"I have a mind like a steel... uh... thingy." Patrick Logan's weblog.

Search This Blog

Wednesday, July 27, 2005

Fundamentals of A Security Hole

I hope no one is surprised about the "Greasemonkey Crisis".

Most closed source and open source running applications, middleware, and basic services on the internet or anywhere else are based on a fundamentally flawed concept of security. Greasemonkey is no different; moreover Greasemonkey is especially dangerous sinces its raison de'tre is dynamic customization over the internet.

Things could be different without too much trouble, but the first step is to recognize the real problem and well-known solutions.

Jon followed up with some important questions and implications. And so I should qualify my claim of "without too much trouble".

That should read "without too much *technical* difficulty". The challenging problem I stated above is the that the core problem is so pervasive: in our current systems, but also in our current thinking. A mindshift is needed to recognize the technical problem, realize there are existing technical solutions that are already out of the lab, and that the problem can be tackled one web site and one client application at a time. Not ideal, but much more practical than the ideal.

Some existing solutions that have escaped the labs already: Jon mentioned the E programming language, which if nothing else demonstrates the problem can be addressed on the current Java Virtual Machine. The DARPA Browser illustrates how to use E in a large, real application. The Waterken web application server and the Waterken browser illustrate how to apply the same concept at the level of HTTP and URI's.

The Squeak programming language (Smalltalk) and the Oz programming language are both being extended with E-like capabilities. Objects, virtual machines, web servers are all related concepts (see Mark Baker's recent note and the referenced observation about Smalltalk and HTTP) and all happen to provide a good foundation for capability-based security.

I'll also toss into the mix that concurrency-oriented (pdf) languages like Erlang and Termite are amenable to the same solutions. Capability-based security is just around the corner from our current thinking and our current tools. Capability-based systems can be released onto the internet incrementally, and already have been. Objects, the web, and shared-nothing message passing are all fundamentally doing the same thing... referencing resources and passing around representations of resources that refer to other resources. Just squint a bit to see the similarities and read about capabilities to understand the security aspects of design.

Saturday, July 23, 2005

Shaping Systems with Seaside

Mark Watson writes...

if building web apps in Java, PHP, etc., is like carving something out of rock, Seaside is like using clay.

Wednesday, July 20, 2005

How to Design Large Erlang Systems

From the Erlang User's email list, the question "How do you design large Erlang programs?"

The answers and references from Erlang experts like Ulf Wiger and Joe Armstrong make interesting reading.

Another thread has mre useful design guidance, e.g. on composing state machines from Vance Shipley (and thus).

Tuesday, July 19, 2005

The Next Postscript

I can count the number of lines of Javascript I have written on, well, 20 hands. The core language makes sense to me, nevertheless: apparently Javascript sucks volumes (volume one and volume two).

My take on Javascript is that it could well be the next Postscript: over time, more of it will be generated than written by hand. Worse is better.

Monday, July 18, 2005

CalDAV

Mark Baker comments...

CalDAV is a red herring. We need calendar-specific operations in HTTP like we need a podcast-specific URI scheme.
This bothered me a fair bit too. Say I want to use WebDAV for authoring schematics of electronic circuits. The CalDAV precendent suggests I would begin a SchemDAV committee.

Makes little sense to me. On the other hand to make calendars or schematics more interoperable I think we should begin agreeing on what the HTTP verbs should mean relative to calendar or schematic resources.

Ideally we would agree what POST means when I send you an event description to your calendar. And that's probably the easiest one. We probably need to do other kinds of resources for and about calendars (and schematics) for searching, comparing, and calculating.

Given the recent ballyhoo of microformats vs. XML -- aren't we still dancing around the verbs? We need to agree on how to handle the verbs to get anywhere deep.

Termite: a Lisp for Distributed Computing

Update via email: Guillaume Germain expects to have a release of Termite in the next few weeks. End Update

Termite is a Lisp for distributed computing. (PDF paper and PDF presentation)

From the presentation...

In short: take Scheme, remove mutations, add isolated processes with mailboxes, add message sending and receiving operations and an addressing mechanism.
The bottom line is Termite is Erlang's distributed concurrency model ported to a dialect of Scheme that has been pared back to something like the sequential aspects of the Erlang language (chapters from Erlang book PDF).

