Security in Plan 9 (2002)
9p.io
9p.io
man mount_9pThere is an old KEXT on GitHub [0] that can mount them from the Finder, but KEXTs are on the way out...
virtfs is the good one, not 9p.
Virtio-fs is independent of 9P and has optional support for using shared memory to greatly increase performance, it also maps better to the permissions and metadata of "modern" filesystems IIRC, not sure if 9pvirtio had this problem but I remember coworkers having permissions problems with the 9P bridge in WSL2 (Plan9's permission system is very simple and doesn't map well to other VFS's)
Plan 9 is a pure VFS OS. 9p uses regular unix permissions which map just fine. The major issue is that since plan 9 is all vfs, there are no crufty unix leftovers like hidden dot files or hard/soft links. User specific configuration files belong in $user/lib and bind replaces hacky links. These old unix hacks were accommodated in 9p2000.u. Further extensions to .u resulted in 9p2000.L which adds some Linux metadata stuff (I cant remember right now, my memory of 9p2000.u/L is fading).
Unfortunately, kids these days seem to be afraid of files. For a hardcore unix fan, curl and wget are useless tools when you can just cat /www/url
/www/url < request > answerI tried to find docs on it, but couldn't. If you could link me to some, I'd appreciate it.
[1] After posting this I remember like a doofus this is an OS from the 90s. Of course it doesn't. But a similar question could be asked about any other TLS level setting. That's just one I've had to spend more time debugging using curl in the past.
Sad but true. Android and iOS are the worst offenders I've seen. They're apparently trying to completely get rid of the concept of files altogether, which is really unfortunate for anyone wanting to build cool stuff on those platforms.
I understand there can be security benefits but at what cost.
I’ve never followed Android very closely but iOS began with no user-facing notion of files and added one many years and major releases later. Granted they’re not Unix everything-is-a-file, as in you can’t execute them or do all sorts of other everything-is-a-file operations with them. But adding mostly-general file functionality is definitely not trying to get rid of the concept.
$ strace htop 2>/tmp/e # wait for htop to load and then press 'q'
$ cat /tmp/e | grep ^open | grep /proc | wc -l
49817
htop is essentially "find /proc" with a pretty output. Is htop broken for you?Timing-wise, it was too late for what they ended up doing, but anything all those people worked on is bound to have some interesting ideas.
It's been weird watching the rise of iOS loosen the reliance on, or even awareness of, files, when 9P was all about files. Files for everything!
I had the impression that it was held back by its proprietary license.
That was my impression, too. And then it got relicensed to a FOSS license... that was GPL-incompatible. And then it got relicensed again to GPLv2, and then it got relicensed yet again to its current MIT license.
In any case, each of these license changes was too little too late to really improve Plan 9's practicality from a "can I legally use this?" standpoint.
But basically, the hardware support was pretty bad. It took me a long time to find a SCSI controller which was supported, when ATA disks were already standard for years. Same with network- oder graphic cards.
Nowadays, if esoteric OS's would just support standard Vmware hardware, they'd be much more successful (looking at you fuchsia!)
For those interested, Himitsu[1] is based on the design of Factotum, but ported to *nix. It's actually a pretty good systems secret store.
That said, I can't say I've seen anyone try to write anything that scales like nginx on Plan 9. That doesn't mean it hasn't happened, I've just not seen anyone talk about it too much.
It did run on IBM's Blue Gene for a bit (https://www.usenix.org/legacy/event/usenix07/posters/vanhens...) but as you can see that was some 15 years ago, and I'm not sure we're talking about anything even remotely similar to a single computer handling tons of concurrent connections.
Plan 9 can also run Go binaries, but, again, not really sure we're talking about the same thing as nginx-level scale.
Rob Pike was on of the main developers behind plan 9 and Go and involved in concurrent programming research focusing on CSP.
Multi-processing was a main focus of plan 9's design and it works well as procs are cheap to spawn on plan 9. Procs are also the smallest unit of execution on plan 9, threads are just light weight procs with a shared heap to pass pointers around. Thread stacks can also be shared as well by being allocated on the heap via fork(2) RFMEM flag (its all done with malloc in the background).
The issue with vanilla (aka labs or legacy ) plan 9 is there is a hard coded limit of 2k procs statically allocated at boot. This was a pragmatic design decision. The unfortunate side effect is vanilla plan 9 falls over under any sort of work load requiring spawning lots of procs like handling web requests. This is actively being worked on by 9front developers so sites hosted on 9front should hold up better (patches welcome :-).
> That said, I can't say I've seen anyone try to write anything that scales like nginx on Plan 9.
Because you really don't need those big web serving monoliths on plan 9. You wire things up using rc scripts and programs like execfs (implements cgi) plus httpd/tcp80 or another web serving listener and sandbox code using namespaces. Plan 9 is more true to unix philosophy and more unix than unix. (edit: execfs is experimental but available on shuthub.us along with other webstuff like tcp80)
1. RK3588 Rockchip 12in Thinkpad cross HTC style slideout keyboard form factor 2. Plan 9 Legacy OS 3. seL4 microkernel, Qi cross Racket IDE
and to compete what people can do scaling out to the "cloud" at price thresholds, maybe a gifted individual or team will realise the 2100 movie's HAL9000 sentience.