D = P(x,y) ← Q(x,z) % z is not shared with head(D)
throws me a bit, isn't it equivalent (as z is unused) to
D = P(x,y) ← Q(x)
which makes me wonder what y is doing. Would that leave y unbound, and if so is that why it's disallowed?
TIA
3 karma · joined February 20, 2022
D = P(x,y) ← Q(x,z) % z is not shared with head(D)
throws me a bit, isn't it equivalent (as z is unused) to
D = P(x,y) ← Q(x)
which makes me wonder what y is doing. Would that leave y unbound, and if so is that why it's disallowed?
TIA
Any solution to the valid point you have made would have to be organisational.
But the saying goes something like "security annoying, good security is very annoying" - anyone know the original?
IIRC a post on naming servers where someone said if they knew one server was called Bilbo then they had a pretty good idea what the other servers might be named after. Seemed a good point.
[1] yeah, CTEs, I know
[2] yeah, words are cheap from my end, I know
Edit: additionally, and for curiosity: the article covers use of datalog but no underlying security model (eg. consistency of access to resources so you don't have one way blocked to you but can go around via another route, as I know of one homebrew system where you could do that). How do you deal with that? I understand lattices can be used for this (TBH I have only done a little reading on these).