Included in Termite are continuations that can support distributed process migration and macros. Continuations, macros, and closures allow Termite to be more amenable to discovering new abstractions than Erlang.

Termite is from the Gambit team at University of Montreal and runs on Gambit 4.

ATOM or WebDAV: The Rest of the Story?

I do not have a deep understanding of either ATOM or WebDAV but on the surface they seem to overlap in their publishing capabilities. ATOM's does not extend HTTP but WebDAV's does. On the other hand ATOM uses some less well-supported HTTP verbs anyway, so does this point matter?

The ATOM publishing protocol is generating a lot of enthusiasm, even saving us from the WS-xxx. So are these two protocols distinct? When would one be preferred over the other?

What about content-specific issues, like calendars. CalDAV extends WebDAV. Does ATOM have enough not to be extended like this? Should WebDAV be extended like this?

Friday, July 15, 2005

Concurrency Bragging Rights

Wes Moise writes about upcoming advances in concurrency in C# and Java. He sees C# as making the bigger leap into the state of the art.

It’s safe to say that Microsoft will be addressing this issue soon, and probably will be leading the way. As for Sun, Java 5 introduces some concurrency features such as AtomicInteger types, ReentrantLocks, lock-free data structures, but it’s not fundamentally different from concepts that originated in the 60s.

The smart minds at Microsoft Research have been focused on a new concurrency constructs in COmega based on join calculus.

On the other hand many years ago I was using Doug Lea's wonderful util.concurrent package. This has become "standard" now as java.util.concurrent.

The real problem is C# and Java are still languages from the middle of the pack of "the 60s" languages (e.g. Concurrent Pascal). Languages from the best of "the 60s" like Lisp and Smalltalk, have not had to change much and are able to move into new concurrency models with much less baggage.

I am not sure I would hold either C# or Java on a pedestal for the coming paradigm of concurrent programming. Eeek. Termites!

Middling Around the Real Problem

Update: See the comments.

The paper by Meijer and Drayton is making the rounds. As long as Microsoft supports the popular "dynamic" languages I don't care much what other languages they support.

Since the paper is a work in progress and they admit to being provocative, I may as well comment...

First of all I would note that the term "test" does not show up anywhere in the paper. This is a bit of a shock for a paper whose opening sentence is...

Advocates of static typing argue that the advantages of static typing include earlier detection of programming mistakes.
Moving on to a few unsubstantiated claims...
data intensive applications need to deal seamlessly with several degrees of typedness
I did not see a definition of "data intensive" nor did I see evidence of what this "need" is.
not inferring the types of these variables whenever possible is literally throwing the baby with the bath water
Everything has a cost/benefit ratio, which informs the answer to "whenever possible". I could not find a description of this ratio in spite of that being the topic of the paper.
in general programmers want to express more advanced contracts about their code
Yes, but the question is how, and at what cost. Testing, even model checking, could be brought into this discussion. The benefits of the specific proposals in the paper are not clearly proposed.
The compiler should verify as much of a contract... as it can
More of the same... "as much as possible", "as much as it can"... the problem is the paper should propose some eveluationc criteria otherwise it is your word against mine. I will go with my word every time in that case.
Perhaps the most useful example [of coercive typing] is "auto-boxing" from value types to reference types
If that's the best example then... ahem. One could simply choose a language that does not even have such things that contribute nothing to the real problem.
the compiler can automatically "lift" addition on normal integers to addition on nullable integers
One could simply choose a language that does not even have such things that contribute nothing to the real problem.
[generics make it] possible to create highly reusable languages, while maintaining the benefits of compile-time type checking
Those benefits have a cost. The point is people disagree on the accounting of the cost/benifit ratios. The paper does not propose an accounting that can be examined.
I want lazy evaluation... the power of the Unix shell lies in the fact that programs consume and produce lazy streams
Agreed. But this has nothing to do with type checking. Maybe this would make a better paper than one on type checking for many readers.

Overall the paper has some ideas on how typical type checkers for C# and Java can be improved. That these checking approaches would be better than "dynamic" languages seems to be an assumption the authors chose not to question. Too bad, I thought that was the point. I don't see many people arguing to stick with the poor checking done currently by C# and Java.

