1,502 karma · joined August 27, 2012
Currently: Senior Architect at F5, working on Cranelift/Wasmtime in the Office of the CTO.
Previously: Principal software engineer at Fastly, working on Cranelift/Wasmtime for the Wasm-based Compute@Edge project, 2020-2024. Mozilla, working on the SpiderMonkey and Cranelift JIT compilers in Firefox, 2019-2020; PhD student (ECE) and then postdoc (CS) at Carnegie Mellon working on compilers, static and dynamic analysis (2009-2013, 2015-2019).
More previously: Google (2014-2015), and Intel (2013-2014).
Web: https://cfallin.org/
[ my public key: https://keybase.io/cfallin; my proof: https://keybase.io/cfallin/sigs/ZJj2pg69eB6Hs0cl9j_babYkyADojbWrfe4uZp11LMo ]
The NetBSD kernel has the ability to be built as a library, letting various drivers be used in other ways -- it's called a "rump kernel" [0]. I've never played with it myself but my understanding is that this would be sufficient to provide drivers in one's own kernel, given enough plumbing and shims and such.
(With enough shims one could borrow drivers from any kernel -- see ndiswrapper to use Windows network-card drivers in Linux -- but the rump kernel scaffolding is supposed to make it easier.)
[0] https://www.netbsd.org/gallery/presentations/justin/2015_Asi...
In general it's very nice to be able to prototype queries/inference rules quickly and then tweak clause ordering, etc for performance later if needed.
Here's an interesting article about Spanish flu and radiators: https://www.bloomberg.com/news/articles/2014-02-17/our-indis...
"engineering manuals from the 1920s dictated that radiators and boilers be manufactured large enough for 'the coldest day of the year, with the wind blowing, and the windows open.'" (!)
(Relatedly, I wonder what effect the current pandemic will have on the modern trend of well-sealed homes...)
When I first moved to Pgh, the street map reminded me of this Mario Kart 64 level: https://mariokart.fandom.com/wiki/Yoshi_Valley
It was fun but happy to be back on the west coast now :-) Also, glad I've never had to drive in NYC -- that looks tense!
https://www.google.com/maps/@40.4287854,-79.9328641,3a,75y,6...
I only took this ramp a handful of times before I learned to detour several miles to avoid it...
Do you know about `wasm2wat` (from the WebAssembly binary toolkit, "WABT")? It produces a 1-to-1 text representation of the bytecode and is meant to always roundtrip via `wat2wasm` back to the same bytecode.
Also on computer architecture / story of developing a new processor, "The Pentium Chronicles" by Robert Colwell is a really interesting book on the story of the Pentium Pro, the first out-of-order CPU from Intel.
I would love to read a collaborative work between you and James Mickens -- this genre of writing seems sadly under-present in the computing world...
The big difference, in my mind, is that each app is integrated with a permissions/capabilities model and strongly sandboxed by individual instance or document. Sandstorm itself handles logins, and handles capabilities to access documents; then e.g. there's no way that Etherpad can accidentally leak your doc to someone else unless you've granted a Sandstorm-level permission to that person.
It sort of flips from the "walled-garden app" model, where the app is the boundary and individual docs and users are within the app, to the traditional "computer with filesystem" model, where the user login and the file with permissions are system-level concepts. (Except instead of "file", they call it a grain, and it's a separate instance of Etherpad or Gogs or whatever.) That's also what makes this more than just Docker containers -- deeper integration into the app.
That also gives you flexibility to have a bunch of different instances of a single app, and IIRC, they have functionality to import/export those instances in a well-defined format from one host to another.
At least, that's what I remember from playing with it 4 years ago. In any case, I got the impression that the model was much more secure, and flexible, than just "install Gogs on vanilla Linux".
LEA rDest, [rBase + 8*rPtr]
(The "load effective address" instruction computes an effective address like a load or store would, but just gives the address without doing a memory access.)Consider: should the VM somehow try to analyze the running code and determine when it's about to commit a logical error and return "forbidden" data? What specification states which data is forbidden?
Consider: even the most high-level VM can execute a program with logical errors if it is Turing-complete. A Java or Erlang program running on a bug-free, fully-compliant implementation of the respective VM can still get (e.g.) an authorization condition wrong, or incorrectly implement a security protocol, or return data from the wrong (in-bounds, but wrong!) index in an array.
Personal opinion: lots of cities have specific quality-of-life issues of varying degrees; in the Mountain View area now, I could equally complain about Superfund sites from all the early silicon industry dumping. Overall in Pittsburgh, the walkability, easy access to hikes through large parks in city limits, lack of stress about high rents, etc., probably outweighed an occasional whiff of sulfur wrt my quality of life. Everyone is of course welcome to make that tradeoff differently!
I wouldn't necessarily discount the city for this; in my time there, I realized there were really two Pittsburghs. You'll see the steel-town football-obsessed side any time you walk past a bar, but near the CMU/Pitt bubble it actually had a really intellectual vibe that I miss now that I've left. Not just the abundance of grad students, doctors and the like, but good libraries and bookstores, a fantastic symphony orchestra, a quality coffee scene, etc. Has a Portland/Seattle-like (including gray weather) vibe. And Steelers games are great times to go grocery shopping!
The travel situation isn't great though. PIT has direct flights to most east coast cities but getting to the west coast indeed sucks. (United does have a direct SFO flight, IIRC, if a bit pricy.)
[1] https://fastmail.blog/2019/08/16/jmap-new-email-open-standar... [2] https://fastmail.blog/2016/12/12/why-we-contribute/
Fundamentally, preemption has to originate from a hardware IRQ (or IPI from another core), so really the only way would be to kernel-bypass by setting an IRQ handler in userspace (ring 3). That's technically possible on x86 (IDT entry can have a ring-3 code segment) but I don't think the kernel has a mechanism for that...