3 ms·
Pony has a concept of Object Capabilities[1]. Basically it lets you whitelist capabilities like network access or more granular access like specific protocol ac
by pull_my_finger 3y ago
Pony has a concept of Object Capabilities[1]. Basically it lets you whitelist capabilities like network access or more granular access like specific protocol access. In the docs it states "If the library is asking for more authority than it needs, do not use the library."
This doesn't solve the problem of people pulling in huge dependencies that they can't reasonably scan, or so many dependencies that they can't scan, but surely it's a step in the right direction.
[1]: https://tutorial.ponylang.io/object-capabilities/object-capabilities https://tutorial.ponylang.io/object-capabilities/object-capa...
- Avshalom 3y agohttps://austral-lang.org/ https://austral-lang.org/ is another with capabilities baked into it.
- 1letterunixname 3y agoDoesn't do much good if the OS doesn't enforce them like seL4 can.
- tauroid 3y agoIf the FFI is also capability gated why can't the language do it? Edit: Pony seems to rely on restricting FFI privileges at the package level https://tutorial.ponylang.io/object-capabilities/trust-boundary https://tutorial.ponylang.io/object-capabilities/trust-bound.... Suppose it could have been function by function ("unsafe") but this sounds fine. Not sure what else I could have meant by a capability gated FFI.
- gpderetta 3y agoIn practice it means no redistributable native libraries or binaries. You would need installation time compilation, jittin or pure interpretation. Or some sort of trusted compiler-as-a-service with signed binaries.
- IshKebab 3y agoYou can compile to WASM to work around that, with some performance penalty.
- stefanha 3y agoLanguages with capability-based security may not be supply chain safe. For example, Pony allows third-party libraries to use the unsafe FFI by default. I think Pony is close to a supply chain safe programming language, but it looks like it's not safe by default. I don't know enough about Pony to understand whether this is a fundamental design issue or just a question of carefully invoking the compiler to avoid unsafe features.