10 ms·
A Secure Runtime for JavaScript and TypeScript Built with V8, Rust, and Tokio
- tfolbrecht 7y agoFor the inevitably "what differentiates this from node?" Single executable Allows imports from url File system & network Sandboxing is controlled with flags Dies on uncaught errors https://deno.land/manual.html#introduction https://deno.land/manual.html#introduction
- carlmr 7y ago>Dies on uncaught errors how can JS programmers deal with this?
- PudgePacket 7y ago... catch the errors?
- carlmr 7y agoIt was rhetorical and meant to be facetious.
- hombre_fatal 7y agoOn HN it's better to just share your point rather than obfuscate it with sarcasm and rhetoric.
- novaleaf 7y agoon node, this can actually be very difficult or even impossible if using 3rd party libraries. For example, some node internals like networking require the invoker to attach to some obscure .on("error") event to avoid uncaught errors. and a lot of the time these 3rd parties are not aware of it. I'm all for deno being built from the ground up to properly crash on uncaught errors. Silent ignoring is a really stupid decision.
- spion 7y agoI never understood why this is necessary. Using promises means you get to use try-with-resources style construct for handling non-memory resources safely. As such you no longer need to crash on uncaught errors, except errors pertaining to resource disposal.
- novaleaf 7y agoi think the reason is that, in my example of networking, the network i/o is an "interupt" kind of event, that is triggered outside of normal execution. like if there's a socket timeout. probably didn't have to be designed this way, but it was designed pre-promises and I guess they are lothe to change it.
- carlmr 7y agoYeah, I'm a huge fan of erroring out properly. It makes it much easier to find problems before they cost money. I think the erlang/elixir model of fail fast and try to restart is the best for availability.
- mattlondon 7y agoI would imagine you have a watchdog of some sort (perhaps a special URL) and have something probe that every 15-60 seconds etc to see if it is up, if it does not respond then spin up a new instance and kill the failed instance. Cattle not pets!
- xtreak29 7y agoRyan Dahl, creator of node.js started this project and is also a lead contributor.
- anaphor 7y agoWhat makes this different from something like https://github.com/Agoric/SES https://github.com/Agoric/SES ?
- qaq 7y agoIt is being actively developed. Has a large pool of active contributors.
- inglor 7y agoSES builds on capability theory to let you run "adversarial" code together with your trusted code safely. Deno is a runtime that aims to isolate the code from the system amongst other issues. SES uses a proof over the JS grammar with induction, Deno does isolation by not giving any OS level access to your code. Neither are particularly complete and are mostly orthogonal. Both are looking for people to help with them :]
- anaphor 7y agoThanks, that's a great summary!
- xvilka 7y agoWould be nice also to have the V8 implementation in Rust as well.
- wereHamster 7y agoYou mean JavaScript implementation in Rust. V8 is one of the many implementations that is written in C++.
- spraak 7y agoI think the parent means they wish V8 were in Rust instead of C++
- kbumsik 7y agoYou can post your opinion here: https://github.com/ansuz/RIIR/issues/ https://github.com/ansuz/RIIR/issues/
- johnhenry 7y agohttps://www.youtube.com/watch?v=_uD2pijcSi4 https://www.youtube.com/watch?v=_uD2pijcSi4
- austincheney 7y agoInstead I would rather a SpiderMonkey written in Rust.
- dlbucci 7y agoIs this a new site, or did the project recently reach a milestone, or is this just resurfacing? I'm really excited about this project, especially the first-class TypeScript. Could easily see it replacing node for me!
- lajawfe 7y agoWatch 10 things I regret about node. js - https://youtu.be/M3BM9TB-8yA https://youtu.be/M3BM9TB-8yA from the creator of both node and deno to undersatnd his motivations behind the deno project. A very intriguing talk.
- 29athrowaway 7y ago> Access between V8 (unprivileged) and Rust (privileged) is only done via serialized messages defined in this flatbuffer. Expect to see this in "n things I regret about deno"
- spraak 7y agoCan you explain why?
- 29athrowaway 7y agoEvery deno API function call goes through flatbuffer serialization + deserialization + more steps. Sounds like a lot of overhead.
- kevinkassimo 7y agoReplying to Flatbuffers concerns: You are right, we will try to get rid of it for some faster serialization mechanisms (after some huge internal refactor lands). See the talk I posted, Ryan mentioned about it near the end.
- pvg 7y agoIt is very interesting although I didn't really understand the 'security' part. The motivation seems to be twofold - some bad things have happened because of compromised npm packages and v8 happens to have a robust sandbox. This sounds like a solution looking for a vaguely defined problem. The illustrative example he gives is 'malicious linter'. Is malicious linter that important a threat?