T Revival

I am not sure how much this matters today, but the T Project from Yale is being revived. T is a dialect of Scheme whose optimizing compiler was a fascinating piece of work 10 years ago and influenced subsequent work on compilation via continuations.

Jonathan Rees has more interesting T background from the insider's view.

T ran on Apollo workstations among other systems. I used them at Mentor Graphics until Gambit Scheme came along.

Emacs: The Extensible, Customizable Display Editor

I had used Emacs for a couple of years or so when I came across this paper in a book on programming environments. This inspired a lot of my subsequent software design in several domains far from text editing.

Another Radically Tailorable Resource

Avi adopted the phrase "radically tailorable". Great. I like that phrase quite a bit.

Here's another reference that has influenced my thinking long before this post. This should also be in the Lieberary, but some links seem broken.

This paper presents a kit called EZWin, which provides many services common to implementing a wide variety of interfaces, described as generalized editors for sets of graphical objects. An individual application is programmed simply by creating objects to represent the interface itself, each kind of graphical object, and each command. A unique interaction style is established which is insensitive to whether commands are chosen before or after their arguments.

The system anticipates the types of arguments needed by commands, preventing selection mistakes which are a common source of frustrating errors. Displayed objects are made "mouse-sensitive" only if selection of the object is appropriate in the current context. The implementation of a graphical interface for a computer network simulation is described to illustrate how EZWin works.

Friday, June 24, 2005

Longhorn and RSS???

This violates all sense of design. Is this their latest attempt to make a "new OS" compelling? What would a sensible developer think about "putting RSS into Linux"? What could that possibly mean that was advantageous to *anyone*???

Friday, June 03, 2005

Programming RSS and Atom

Here is at least one more blog reference to Danny Ayer's book. (re: This first reference.)

I just got it recently and so far so good. A variety of topics and apparently useful core information.

Another good book seems to be Developing Feeds with RSS and Atom, by Ben Hammersley. That one seems to stay more to the core though I've barely cracked either of them.

At least two more with similarly sounding titles are on their way.

Thursday, June 02, 2005

"In XML format" ==> Still not enough information

Update: Brian Jones has a blog with more information. Not a whole lot more yet, but more. For example the default stroage will be zipped XML. The XML will be "fully documented". A royalty-free license is mentioned with no hints as to what it provides. However on their press site comes this encourage news...

PressPass: Won't this make it easier for your competitors to copy Microsoft Office?

Sinofsky: Certainly this will make it easier for other developers to use our formats to build solutions that don't require Office. However, the ability of other technology providers to use the new file format to integrate their solutions with the Microsoft Office System is an important and frequently requested capability by the industry. We feel it's to everyone's advantage to respond. Customers also know that the true value of a desktop application is not the format in which data is stored but the full breadth of capabilities offered by that application, along with the quality and security of the user experience that it provides.

So now I mainly wonder a few things...
  • Hopefully "fully documented" means what you would hope it means.
  • Hopefully "other technology providers to use the new file format to integrate" means what you hope it would mean.
  • Hopefully, since they apparently will not support Open Document format, "integration" is as easy as you would hope it would be.
Hopefully. End Update

What does it mean these days to anyone knowledgeable enough to care to say that you store your data "in XML format" without saying anything meaningful about what that format actually is.

My interpretation of this contentless "news" about content is that it serves as FUD given the recent ballyhoo about OASIS and the Open Document format. I have seen no other meaningful information to suggest an alternative explanation.

Unwittingly the typical customer says, "Why switch to another office suite when Microsoft is also publishing 'in XML format'".

Eek

A tag line found on Danny Ayers blog...

Tags: hReview, microformats, microformat, rdf

Is there something concerning about this?

Not Scheming

Mark Baker suggests about web description languages...

I generally think it's a bad idea to describe the data produced using a schema since schemas generally (DaveO's excellent extensibility advice notwithstanding) change foreseeably over time, and I don't want a change in the schema produced by a service breaking clients if I can help it. Instead, I'm more a fan of simply using a media type as a name for an open-ended sequence of backwards-compatible schemas (think "text/html" vs. HTML 2.0, 3.2, 4.01, etc..), as well as, of course, associating an extensible processing model to that media type to accomodate as many unanticipated extensions as possible over time.

