3 ms·
The thing I really want is a language or environment with no implicit access rights. So, if I call add(a, b) then the add function doesn’t have implicit access
by josephg 1mo ago
The thing I really want is a language or environment with no implicit access rights. So, if I call add(a, b) then the add function doesn’t have implicit access to the filesystem, network or global variables in other parts of the program. If you want to give a function access to a subdirectory, you should pass a handle to that subdirectory as an argument and use openat() or equivalent.
This would guarantee - at a language level - that leftpad or log4j can’t root my computer.
Safe rust doesn’t give this guarantee. Safe code can still make arbitrary syscalls. Safe rust can convert a path string to a File. Or open arbitrary network sockets. Rust also doesn't have a way to import a crate but forbid the use of any unsafe blocks.
I want to be able to use 3rd party code from cargo without getting hacked. Right now rust does not keep me safe from these supply chain attacks.
I don’t know enough about safe Haskell to know how close it tacks to this. But that’s what I want.
- tome 1mo agoI think nextaccountic is not technically fully correct, but he/she is at least correct in the most important part: Safe Haskell is not really practical. But if you don't want an ironclad guarantee and instead you're content with making wrong code obviously wrong even if it's not formally verified, then I recommend Haskell with a capability system (what the Haskell world calls an "effect system"). As far is I'm concerned there are two practical choices in 2026, Bluefin (mine) and effectful (one of Bluefin's inspirations) * https://hackage.haskell.org/package/bluefin https://hackage.haskell.org/package/bluefin * https://hackage.haskell.org/package/effectful https://hackage.haskell.org/package/effectful
- josephg 1mo agoHow does this compare to Spritely Goblins? I had a good chat with Christine about it at a conference. She said "Ah, you've been infected with the capabilities virus too. My condolences." https://spritely.institute/goblins/ https://spritely.institute/goblins/
- tome 1mo agoInteresting, I have not heard of Spritely Goblins! But neither Bluefin nor effectful could be described as distributed capability systems/effect systems, so I don't think they're comparable. On infection, I think it's a bit like being infected by mitochondria :)
- tialaramex 1mo ago> The thing I really want is a language or environment with no implicit access rights I don't think you'll find anything like that from a General Purpose Language, so you probably want something like WUFFS [Wrangling Untrusted File Formats Safely]. https://github.com/google/wuffs https://github.com/google/wuffs
- josephg 1mo ago[dead]