https://mods.factorio.com/mod/Moon_Logic
Besides, it's quite limiting to create software that can't just execute in a Turing complete environment.
Anyway, we really need interpreters that include a strong capability system.
https://mods.factorio.com/mod/Moon_Logic
Besides, it's quite limiting to create software that can't just execute in a Turing complete environment.
Anyway, we really need interpreters that include a strong capability system.
Sure, the output of the lua compiler might be guaranteed to not invoke undefined behavior in the byte code interpreter, but the compiler itself might be vulnerable.
To my knowledge, compilers like GCC and clang treat source code as trusted for this reason
Or maybe, down the road, Factorio could enable mods with greater privileges, as long as they are open source, and do an App Store-style review process with the community. Approved mods get not just bytecode, but perhaps even some of the typically forbidden modules like filesystem access. Unapproved mods using those enhanced privileges won’t run without a startup flag.
This works until a popular mod requires it (for legit reasons) then enabling the option becomes the de-facto standard for people who install mods.