These monkeys...

...wannabe something else.

But they're not.

Dance, monkeys, dance.

Tuesday, May 31, 2005

Good Point

Chris Sells makes a, er, "point"...

The thing that I really need that I'm missing is for my computer, and everyone's computer that I'm conferencing with, to have a stylus attached to their screen. The "let's just sketch something on the white board" is really the last remote collaboration frontier 'til we get some kind of fancy "virtual presence" stuff going.

I don't mean that every computer needs to be a Tablet PC. Frankly, I'm not very productive on a computer that doesn't have a keyboard. But, I want to be able to sketch something right on my computer screen like a tablet can and instantly share it as I do so. Plus, and here's the rub, I want everyone else to have a stylus, too. If they don't, they'll turn to the white board and I'm out of luck across the great divide.

Good point. A freehand drawing and handwriting surface should "just be" part of the standard desktop.

In the Loops

Martin Fowler looks for a rigoruous definition of "agile" software development practices, and measurements of which practices may be more effective than others.

...agile methods fundamentally expect teams to decide what process to follow and furthermore expect teams to actively and regularly change their process. Any attempt to define a rigorous process that can be tested for conformance runs contrary to this philosophy...

How can you do a survey on whether agile methods are more effective that alternatives, or whether Extreme Programming is more effective than Scrum, when you can't get a clear definition of what Scrum is in the first place? If a client wants a system built using Extreme Programming how can they tell if it's really being done?

The first part of the quote above *is* the definition of agile in my experience: if the team decides what to follow and actively improves their performance then they are "being agile". The second part of the quote becomes less interesting in this case.

Comparing textbook definitions to each other is less interesting than comparing an agile team to its own history. If the team is improving then that's the goal.

A useful excercise for a team when considering their own agility is for them to explicitly describe their feedback loops (plural), who should be in their loops for which information, and how are decisions (and their timing) made in each of these loops.

(Hint: many problems in an organization of any size occur, and are therefore obscured, outside the boundaries or on the border of the "team" per se.)

Using this approach Scrum, XP, and other approaches become possible sources of improvement and less a necessarily well-defined instruction manual that can be graded independent of actual performance.

Friday, May 27, 2005

And the Sith Came Tumbling Down

James Robertson defeats the Dark Side with one simple observation...

The characters made stupid choices again and again. Not to mention the improbability surrounding the central fear point of the movie, that Padme would die in childbirth. Apparently, hyperdrive is one thing in the Star Wars galaxy, but knowledge of C-Sections - nope.
Anakin's response: "Oh. Yeah. Good idea."

Monday, May 23, 2005

Still Crazy After All These Years

Via the Utne Reader...

This week Halliburton holds its annual shareholders meeting at the Four Seasons Hotel in Houston. Attendees will toast a whopping 25 percent overall revenue growth thanks to recent work in Iraq. Others will gather outside the swank hotel to protest corporate-cronyism and war-profiteering.
Accountability? America needs you, Harry Truman

SAP, Python, and Passion

Yet?

"Open-source technologies such as Python and PHP, to name just two, are of great interest to college students and younger people with a passion," according to Shai Agassi of SAP's Executive Board. But he doesn't believe there is yet the same enthusiasm for ERP (Enterprise Resource Planning) applications.
Evidence the long-tail may be gaining mind share over the SOA?

Orange Billion Dollars

A.F. reports...

Maher followed by asking Coleman if it struck him as odd that there haven’t been any terror alerts since the election?

After a long laugh from the audience, Coleman answered with some stuff about there still being a high level alert, but then reassured everybody with: "If in fact people used these things for political purposes, I’m sure Congress will look into that."...

Meanwhile, the Coalition Provisional Authority, which we ran, has lost 8.8 billion dollars. By lost, I mean it’s totally unaccounted for. Not only has Congress not "looked into" this $8.8 billion and who might have it now, but it seems that some members are completely unaware that this staggering sum, which was supposed to go toward rebuilding Iraq, is missing. The Sunday morning after the White House Correspondents dinner, I ran into Senator George Allen at a brunch thrown by John McLaughlin and his wife. Allen had never heard of the missing $8.8 billion, or at least that's what he told me. And he's on the Senate Foreign Relations Committee.

Stunned, I went up to Susan Page of USA Today and her husband Carl Lubsdorf of the Dallas Morning News, two veteran Washington political reporters, and told them about Allen’s ignorance of this huge scandal, which has no doubt contributed to hatred for America and the deaths of our troops. There’s less electricity in Iraq now than there was before we invaded Iraq.

Turns out that Page and Lubsdorf had also never heard of the unaccounted-for $8.8 billion. For a moment I thought that maybe I had been imagining things.

Then I spotted my friend Norm Ornstein, scholar from the American Enterprise Institute. "Would you believe it if Norm Ornstein told you about the $8.8 billion?" I asked Susan and Carl.

"Sure."

I brought Norm over, and indeed I had not been imagining things. "It was a huge story," Norm told them.

"Was it in the New York Times?" Carl asked Norm.

"Yes," Norm assured him.

Five Percent

Howard Dean on the Senate...

One of the great geniuses of American democracy, unlike most of the democracies in the world that minority rights are protected, 48 percent of us didn't vote for President Bush, but we still have some say in shaping the agenda of the country. If the filibuster is gotten rid of, the extended debate is gotten rid of in the Senate, first of all, it means the president can put 10 judges on the bench that we believe are not qualified to serve. We've confirmed 205 of his judges. He wants those last 10, so they're willing to change the rules to do it.

But it has much worse implications.

Touch Enough

A.H. observes Tim Russert "interviewing" Howard Dean. As a counterpoint to my last post, what happens when a Democrat does try to really talk about the war in a national forum...

The key exchange came when Dean raised the most critical point about Iraq:

DEAN: Because of the president’s actions, I would argue that we are in greater danger now because of what’s going on in Iraq than we were before. Now there are terrorists in Iraq. They have migrated there since our troops were there.

RUSSERT: Let me stay on your rhetoric…

Nice pivot, Tim. Yes, by all means, let’s stay on Dean’s rhetoric rather than on the insignificant fact that our country is less safe as a result of our invasion of Iraq. Good to see you’ve got your priorities in order.

Another reason why I don't watch "major" news networks.

As I write this one of the best programs for real news and interviews... Democracy Now is on my TV, on a local community cable channel from 5am to 6am M-F. But you can watch it on the Internet too.

Slip Sliding Away

James Boyce writes...

The fact that thousands of young men and women are coming home disabled for life and learning to live on $2,000 a month disability is a disgrace. The future security of our country is at stake because, as an Army recruiter was explaining on a talk show the other night, this is the first “real” extended war the volunteer army has had to fight, and recruiting to actually fight is different than recruiting to train to fight...

I spoke with a top Democratic fundraiser, smart guy, best of the best, and I quote: “The Democratic consultants here in Washington are convinced that the 2008 election will be all about domestic issues.” Sure it will be. Just like the last one was.

Friday, May 20, 2005

POO

Joe Gregorio (BitWorking) smells a missed opportunity...

Personally I think he missed a great opportunity to name it Post Only Once.

Ballmeristic

Steve Ballmer of Microsoft sez of RSS (which one?)...

It is a little too simple, that is also the reason everyone’s using it. We are working on more existing powerful stuff, around XML/web services [sic] that will address many issues beyond RSS. RSS will be around, but whatever we are working next will be cooler and more prevelant.
(via James Robertson)

Thursday, May 19, 2005

muf

Eric Meyer writes...

What’s fascinating is how fired up people get about microformats.
I'm kind of fired up.

Wednesday, May 18, 2005

More Data

IEEE Computer May 5, 2005 Beyond the Relational Database Model David M. Kroenke, University of Washington Former VP of Development at Microrim (R:Base 5000) pp. 89-90

During the next hour or so, I walked her through the process of creating five normalized tables - Customer, Salesperson, Invoice, Line Item, and Item - and hooking them together with foreign keys. Then I explained how to rejoin them to get her sales order back. Long into the call, she asked, "Why am I doing this?"...

