proomt

Search

Search posts, papers, and topics

All posts

InfoQOlimpiu Pop3 min readadvanced

Google Rewrites Critical C Dependencies to Rust Using AI and Differential Fuzzing

Summary

Google successfully used Gemini AI and differential fuzzing to rewrite giflib, a critical C dependency, into memory-safe Rust. This process created an ABI-compatible drop-in replacement, preempted a zero-day vulnerability, and improved p99 tail latency by enabling the removal of process isolation sandboxes.

  • Gemini AI performed a single-shot C to Rust translation, retaining original symbols for ABI compatibility.
  • Rigorous validation included mass-scale regression decoding (30M GIFs) and 6 days of differential fuzzing (200M iterations).
  • The Rust rewrite preempted CVE-2026-26740 and allowed decommissioning OS sandboxes, improving p99 latency.
  • FFI wrappers required human expertise to manage raw pointer semantics, ownership, and lifetime invariants.

Engineers facing legacy C/C++ security vulnerabilities and performance bottlenecks should consider this AI-assisted, fuzzer-validated migration path to memory-safe languages like Rust.

7/10

Related reading

  1. AI-powered fuzzing with the GitHub Security Lab Taskflow Agent

    GitHub Security Lab developed the Fuzzing Taskflow, an autonomous LLM-driven pipeline for C/C++ projects that automates continuous fuzzing from identifying entrypoints and writing harnesses to triaging crashes and generating vulnerability reports. It aims to reduce the human effort traditionally required for effective fuzzing campaigns.

    GitHub Oldgithub.blog9 minHN2
  2. Optimizing Gemini 3.8 Flash for Autonomous Coding Agents: Thinking Levels and Tool Fallbacks

    The article shows how to cut latency and token waste in Gemini‑3.8‑Flash coding agents by routing each step to a suitable `thinkingLevel` (low/medium/high) based on a cheap complexity classifier, validating tool‑call payloads with Zod, and retrying failed calls with exponential back‑off. A full TypeScript harness is provided, including middleware, classifier, level mapping, and retry logic.

    SitePointsitepoint.com17 min
  3. Changing the game: How Google uses agentic AI to secure hundreds of millions of lines of code

    Google’s AI & Infrastructure team built an agentic pipeline (Mantis) that runs pre‑submit AI‑driven scans on every code check‑in, validates findings with a fast triage agent (AST + call‑graph analysis) achieving >92% precision in <1 min, then auto‑generates fixes via a bug‑fix agent. Localized threat models and a two‑step scan cut false‑positives to ~3% and prevent hundreds of vulnerabilities eac…

    Google Cloud Bloggoogle.com4 min
  4. Migrating the GitHub Copilot runtime to Rust, using Copilot

    The Copilot agent runtime was rewritten from a 130‑k‑line TypeScript/Node.js codebase into a native Rust library (~830 k lines of Rust) to reduce startup latency, memory use, and improve reliability. The migration was done incrementally (in‑place) across 128 PRs, with AI‑generated code handling most of the work. The new runtime exposes a C ABI for in‑process embedding by all six Copilot SDK langu…

    GitHub Oldgithub.blog65 minHN188
  5. Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses

    Google’s Threat Intelligence team outlines three AI‑driven shifts—software build changes, expanded attack surface, and enhanced threat capabilities—then describes their multi‑model, graph‑based defense stack (AI Threat Tracker, in‑editor “spellcheck”, Wiz Security Graph, Gemini‑powered AI Threat Defense) and concrete threat examples like supply‑chain poisoning, LLMJacking, and AI‑orchestrated cre…

    Google Cloud Bloggoogle.com11 min