BTW, the link to your capabilities columns on your home page appears to be be broken:
As to your original question, Sun was a pretty political place in general. Java was a "weird" place because it only existed because Gosling and some other folks were walking out the door and Scott McNealy asked what he could do to keep them. Their response was give them full autonomy to pursue their ideas. That gave birth to "First Person" which was an independent company wholly owned by Sun (I still have my First Person business card :-)). One of the people knew I was "loose in the socket" as they say and wanted to be sure I had an opportunity to participate and brought me over. It made the last 4 years at Sun mostly enjoyable.
As the limelight started fading from Sun and they started killing off things that couldn't make a profit, they decided to kill off First Person (couldn't make a business case for it). So the Java team negotiated with them to let us release the sources so that when we were job hunting the person could look at the source to see what we had been doing for the last 4 years. We did a stealth release in January of '95, then an "official" release in March. That put us on the front page of the Mercury News. A couple of us attended the WWW conference in Darmstadt Germany and it was all anyone wanted to talk about (much to SGI's chagrin). At which point the politics REALLY ramped up back at Sun when people figured out it would be a "good" thing to be associated with Java instead of a "loser" thing. This affected different people differently, and some, who had pretty bad case of imposter syndrome, went all out trying to claim credit for everything. It ceased to be "fun" with the hard to get along with folks becoming intolerable.
But to be fair you are looking at it from the future backwards. At the time Sun considered "the web" to be a feature not a product (many were bemoaning that because SGI was making it so central to their identity) and a "browser plug-in" (which in itself was kind of a weird concept, originally we thought all applets would be java://applet-host) was hardly something to interest a big enterprise player like Sun. We literally went overnight from other parts of the company saying "I knew they were never going to make it." to "really this project has been ours all along it only seems fair that we should continue to direct it.", Sun Labs, SunSoft, and Sun hardware all claimed to be the reason we were even existing.
It stands today, for me, as a classic "accidental" disruption.
https://en.wikipedia.org/wiki/Lars_Bak_(computer_programmer)
>After participating in the design and implementation of the BETA Mjølner System, in 1991 he joined the Self group at Sun Microsystems Laboratories in Cupertino, California. During his time there, he developed a programming environment for Self and added several enhancements to the virtual machine.
>In 1994, he joined LongView Technologies LLC, where he designed and implemented high performance virtual machines for both Smalltalk and Java. After Sun Microsystems acquired LongView in 1997, Bak became engineering manager and technical lead in the HotSpot team at Sun's Java Software Division where he developed a high-performance Java virtual machine.
https://news.ycombinator.com/item?id=18691446
Java’s Forgotten Forebear (2009) (ieee.org)
https://spectrum.ieee.org/computing/software/javas-forgotten...
https://news.ycombinator.com/item?id=23800625
Call with David Ungar (2015) [video] (youtube.com)
https://www.youtube.com/watch?v=8nfrC-YLYqc&ab_channel=Herna...
https://news.ycombinator.com/item?id=20377077
>Lua's main problem is that it isn't JavaScript (i.e. in JavaScript's enviably lucky position of ubiquitous dominance).
>If I had a time machine, I'd go back and try to convince Netscape to use Lua 2.1 instead of inventing JavaScript (released December 4, 1995). And hire the Self guys (Dave Ungar, Randy Smith and the crew who eventually made the Java HotSpot compiler) away from Sun, and Mike Pall (LuaJIT) from wherever he was!
https://www.lua.org/versions.html
>Lua 2.1 was released on 07 Feb 1995. Its main new features were extensible semantics via fallbacks and support for object-oriented programming. This version was described in a journal paper. Starting with Lua 2.1, Lua became freely available for all purposes, including commercial uses.
https://news.ycombinator.com/item?id=12574290
https://channel9.msdn.com/Blogs/Charles/A-Conversation-with-...
Here's some discussion with Jens Mönig about Self's roots and Morphic's evolution, and Lars Bak on JIT compilation:
Jens Mönig (the author of Snap!) talked all about the new version of Snap! and the new HyperBlocks feature (APL like arrays) in the Snap!Con20 Keynote!
His delight in programming is so contagious even with social distancing and teleconferencing!
https://www.youtube.com/watch?v=K1qR4vTAw4w&ab_channel=JensM...
I asked him about the architectural changes, and we discussed them and he sent me this:
Don: Hi Jens! I'm catching up with all the work you've done since the Snap 5 release! You've made excellent progress!
The problems you had and optimizations you made for Chrome sound interesting! Is there a summary or design document or discussion thread about it that I can read to catch up with it?
Watching your Snap!Con20 keynote on Hyperblocks. Your delight in programming is so contagious even with social distancing and teleconferencing!
Jens: Thanks, Don! The architectural changes were kinda profound, and I wasn't too eager about them had it not been for Chrome's suckiness. Now I'm really glad that all the work paid off, and Snap! has become much better, more stable and faster on all browsers, especially also on mobile ones.
I don't really have a document aside from the short "migration guide" in the Github repo, but that doesn't discuss the architecture. That was a discussion between moi, John Maloney and some others.
Don: Was there a Buddha Nature of the changes, or did everything change?
Jens: Not everything changed.
Don: I find architectural evolutionary stuff fascinating, like watching people solve the trolley problem for sport!
Jens: I basically reverted to a Squeak model of display refreshing, instead of pre-rendering and caching every morph in advance. So the changes were mostly "surgical" and only affected parts of the whole thing.
Don: Bert's paper about SqueakJS was a delightful mind-blower! His solution to the GC problem!
Jens: Now that I mention is, I do have some slides that I drew for SAP management in April that talk about architecture - even though they didn't understand any of it. Let me see whether I still have them...
