}; }
  35. ernimriljbosmans, what about the newarray ?
  36. jbosmans 0: iconst_1
  37. jbosmans 1: newarray int
  38. jbosmans 3: dup
  39. jbosmans 4: iconst_0
  40. jbosmans 5: sipush 9999
  41. mawkwell it calls "newarray byte" so it must be allocating it on the heap
  42. mawkso I should do that only in the constructor of my applet so it's only called once
  43. mawkI can technically trigger the garbage collector but it has to be done manually and it's not portable, not every card has it
  44. jbosmansthanks for unbanning :)
  45. jbosmansmawk, there's the epsilon gc which doesn't do anything iirc, might be useful for measuring/.. to accomplish your goals
  46. mawkah yeah, I can run this on a simulator on a pc
  47. jbosmansshould you want to invest in that approach
  48. mawkthanks
  49. jbosmansmawk, assuming sarcasm, understand what you mean (i think). You could make it runnable on a pc if you can separate the dependencies from the code that's actually doing the work (or the work you care about)
  50. jbosmansoverlapping msgs:)
  51. jreichermawk: are you really assigning the byte array something known at compile time? Or is that just how you wrote the example?
  52. mawkyes it's known at compile time
  53. mawkmaybe if I set it as "final" it won't make an allocation
  54. jbosmansafaik object instantiations are extremely cheap on jvm
  55. ernimrilit is on all modern jvms, yes, has been so for a long time. Also constants are quite often inlined by the compiler
  56. jbosmans~jep 519
  57. javabot'JEP 519: Compact Object Headers' can be found at http://openjdk.java.net/jeps/519
  58. nevetJEP 519: Compact Object Headers
  59. jbosmansalso, it was pretty cheap before, too
  60. jbosmans(before java 25)
  61. jbosmansalso, up to recently, i compiled some tools using docker to an ubuntu 18/debian 10 compatible binary
  62. jbosmanswhich really made a difference for cmdline tools
  63. jbosmansfwiw it was compatible by compiling in dedicated docker containers, i just upgraded the container OS versions
  64. jbosmansiirc i got java+spring+jdbc+postgres+code down to ~60mb, which was nice
  65. jreichermawk: if it's known at compile time then declare it static and don't worry about the new. At worst it will only be done once, but perhaps not at all.
  66. jbosmansUPX compression could drive that down substantially, but that would take longer to execute (because of decompression)
  67. jreicherA good rule of thumb IMO is to always tell the compiler everything you know.
  68. mawkjbosmans: this is running on a smartcard, it's a a very small and slow microcontroller
  69. mawkwith just a couple hundred bytes of RAM to spare, maybe a thousand
  70. jbosmansmawk, great to be working on that :-)
  71. jbosmansi actually recognized JavaCard
  72. jreicherIs it possible Java is not the best language for that kind of target? (Honest question; I have no experience in this area)
  73. mawkwell there's no choice, java is all they run; in your credit card, your epassport, your SIM card
  74. mawkyou can sometimes run C but you need to sell your soul for a NDA
  75. jbosmansmawk, which context? eid or alike?
  76. mawkI'm working on a PKI smartcard
  77. jbosmanssweet, iirc our eid runs JavaCard too
  78. mawkjava is actually a sane choice for the application, the JVM is fully controlled by the OS and can apply all the static checks and security mitigations they want
  79. jbosmanscrazy stuff
  80. mawkthey can do stuff like rolling back transactions in case of tearing, skewing the clock inbetween instructions or running instructions several times to throw off side channel attacks; and also exceptions are an integral part of how the card communicates with the reader, that's how you set the APDU status codes
  81. jbosmansmawk, what jdk version are you working in?
  82. mawkit's javacard 3.0.5
  83. mawkcompiling with jdk 17
  84. jbosmansthat's not too bad for such a restricted context
  85. jbosmansiirc records are already supported
  86. jbosmansbest use those wherever they make sense
  87. jbosmansbecause both the compiler and jvm will know they're mean to be (shallowly) immutable
  88. jbosmansalas way post midnight, sweet dreams
  89. dreamrealfor javacard, eh
  90. dreamrealThat's a little surprising
  91. mawkwhy?
  92. dreamrealjavacard's not very common in the wild. What are you deploying it to?
  93. mawkI'm currently trying to add remote management capabilities with public key crypto
  94. mawklike SIM cards have
  95. mawkthen you can open a secure channel with the card even through an untrusted network
  96. mawkthen the card will serve as a secure element to hold keys for mTLS or other things, in an embedded product, in SIM format
  97. mawkand it's running on a JCOP 4 smartcard from NXP
  98. dreamreal*nod* nice!
  99. mawkI have half of the secure channel thing working, I can request AES session keys from the card and then continue with AES and CMAC
  100. mawkbut now I need to wrap the AES keys with a public key instead of transmitting them in cleartext
  101. dreamrealso I have VERY VERY VERY little experience with that profile, but in general you avoid allocations like the plague: new is fine *but* you reuse *everything* you can, so if you allocate an array, you reuse that array for the lifetime of the application
  102. mawkyeah indeed
  103. dreamrealIt's like you're writing in MUMPS except with java syntax, wooo
  104. mawkI can request transient arrays which get cleared either on deselect or on reset (like if the application is selected several times on different logical channels or different interfaces like contact vs contactless)
  105. mawkbut then it's not with new
  106. dreamrealI don't know if there's a GC on that profile at all: you'd want to allocate and preserve
  107. dreamrealunless things have changed! Like I said, I've got VERY little experience here, like "ooo I tried it once"
  108. mawkyeah some cards do have a GC but not all of them
  109. mawksome cards even have ints and not just bytes and shorts
  110. mawkluxurious
  111. mawkand you need to invoke the GC manually, and it will maybe run next time a command is received
  112. dreamrealI think I last did javacard on a lark for javaone 2007? maybe 2008?
  113. mawkah yeah the standards were quite different then
  114. mawkI think the standard was still to use the VISA platform manager instead of being the globalplatform thing of now
  115. dreamrealGosh, I don't remember that at all - we had this physical connection to the board, I don't even remember what it was called to install the application
  116. dreamrealI remember having a GPS available, which I thought was going to be great for basically building the apple tags using java
  117. dreamreallike how train car locators work: when connected to an open network, send an identifier ("package XYZ is at X:Y at 23:01")