- ricardobeat 7y ago
- kevinkassimo 7y agoAs a contributor to Deno, I am actually quite surprised that this got resurfaced on Hacker news after the hype June last year. That being said, I suggest checking out this video (recorded this April) for updated information about Deno, since things have changed quite a bit since the initial announcement: https://youtu.be/z6JRlx5NC9E https://youtu.be/z6JRlx5NC9E (Edit: fixed link, posted the wrong one. Why would YouTube think I want to share ads...)
- kreetx 7y agoCurious about deno's development stage: can the brave already run it in production, or there are probably too many breaking changes in the pipe that it's better to wait?
- inglor 7y agoThe brave? Sure - but there will likely be breaking changes. I actually run a small deno server in production for a non critical service and it's been working out fine :]
- MuffinFlavored 7y agoCheck out the benchmarks. I'm pretty sure normal usage (aka actual HTTP server, not specialized use cases just for benchmarks) is quite a bit slower than node.js
- codewithcheese 7y agofyi the sound gets much better at the 3 minute mark
- LunaSea 7y agoAs a long time Node.js developer I took a look at the project but it's still a really half-baked implementation of the security flags. You almost always end up flipping all security switches off because your application needs every feature (network, filesystem, etc). No package signing, no flags per module, no syscall whitelisting, etc.
- qaq 7y agoIt's not even 1.0 yet.
- LunaSea 7y agoI'm not talking about the maturity of the project but more about the concept of the feature flag for security.
- tfolbrecht 7y agoI like the idea from a ux perspective. It puts the control in a place where the user runs the code.
- inglor 7y agoNode.js had a PR to add that in (with packages enforced but not your 'own' code) and Node has policies to deal with loading untrusted code ( https://nodejs.org/api/policy.html https://nodejs.org/api/policy.html ). Personally I isolate with OS level containers as I think it's a lot more robust and tested but I definitely see the merit in Deno exploring this - even if it doesn't really work yet it's interesting.
- mnutt 7y agoI thought node.js policies were basically just SubResource Integrity hashes? Are they planning for something more? I’ve been looking into the isolated-vm module recently and it looks pretty nice. Fly.io built their run-untrusted-code service on top of it.
- 7y ago
- unictek 7y agoCareful with Deno, performance is still low: https://user-images.githubusercontent.com/3397140/48649635-89060d00-e9f3-11e8-9447-d4dbd050a310.png https://user-images.githubusercontent.com/3397140/48649635-8...
- inglor 7y agoThat's just FUD through a synthetic benchmark by the person who wrote uWS after he approached Ryan and Ryan wouldn't do everything he asked for...
- unictek 7y agoRunning a local benchmark to compare Node.js and Deno gave me the same magnitude of performance difference. I like the concepts behind Deno but the performance should stay a top priority. Even more for a new technology that is looking for future adoption. If Deno gets faster than Node.js, I adopt it. If it stays 5x less performant than Node.js, I skip it.
- kevinkassimo 7y agoAre you running deno 0.10.0 versus Node? Since there has been some internal refactoring it should now be 80% wrt basic http req/sec (ref: https://deno.land/benchmarks.html#all https://deno.land/benchmarks.html#all , though the benchmark might have not covered everything) Overhead from Flatbuffers is a major reason of the slowdown and we are seeking to get rid of it.
- PudgePacket 7y agoThat bench has deno at 0.2, it's now at 0.10, though I have no idea how much performance work has been done. Performance should improve over time, there's no fundamental reason from what I understand that it shouldn't be as fast or faster than node. node has had 10 years of work and performance effort from so many people and organisations.
- siempreb 7y ago> A Secure Runtime for JavaScript and TypeScript So, does it support a specific ECMAscript version? Or am I restricted to the Typescript JS definition? This is confusing..
- JeremyBanks 7y agoNobody's support strictly matches a specific ECMAScript version.
- ComodoHacker 7y agoDoes "secure" implies some protections against Spectre-like attacks?
- kunaluchain 7y agohttp://rajasthanpatwarivacancyrecruitment2019.in/patwari-bharti-2019/ http://rajasthanpatwarivacancyrecruitment2019.in/patwari-bha...
- kodablah 7y agoI admittedly haven't researched too deeply, but are there any examples/docs on embedding Deno in another Rust program and/or writing/exposing Rust libs with a TS API?
- limsup 7y agohttps://crates.io/crates/deno https://crates.io/crates/deno