Safe haskell

Safe haskell
复制标题

安全哈斯克尔

DOI:
--
复制
发表时间:
2013
期刊:
ACM SIGPLAN Symposium/Workshop on Haskell
影响因子:
--
通讯作者:
David Mazières
David Mazières
中科院分区:
--
文献类型:
--
作者:
David Terei;S. Marlow;S. Jones;David Mazières

文献摘要

被引文献

相似文献

尽管Haskell主要是类型安全,但实现包含一些漏洞,代码可以绕过打字和模块封装。本文提出了安全的Haskell,这是一种关闭这些漏洞的语言。安全的Haskell使得可以局限并安全执行不受信任的,可能是恶意代码。通过严格强制执行类型,安全的Haskell允许从API沙箱到信息流控制的各种不同的策略可以轻松作为单月实施。安全的Haskell的目的是尽可能不受欢迎。它强制执行程序员倾向于通过公约遇到的属性。我们描述了安全的Haskell的设计和实施(目前与GHC发货),该设计不在该语言的安全子集中​​。我们使用安全的Haskell来实现在线Haskell解释器,该解释器可以在没有开销的情况下安全执行任意不信任的代码。安全Haskell的使用极大地简化了这项任务,并允许使用大量现有代码和工具。
Though Haskell is predominantly type-safe, implementations contain a few loopholes through which code can bypass typing and module encapsulation. This paper presents Safe Haskell, a language extension that closes these loopholes. Safe Haskell makes it possible to confine and safely execute untrusted, possibly malicious code. By strictly enforcing types, Safe Haskell allows a variety of different policies from API sandboxing to information-flow control to be implemented easily as monads. Safe Haskell is aimed to be as unobtrusive as possible. It enforces properties that programmers tend to meet already by convention. We describe the design of Safe Haskell and an implementation (currently shipping with GHC) that infers safety for code that lies in a safe subset of the language. We use Safe Haskell to implement an online Haskell interpreter that can securely execute arbitrary untrusted code with no overhead. The use of Safe Haskell greatly simplifies this task and allows the use of a large body of existing code and tools.