After 35 years of computer science and numerous iterations of Moore's 18-month cycles, isn't there a better way?

Data

Communications of the ACM
Volume 48, Number 5 (2005), Pages 111-118
The Lowell database research self-assessment

It is time to stop grafting new constructs onto the traditional architecture of the past. Instead, we should rethink basic DBMS architecture with an eye toward supporting:

  • Structured data;
  • Text, space, time, image, and multimedia data;
  • Procedural data; that is, data types and the methods that encapsulate them;
  • Triggers; and
  • Data streams and queues
as co-equal first-class components within the DBMS architecture—both its interface and its implementation—rather than as afterthoughts grafted onto a relational core...

Many new applications that use DBMSs are going to require unattended operation. In addition to no-knobs tuning, the DBMS must be able to recognize internal malfunctions and malfunctions of communicating components, identify data corruption, detect application failures, and do something about them. Such capabilities require making the DBMS more self-aware and providing it with explicit models of the information system in which it participates...

A small number of slick visualization systems oriented toward information presentation were proposed during the 1980s, notably QBE and VisiCalc. There have not been comparable advances in the last 15 years, and there is a substantial need for better ideas in this area.

Thirty years of research on query languages can be summarized by "we have moved from SQL to XQuery."

First, the database research community should avoid drawing too narrow a box around what we do. We must explore opportunities for combining database and related technologies that can improve the usage of information, such as information visualization technologies, which has often been left to the domain of other research communities. To broaden the set of technologies database researchers apply, they need to expand their breadth of competencies. Consider the plasterers' union, which decided many years ago, when wallboard was being introduced, that it was not their competency. As plaster was replaced by wallboard, the union lost out. This fate could befall the DBMS community if it does not respond to the new challenges of integrating related technologies with information management.

Second, it was noted that the average age of participants at these meetings has been increasing. On the other hand, there are more young database researchers than ever before, as evidenced by the large number of junior faculty in databases. We recommend the next meeting invite a broader mix of age groups within our community.

Coordination vs. Command and Control

From Vanessa Williams we get...

For my taste, Web Services and SOA architecture puts too much emphasis on centralized orchestration and not enough on self-organized, coordinated behaviour in large open systems.

No Regrets

Update: See my response to the comments if you're interested.

I have no regrets having dropped Newsweek about a year ago, what with the Bush administration CBS'ing them and Newsweek having no more backbone than the other "mainstream" corporate media so-called "news" agencies.

For their good behavior, I'm giving Newsweek and its owner, the Washington Post, this week's Yellow Streak Award for Craven Cowardice in Journalism.

As always, the competition is fierce, but Newsweek takes the honors by backing down on Mike Isakoff's exposé of cruelity, racism and just plain bone-headed incompetence by the US military at the Guantanamo prison camp.

Isakoff cited a reliable source that among the neat little "interrogation" techniques used to break down Muslim prisoners was putting a copy of the Koran into a toilet.

In the old days, Isakoff's discovery would have led to Congressional investigations of the perpetrators of such official offence. The Koran-flushers would have been flushed from the military, panels would have been impaneled and Isakoff would have collected his Pulitzer.

No more. Instead of nailing the wrong-doers, the Bush Administration went after the guy who reported the crime, Isakoff...

Have some sympathy for Isakoff: Mike's one darn good reporter, but as an inmate at the Post/Newsweek facilities, his ability to send out serious communications to the rest of the world are limited.

A few years ago, while I was tracking the influence of the power industry on Washington, Isakoff gave me some hard, hot stuff on Bill Clinton -- not the cheap intern-under-the-desk gossip -- but an FBI report for me to publish in the Guardian in England.

I asked Isakoff why he didn't put it in Newsweek or in the Post.

He said, when it comes to issues of substance, "No one gives a shit" -- not the readers, and especially not the editors who assume that their US target audience is small-minded, ignorant and wants to stay that way.

That doesn't leave a lot of time, money or courage for real reporting. And woe to those who practice real journalism. As with CBS's retraction of Dan Rather's report on Bush's draft-dodging, Newsweek's diving to the mat on Guantanamo acts as a warning to all journalists who step out of line.

