4 ms·
Wow! I really like this project. I have been loving actor systems, and your project brings a lot of interesting concepts together. I do not have much of anythi
by Nican 4y ago
Wow! I really like this project. I have been loving actor systems, and your project brings a lot of interesting concepts together.
I do not have much of anything to say, but I did come up with an idea. One thing that Fuchsia (operating system) does is that parents are able to lock down the permissions when spawning childs. For example, if a child is spawned with no I/O permissions, that child will have all those permissions removed, and any child that spawns from that will have the same restraints.
Could Lunatic support something like this on the far future?
EDIT: I just read the FAQ and looks to be heading that way. Awesome.
- bkolobara 4y agoThanks! You can already do this in lunatic. For example, in the Rust library you can create a configuration (https://docs.rs/lunatic/latest/lunatic/struct.ProcessConfig.html https://docs.rs/lunatic/latest/lunatic/struct.ProcessConfig....) with specific permissions (e.g. no i/o) and then use the spawn_config function to spawn children with it. Children will automatically inherit the configuration from their parents. Lunatic is also a bit of a meta-system. We expose a lot of the vm stuff directly to the running wasm instances. So you can in a running wasm modules embed other modules or dynamically load them, then spawn processes from them. At the same time you can use the configurations to limit capabilities of this, potentially untrusted, modules.