Re: [friam] Formal modeling of systems based on E/CapTP/(Water)Ken/Cap'n Proto ideas
Mark Miller <[email protected]> Mon, 6 Jul 2015 22:59:11 +0200
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAK5yZYhtYjVCTA29-upcO4dAJSQmLMFCmmLWR=BCieiBsw2Rew@mail.gmail.com> |
IANAF -- I am not a formalist. But my co-authors (Sophia and James, cc'ed) are. Today at PLAS (Programming Languages and Security) Sophia presented Swapsies on the Internet: First Steps towards Reasoning about Risk and Trust in an Open World <http://research.google.com/pubs/pub43808.html> Having observed and participated in many attempts to formalize aspects of capability reasoning, I think what Sophia and James have done here is a real breakthrough. Sophia and James, Every Friday morning (10-12 pacific time) we have an informal meeting of various ocap interested people, which we call the "friam" meetings. Several people attend remotely by hangout. We should pick a friam meeting for you both to join by hangout for us to discuss this work. Tony, This has nothing whatsoever to do with temporal logic. Your message just provoked me to announce this as a response ;) Friamers, I know it isn't usually done, but can I ask us all to read-or-at-least-skim the paper prior to that hangout? IMO, this is really important work, Enjoy! On Mon, Jul 6, 2015 at 8:04 PM, Tony Arcieri <[email protected]> wrote: > One thing I've observed about distributed object capability systems is > that things like handling errors and ensuring messages don't get dropped is > generally described in terms of "guidelines". I'm thinking things like COVR > here. > > This gives a developer a lot of expressiveness and flexibility, but not a > lot of assurances that making a single misstep anywhere will break > everything. > > Tools like temporal logic (with mechanically checked proofs) and (formally > modeled) replicated state machines seem like they could help here, and > ensure that all potential failure modes are handled in some way (even if > it's surfacing an error). I'm thinking of something like TLA+ here, at > least to model check an approach like COVR. > > Have there been any attempts at applying temporal logic to proving the > correctness of object capability systems? > > -- > Tony Arcieri > _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk