My Pure Rust Wishlist
gburghoorn.com
gburghoorn.com
I think a better goal would be to create an entirely new design, with a decent scripting language for expressing which authentication/authorization queries to do and when to succeed (which PAM config files, ahem, are not), and get distros to use it. And maybe allow loading legacy PAM modules as an optional feature.
(Aside from all the obvious suckage, I have my personal pet peeve: it’s been how many years, and we still can’t grant ambient capabilities using PAM?)
Like, why does it still have to be C, didn’t we learn a bit from all those vulnerabilities?!
The latter is a functionality weakness (e.g. doing anything useful using PAM when accessing a system over SSH or HTTPS or really anything else is a mess and not terribly useful, but it also makes the fact that PAM is written in C be less of a problem: there is so little untrusted input available to PAM that it’s not a very easy target.
What PAM needs is a redesign. A different language would just be icing on the cake.
Very hardware focused. I would say the biggest one is OpenSSL. My heart always drops when something depends on that. Guaranteed pain.
Not sure about TCL. TCL is a terrible language. Surely it would be better to simply move to a sane modern one? There are a few decent embedded languages written in Rust, e.g. Rhai or Starlark.
I've definitely had "damn, I wish I could do xyz" moments with all three of those, but "early days" is a bit of a stretch.
Somebody has to make all this stuff. Be somebody. If it doesn't do what you want, fork it and make it do it. If it's unmaintained, fork it and take it over.
If companies start using the code, isn't it child labor?
Slint alone is more than capable and backed by an actual company of ex QT engineers. ;P