8 ms·
Shill: A Secure Shell Scripting Language
- anonfunction 12y agoVery relevant timing. I've all but switched to zsh on my dev boxes but this looks to be a great option for production environments.
- notduncansmith 12y agoAll but? Edit: I meant to ask what your setup is like, such that you would describe yourself as being somewhere between "have switched" and "have not switched". It seems to me like it would be one or the other.
- kolev 12y agoWell, zsh isn't much better than Bash. Fish beats both, but the web-based stuff annoys me. Given Windows has the super-powerful and elegant PowerShell, I think a new shell language is definitely needed.
- noinsight 12y agoNot just a shell language, I want a better/modern shell. Fish is pretty good but not quite and I don't need "newbie friendly".
- kolev 12y agoExactly! The newbie web configuration is such a turn off, but the language is definitely better - events and all.
- Symmetry 12y agoYou can always just edit config.fish in vim if you want to, that's what I do.
- kolev 12y agoIt's hard to explain, but just the fact that it has some huge useless feature bothers me.
- jamesgeck0 12y agoIs it really that huge? The config pages are pretty simple, and it looks like it's just served using Python's built-in SimpleHTTPServer library.
- kolev 12y agoIt's some kind of a heuristic rule: Don't use a product by a guy with a vastly different mindset than your own.
- xiaq 12y agoTime for advertisements! I've been doing this for some time: https://github.com/xiaq/elvish https://github.com/xiaq/elvish (https://news.ycombinator.com/item?id=8090534 https://news.ycombinator.com/item?id=8090534)
- Eleopteryx 12y agoCan't say I like the name; it evokes nothing but negative connotations.
- vezzy-fnord 12y agoI just find it so amusing, personally. I like it. It fits in with the security theme relatively well, too.
- Eleopteryx 12y agoHow does "shill" relate to security in any kind of fashion? Am I missing something?
- zalzane 12y agoin the same way that the name "john the ripper" relates to security it's just a cute name
- vezzy-fnord 12y agoIt has that rogue intelligence/geopolitical power play to it.
- danking00 12y agoIt's a play on the name "Scheme" and "Schemers" which was continued by the "Racket" and "Racketeers" name. There's something of a history of naming things like this in the LISP community. Wikipedia says: "Scheme was originally called 'Schemer', in the tradition of other Lisp-derived languages like Planner or Conniver." Your reaction is, however, valid. People outside the Scheme community and it's closely related communities are unlikely to know this etymology.
- Gonzih 12y agoDeveloper in Racket, does not have S-expressions syntax? Why? Would love to use some scripting lisp on my machine.
- xiaq 12y agoMaybe some lisp hackers gradually find out that a lot of parenthesis is not that fun for everyone. Not meant to enrage Lisp hackers, I actually find parenthesis bearable. There is also Pyret(http://www.pyret.org/ http://www.pyret.org/) created by some people on the PLT team (you can confirm this by looking at the owner of their Github repo https://github.com/brownplt/pyret-lang https://github.com/brownplt/pyret-lang). But more surprisingly it's implemented in JavaScript...
- agumonkey 12y agoAs usual, one just need a paredit equivalent to forget about parens forever. I also remember an extension (maybe emacs, or a scheme SRFI) removing the top-level parens (implicit rewriting rule). repl> defun id (x) x repl> defun fact (n) (if (< n 2) 1 (* n (recur (1- n)))) A little more pleasant for people used in curly braces I'd say.
- xiaq 12y agoCodes are read much more often than written. paredit makes editing parens easier, but reading them is still difficult for the unskilled (rainbow parens help, but it's still far from painless). Compare this to how autocompletion makes it easier to write a VeryVeryVeryVeryVeryVeryVeryLongMethodName but doesn't make it any easier to read.
- agumonkey 12y agoI don't know, properly abstracted LISP code is 'supposed' to be tiny (you have all you need to write nice DSL/API) so you don't have long winded things on screen. And I have a differing opinion about code meant to be read. This is a side effect of syntaxful languages read statically in buffer editors. You want to understand LISP ? you load the code, play with and evaluate sub expressions, and sexps/paredit is of great help here.
- thinkmoore 12y agoDeveloper here, happy to answer any questions.
- tkinom 12y agoPersonally, I am not a big fan of putting more acl/config/monitor requirements to the shell. New features add complexity, possible bugs and hacking vectors. Prefer just simply "git add /{etc,bin,sbin,lib} /usr/{bin,sbin,lib} ... && git commit " And daily cron jobs run a "git status" would give me some idea, trigger and confident if someone have "hack into" the server.
- IshKebab 12y agoI would have thought the best way to do secure shell scripting is to use a non-shell language, e.g. Python or Go. It seems most shell vulnerabilities (including shellshock) fundamentally come from the awful and dangerous syntax.
- thinkmoore 12y agoFundamentally, it's not an issue of syntax. The problem is that the way commodity systems are set up, the capabilities of a script or program come from the environment in which it is run. There is no way that a user can easily tell what a script will do, even if it isn't malicious or doesn't have a code injection vulnerability.
- templeos2 12y agoMy grades?