5 ms·
> It would be neat if there was a Go Playground running the latest beta/RC version of Go. (Or is there?) umm, no, not automagically. the playground is restrict
by f2f 10y ago
> It would be neat if there was a Go Playground running the latest beta/RC version of Go. (Or is there?)
umm, no, not automagically. the playground is restricted. it would require some work to be put in to make it work with the latest release. that work isn't available for free.
- maddyboo 10y agoThis is why I don't comment on HN. Maybe I'm stupid and just always make stupid comments, but I think the attitude you displayed with your "umm, no" is way too common around here. Is it too hard for you to not be condescending when making a counter argument? Edit: After re-reading both my comment and yours, I'm not sure if you were using the "umm, no" innocently in response to the `(Or is there?)` at the end of my sentence, or if you were trying to say it in a condescending way. I'll give you the benefit of the doubt and assume it was the former. I'm not trying to be one of those SJW people who gets offended at any little thing. Regarding the rest of your comment: > the playground is restricted What exactly do you mean by that? > automagically And that? I'm referring to large RCs like this. I think a lot of people want to test out new features/changes without pulling the latest version to their machine right away. That work is going to have to be done anyway before the final release, right? And I can't really imagine it would be a lot of work, I would think _maybe_ a few things would break, but otherwise it should work? And if you think I mean to have the normal `play.golang.org` start using the latest RC, that's not what I mean - I would imagine it would either be on a separate subdomain, like `play.beta.golang.org`. Or, have a dropdown on the main Playground, but that might be potentially confusing?
- jerf 10y ago"What exactly do you mean by [the playground is restricted]?" The Playground is a very special build of Go. I don't even think it's open sourced, often because while you can't depend on security-by-obscurity you still don't necessarily want to just hand people the source to attack on their own. It's written to prevent people from abusing the playground, so for instance, the os package can't read real files, the time package returns constants for "time.Now()" rather than using the clock, and an arbitrary number of other changes are made to prevent abuse. How many changes it is I don't know exactly, but there's certainly a number of them. But, more importantly, the QA work for such a thing is quite substantial. Many of the changes would also preclude using the playground to investigate the new features; for instance, you can't test HTTP2 support on there since you can't open sockets or servers. Presumably updating it would require significant effort, and at the very least, it can't be afforded to make that a blocker for a release.
- arjovr 10y agohttps://github.com/golang/playground https://github.com/golang/playground
- jerf 10y agoThank you, I stand corrected.
- maddyboo 10y agoOh interesting, I didn't realize it was a very special build of Go itself. I did know it was restricted, I guess I just underestimated how difficult that is to do. I didn't think the restrictions were actually implemented in the Go source, I thought it was more a locked down container plus a few restrictions implemented externally in the Playground's server code. It would be cool to know more about this, maybe I'll take a look at the source as @arjovr linked. Thanks!
- Merovius 10y ago> Oh interesting, I didn't realize it was a very special build of Go itself. It's not. It uses NaCl (native client), but that's just a special GOOS/GOARCH pair with a supporting runtime. NaCl is what the chrome sandbox is based upon, it's cool technology :) > It would be cool to know more about this, maybe I'll take a look at the source as @arjovr linked. You can also start here: https://blog.golang.org/playground https://blog.golang.org/playground
- Manishearth 10y agoInteresting. Rust has two playgrounds (official: https://play.rust-lang.org/ https://play.rust-lang.org/, unofficial: http://play.integer32.com/ http://play.integer32.com/), and each is a completely different bit of open-source software (https://github.com/rust-lang/rust-playpen https://github.com/rust-lang/rust-playpen , https://github.com/integer32llc/rust-playground https://github.com/integer32llc/rust-playground) They both use docker for isolation, with a bunch of things to make it work. IIRC we haven't had any issues with this. Furthermore, the official playground used to be a third completely different bit of software until it was rewritten in Rust. It also used to use https://github.com/thestinger/playpen https://github.com/thestinger/playpen. I'm skeptical that the problem will take that much effort since Rust has solved it (to some degree) twice. At the same time, it's likely that Go's playpen does a lot more mitigation, e.g. the time.Now() probably futzes timing attacks. Though in that case they would need to mess with mutexes or scheduling as well (since you can use shared memory to build a timer), which complicates things. (For timing attacks I still think the solution still lies in how you set up the container, specifically isolating its memory accesses -- instead of tweaking the compiler itself)
- oelmekki 10y agoWhile I'm also often annoyed by global negativity on HN (which, to be fair, has greatly improved lately, way to go guys!), I didn't read parent comment as aggressive, but like if "ummmm no" meant "wait, let me think about it for a sec... no, I don't think so", like you mention in your edit. But now, this user has been heavily downvoted, which is aggressive, without any doubt. I really wish downvote features were out of the web, this is just group bullying. Upvoting is plenty enough to make good contributions raise above the others.