Don: I loved reading the original Self papers back in 91 or so. I was visiting Amsterdam for the first time and had printed them out, and was reading them in a coffeeshop smoking weed. MIND=BLOWN!
Jens: https://drive.google.com/file/d/1QD-tqtTL3ldtmtqmViNm-C7TW0n...
Don: Thank you!
I'd heard so much about Morphic and wanted to know what that was about, and why people liked it so much. Didn't that come from Self?
Jens: Oh, yes the SELF papers were all wonderful, and Bert's / Vanessa's SqueakJS is the most awesome piece of software.
Yep, Morphic came all from SELF, that's right
Of course, I first saw it in Squeak, and hated it at first, haha.
Don: The self papers just kept piling on layer after layer of amazing stuff: clean model. efficient implementation. jit compiler. but actually debuggable, with dynamic deoptimization! And they made it clear in those papers that those ideas could be applied to other languages, not just Self. They meant Smalltalk but didn't realize that Java would be the main beneficiary soon (then JavaScript).
When I was working for Kaleida and evangelizing ScriptX (like CLOS-y object oriented scheme, kinda like dylan, with a multimedia library), the Python people really annoyed me because they were so smug and happy with their language, and I had a kind of envy for them, clinging to my sinking language.
Then I became one of them and it was ok.
I still do Python, but it's not my focus now, and I'd start new stuff in JavaScript now.
Jens: Yeah, it's somewhat ironic that V8 turned out to be the main beneficiary of Lars Bak's work, not a Smalltalk system, isn't it?
Don: Yes, and sadly ironic that David Ungar stayed loyally at Sun while the other guys forked off their own company that got bought by Sun for lots of money, and poor Dave didn't cash in on the reward he deserved.
Well maybe ironic is the wrong word, just too bad Sun didn't treat Dave better, for all his work. But leaving a company, doing something cool, then selling it back to the company is a great "we told you so" move!
All those ideas from Self were portable, and migrated out of Self to Java then to JavaScript, and lots of other places too, like LuaJIT! But they called in in the original papers, it was not language specific.
I found that part much more surprising and interesting than the presence of harmful politics or people climbing over each other to claim credit for something they previously dismissed.
Of course the story would be even more uplifting had Java become profitable and not just popular...
(I mean certainly Java was worth something and the prime reason Sun got bought by Oracle, but it wasn't enough to help the company survive as an independent entity and even with hindsight it's not obvious to me what strategy would have allowed Sun to prosper)
Would that be something discussed long before anyone implements anything? It touches every part of the system and informs the very essence of the product.
If you combine that with their ego being unable to accept that something is more complicated than they assume, then you get the situation where they propose a solution that is simple, easy to implement, and wrong.
Add to that a measure of "hurt" from feeling like the messenger is getting the credit that you are due. And you get someone who directs their anger at the messenger not the message. Yes, it's broken, yes it's dysfunctional, but it's just business. If you are in that spot you can assuage your hurt feelings by forcing the simple/wrong solution through to "prove" to yourself that you have more power.
In all fairness I don't blame the engineer. They fully believed that their simple solution was completely adequate. I do however blame the management that put up with this. They are the ones who should have been looking out for the company/technology and not whose feelings would be hurt by doing the right thing. Several years later James apologized to me for not doing the right thing, and I appreciated that, but I also recognize that while my system was much more secure and would have not had the vulnerabilities that were later found, it was more complicated and thus harder to validate, and it could have just as easily been broken in a different way.
However - it doesn't abnegate the fact that no matter how you slice it the 'Security Model' is an important thing unquestionably deserving of some open discussion among participants, because there existential consequences.
Especially with Security - it's not one of those things that's ever obvious. This is why we have bug bounties, certain kinds of open source - it generally benefits from 'a lot of eyes, and pondering'.
It's probably something you might try a few versions of and not even make your mind for a bit.
The evidence that 'it's a big deal' is in your own response: the solution was screwed up, and Java paid a big price.
The fact that anyone 'right or wrong' was trying to put together a solution and just 'check it in' frankly is a little frightful.
Engineers threatening to quit, and decisions made on the basis of that are comical.
If this narrative is authentic, then it seems Java Security Model - and probably a bunch of other things were just 'slammed together' by a bunch of smart guys passionately working on it, arguing, playing games' and we're lucky to have what we have today I guess.
Imagine what we would have if there was some intelligent social deliberation there.
Literally as soon as we started prototyping "Webrunner" (which later became "HotJava"), the web browser written in Java, we started talking about the risks associated with loading executable content from a server you didn't trust and running it on your computer.
Everyone agreed we had to do something but not everyone agreed with how much we should do given that Sun was going to toss the language anyway and so we would be lucky if we got half the number of users that Tcl already had.
I was nominally tasked with solving this problem and chose to solve it to the best of my ability.
To do that I created a system for signing Java code, a capabilities model that would prevent unauthorized code execution, started Sun on the path of licensing a right to use the RSA patent, added an entire crypto subsystem to the sys.* code base, negotiated with the NSA a system that would allow Sun to actually ship strong encryption in an interpreted language, and designed some structure that had to be in the JVM to support this framework.
But what you have failed to grasp is that at the time the prevailing attitude at Sun corporate was that this was a 'throw away' project and amongst some of the engineers in the team, they were more interested in showing off their language design skills rather produce something that was an actual product. After all, as these language designers reasoned, Java had removed all the things that made C and C++ unsafe right? So if the language was correct (as the reasoning went) it couldn't possibly be used to do something bad.
One of them felt all of this "security complexity" was unnecessary. They also felt that my checking into the code base this complex stuff was disruptive. But they did agree that there needed to be "something" so they wrote the SecurityManager class over the weekend and called it done. And threatened to quit when I tried to get it undone.