Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tschneidereit
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
tschneidereit
4mo ago
Oh, no worries at all—it happens!
2.
▲
by
tschneidereit
4mo ago
[Creator of the StarlingMonkey JS runtime here] > It works in the browser already, by bundling another browser runtime engine into wasm. Note that that's not how JCO works: JCO unbundles a Component, emitting core wasm modules plus
3.
▲
by
tschneidereit
5y ago
Oh, no worries at all! While there was no acquisition involved, a whole group of folks working on WebAssembly at Mozilla (myself included) moved to Fastly last Fall. What I tried to emphasize is that instead of the projects at hand here bei
4.
▲
by
tschneidereit
5y ago
It's really the other way around: we joined Fastly because we knew it's a place where we could do this kind of work in the open. None of the code involved here existed a year ago, and none of it was somehow forced to be open sourc
5.
▲
by
tschneidereit
7y ago
That is how we support references in the Rust toolchain right now, via wasm-bindgen, and it's an important part of making unforgable references work for languages that rely on linear memory. It doesn't help with making capabilitie
6.
▲
by
tschneidereit
7y ago
Agreed, and there are a lot of UX questions to sort out. Many security concepts took many attempts to figure out in full (or to the extent that they have been figured out :)) One important aspect here is that this doesn't just target w
7.
▲
by
tschneidereit
7y ago
Indeed: that and many other things are prior art in this space. And there is a lot of prior art for what we're working on—this is not meant as an academic research project! :)
8.
▲
by
tschneidereit
7y ago
What you're describing will indeed be introduced with the WebAssembly GC proposal: https://github.com/WebAssembly/gc For languages that can express unforgeable pointers as first-class concept, that is indeed a ver
9.
▲
by
tschneidereit
7y ago
To expand on this, capabilities allow us to go further than pledge(2): it enables selective forwarding of capabilities to other nanoprocesses, such as only forwarding a handle to a single file out of a directory, or a read-only handle from
10.
▲
by
tschneidereit
7y ago
And Wasmtime will also support both of those. Support for environments in which JITting is not an option is of course really important to this!
11.
▲
by
tschneidereit
8y ago
We're working on that, too :) See this post from last Fall where we laid out a way to think about where WebAssembly is going, which use cases to enable, and how: https://hacks.mozilla.org/2018/10/webassemblys-
12.
▲
by
tschneidereit
8y ago
Good news: we fully agree with these goals! On 1, the libc we're working on[1] is based on musl. It won't ever be 100% compatible with all code, because that runs into constraints imposed by our security goals, but the vast majori
13.
▲
by
tschneidereit
8y ago
Oh, this is amazing!
14.
▲
by
tschneidereit
8y ago
Yes!
15.
▲
by
tschneidereit
8y ago
We've mainly based the current design on CloudABI/Capsicum, but it's all early days, and Fuchsia is on our list of systems to at the very least take heavy inspiration from :)
16.
▲
by
tschneidereit
8y ago
(Member of the team at Mozilla here ) Yes, that's the list. And the layout of structs, strings, etc is up to the compiler, within the bounds of the restrictions WebAssembly imposes. We'll definitely have a test suite, but this is
17.
▲
by
tschneidereit
8y ago
This is indeed a problem for Wasm/JS integration. The JS WeakRef proposal[1] will address it for many use cases, and the WebAssembly GC proposal[2], combined with JS Typed Objects[3] will address many others. Even before those features
18.
▲
by
tschneidereit
10y ago
Intermittently failing tests are a problem that all large code bases have, regardless of the used language. See for example this post about Google's code base[1], which is largely Java, Python, and to some extent Go and Dart, IIUC: ht
19.
▲
by
tschneidereit
10y ago
That last part doesn't work, unfortunately. We looked into doing exactly that, but the way history navigation works is specified quite strictly - and relied upon by existing web content - making this infeasible.
20.
▲
by
tschneidereit
10y ago
See my reply in another conversation thread: https://news.ycombinator.com/item?id=13520978
21.
▲
by
tschneidereit
10y ago
(Member of the browser.html team here) There's a section at the end about how we got to this approach. You're right that there isn't too much detail there, though. In short, research on how people interact with information so
22.
▲
by
tschneidereit
10y ago
Things like history management. While tabs in browser.html are just iframes, browser.html needs more access to the contained documents to be able to fully do its job. For security reasons, you can't get at an iframe's current loca
23.
▲
by
tschneidereit
12y ago
EME is a way to add DRM support to html5 video, but it's not compatible with Flash's DRM system, so can't directly be used to implement that.
24.
▲
by
tschneidereit
12y ago
Thanks, bug filed: https://bugzilla.mozilla.org/show_bug.cgi?id=1133323
25.
▲
by
tschneidereit
12y ago
Can you give steps to reproduce this crash? It should definitely not happen. In fact, until https://bugzilla.mozilla.org/show_bug.cgi?id=558184 is implemented we rely on an installed Flash plugin to make the Flash detecti
26.
▲
by
tschneidereit
12y ago
The problem with PIV, as with a few other video services, is that it uses DRM. AS you're probably aware, there are some quite unfortunate laws around that which prevent anyone from just offering an alternative implementation of a DRM s
27.
▲
by
tschneidereit
12y ago
Exactly. We did a survey of Flash exploits from the last few years and almost all of them would simply have been impossible in Shumway. That doesn't mean that Shumway will automatically free of all security bugs, but the whole class of
28.
▲
by
tschneidereit
12y ago
We're looking at tests and sometimes implementation details from the other open source projects, yes. E.g., we've used the SWFDec tests extensively in our work on the older AVM1 language runtime.
29.
▲
by
tschneidereit
12y ago
Eventually we hope to get to the point where we can play all SWF files and hence have Shumway be a complete drop-in replacement for the Flash plugin. Since implementing full support for all capabilities (and matching all quirks) of a two de
30.
▲
by
tschneidereit
12y ago
Our pleasure! :) There are two easy ways to test Shumway on all SWF files: if you don't want to use Firefox Nightly, you can just install the extension from http://areweflashyet.com/ and should be all set. If you'
More ›