Re: TIL: all exceptions before the commit point

"Mark S. Miller" <[email protected]> Fri, 18 Mar 2016 20:19:35 -0700
Newsgroups gmane.comp.capabilities.general
Message-ID <CABHxS9gZW10ovnNoToTiV3iFBXCeTPTvnT0vHvOE17Pa1PHwnA@mail.gmail.com>
--===============1504387281576568144==
Content-Type: multipart/alternative; boundary=001a11442ef83fa4da052e5e55da

--001a11442ef83fa4da052e5e55da
Content-Type: text/plain; charset=UTF-8

On Fri, Mar 18, 2016 at 8:18 PM, Mark S. Miller <[email protected]> wrote:

> Your memory is correct. I got the principle from KeyKOS and EROS, both of
> which practiced it brilliantly. Although both as ocap systems, as it my
> application of it, I think the point is orthogonal from ocaps. It is just a
> beautiful way to structure a system.
>
> I have had many idle thoughts about direct language support for this
> pattern but I have not pursued it. I encourage someone to. It smells
> promising.
>
>
>
>
> On Fri, Mar 18, 2016 at 7:15 PM, Dan Connolly <[email protected]> wrote:
>
>> I have flipped through the Secure Distributed Programming with
>> Object-capabilities in JavaScript
>> <http://soft.vub.ac.be/events/mobicrant_talks/talk1_ocaps_js.pdf> slides
>> a few times, but this week I discovered a very interesting point about
>> 48 minutes into the talk
>> <https://www.youtube.com/watch?v=oBqeDYETXME&feature=youtu.be&t=2915> that
>> isn't on the slides:
>>
>> Do all of your gating checks before you do any of your irrevocable side
>> effects.
>>
>> It's somewhat obvious in retrospect, but I don't recall reading it in the
>> "robust composition" thesis or anywhere else. Perhaps it's just my memory
>> that's failing. I should check again.
>>
>
Please don't let my confirmation that it is not in my thesis deter you from
looking at it again!

;)


>
>>
>> --
>> Dan Connolly
>> http://www.madmode.com/
>>
>>
>> _______________________________________________
>> cap-talk mailing list
>> [email protected]
>> http://www.eros-os.org/mailman/listinfo/cap-talk
>>
>>
>
>
> --
>     Cheers,
>     --MarkM
>



-- 
    Cheers,
    --MarkM

--001a11442ef83fa4da052e5e55da
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Fri, Mar 18, 2016 at 8:18 PM, Mark S. Miller <span dir=3D"ltr">&lt;<=
a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</=
a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0=
 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">You=
r memory is correct. I got the principle from KeyKOS and EROS, both of whic=
h practiced it brilliantly. Although both as ocap systems, as it my applica=
tion of it, I think the point is orthogonal from ocaps. It is just a beauti=
ful way to structure a system.<div><br></div><div>I have had many idle thou=
ghts about direct language support for this pattern but I have not pursued =
it. I encourage someone to. It smells promising.</div><div><br><div><br></d=
iv><div><br></div></div></div><div class=3D"gmail_extra"><br><div class=3D"=
gmail_quote"><div><div class=3D"h5">On Fri, Mar 18, 2016 at 7:15 PM, Dan Co=
nnolly <span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]" target=3D"=
_blank">[email protected]</a>&gt;</span> wrote:<br></div></div><blockquote c=
lass=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;=
padding-left:1ex"><div><div class=3D"h5"><div dir=3D"ltr"><div>I have flipp=
ed through the=C2=A0<a href=3D"http://soft.vub.ac.be/events/mobicrant_talks=
/talk1_ocaps_js.pdf" target=3D"_blank">Secure Distributed Programming with =
Object-capabilities in JavaScript</a>=C2=A0slides a few times, but this wee=
k I discovered a very interesting point <a href=3D"https://www.youtube.com/=
watch?v=3DoBqeDYETXME&amp;feature=3Dyoutu.be&amp;t=3D2915" target=3D"_blank=
">about 48 minutes into the talk</a>=C2=A0that isn&#39;t on the slides:</di=
v><div><br></div><div>Do all of your gating checks before you do any of you=
r irrevocable side effects.</div><div><br></div><div>It&#39;s somewhat obvi=
ous in retrospect, but I don&#39;t recall reading it in the &quot;robust co=
mposition&quot; thesis or anywhere else. Perhaps it&#39;s just my memory th=
at&#39;s failing. I should check again.</div></div></div></div></blockquote=
></div></div></blockquote><div><br></div><div>Please don&#39;t let my confi=
rmation that it is not in my thesis deter you from looking at it again!</di=
v><div><br></div><div>;)</div><div>=C2=A0</div><blockquote class=3D"gmail_q=
uote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1e=
x"><div class=3D"gmail_extra"><div class=3D"gmail_quote"><blockquote class=
=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padd=
ing-left:1ex"><div><div class=3D"h5"><div dir=3D"ltr"><span><font color=3D"=
#888888"><div><br><br>-- <br>Dan Connolly<br><a href=3D"http://www.madmode.=
com/" target=3D"_blank">http://www.madmode.com/</a><br><br></div></font></s=
pan></div>
<br></div></div>_______________________________________________<br>
cap-talk mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">cap-talk@mai=
l.eros-os.org</a><br>
<a href=3D"http://www.eros-os.org/mailman/listinfo/cap-talk" rel=3D"norefer=
rer" target=3D"_blank">http://www.eros-os.org/mailman/listinfo/cap-talk</a>=
<br>
<br></blockquote></div><span class=3D"HOEnZb"><font color=3D"#888888"><br><=
br clear=3D"all"><div><br></div>-- <br><div>=C2=A0 =C2=A0 Cheers,<br>=C2=A0=
 =C2=A0 --MarkM</div>
</font></span></div>
</blockquote></div><br><br clear=3D"all"><div><br></div>-- <br><div class=
=3D"gmail_signature">=C2=A0 =C2=A0 Cheers,<br>=C2=A0 =C2=A0 --MarkM</div>
</div></div>

--001a11442ef83fa4da052e5e55da--

--===============1504387281576568144==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk

--===============1504387281576568144==--