Newsweek has now publicly committed to having its reports vetted by Rumsfeld's Defense Department before publication. Why not just print Rumsfeld's press releases and eliminate the middleman, the reporter?

The term "pussy whipped" comes to mind.

Delicious

A.H. wonders...

Wouldn’t it be delicious if the female orgasm were the thing that tips the scales in favor of the Intelligent Design crowd? It would make for a great closing argument: "The female orgasm is so complex and strange, it could only have come from God. The reason there is no evolutionary purpose to it is because there is no evolution! God is in the details... and the bedroom. Who needs Darwin when you have the Bible -- and the Jack Rabbit (grown ups only). Case closed. Amen."

Big Ice

Live Science, via Yahoo News...

If B-15A gets stuck, as it has before, researchers fear it could block sea ice behind it, thwarting animals that need to move from shore to the open sea.

B-15A is the largest chunk left of a bigger iceberg, known as B-15, that broke off the Ross Ice Shelf in March 2000. That initial frozen hunk was about the size of Jamaica. After B-15 broke apart, the chunk named B-15A drifted into McMurdo Sound, where it blocked ocean currents and caused other sea ice to build up, threatening wildlife.

Scientists predicted an imminent collision back in January this year. Instead, the iceberg ran aground and stalled out. Then it broke free in March. On the move again, it collided with the Drygalski ice tongue in April, forcing the redraw of Antarctica maps.

Tuesday, May 17, 2005

Missing More Boats?

Chris Anderson has been exploring Python and states...

I've really come to the conclusion that Microsoft is missing the boat around dynamic languages and scripting in general.
Agreed. And yet...
I think that scripting and many dynamic languages are in the same camp. They are great for small applications and writing glue code. Look at Google Maps, the real processing is on the server...

Regardless of the limitations, our singular focus on strongly typed compiled languages has blinded us to the amazing productivity and approachability of dynamic scripting langauges like Python and Ruby.

Python and Ruby are fine languages. Miles ahead of most others. They work well in many situations.

Remember their most common implementations are relatively simple. Don't use them as the benchmark of where the performance can really go, and has been for some time, e.g. in Smalltalk, Common Lisp, and Scheme where more attention has been paid to efficient implementations.

Microsoft will be missing a huge opportunity if they settle for current Python and Ruby performance as their "scripting" language par. The first step toward this new consciousness would be to stop using the term "scripting". Call them "dynamic" or "agile" or something that does not connote just slow "glue".

Check out JP Morgan's KAPITAL system in Smalltalk. This is the engine, not the glue. Don't miss the boat.

Decidedly Unwiki-like

Jotspot is about as cool as it gets. But when you are dealing with stuff like this can it fairly be called a wiki?

<wiki:search forAll="true" filter="it/ActualTimeForm/iteration=args/iteration" />
<wiki:var var="totalSpent" value="${0}" />
<wiki:var var="totalRemaining" value="${0}" />
<wiki:loop>
  <wiki:var key="ms" value="${it/ActualTimeForm/timeSpent/milliseconds}" />
  <wiki:var key="totalSpent" value="${totalSpent + ms}" />
  <wiki:var key="ms" value="${it/ActualTimeForm/timeRemaining/milliseconds}" />
  <wiki:var key="totalRemaining" value="${totalRemaining + ms}" />
</wiki:loop>
<wiki:var key="percent" value="${round(totalSpent div (totalSpent + totalRemaining) * 100)}%" />
@chart
<div style="width:100%; border: 1px solid black; padding:0px; background-color:red">
  <div style="background: green; width: ${percent}; margin: 0px;text-align: center; color: #ddd">
  ${percent}
  </div>
</div>
@chart

Accounting for the Long Tail

The Accounts framework and other Adaptive Object Models provide more support for long-tail notions in software...

A system with an Adaptive Object-Model has an explicit object model that it interprets at run-time. If you change the object model, the system changes its behavior. For example, a lot of workflow systems have an Adaptive Object-Model. Objects have states and respond to events by changing state. The Adaptive Object-Model defines the objects, their states, the events, and the conditions under which an object changes state. Suitably privileged people can change this object model "without programming". Or are they programming after all? Business rules can be stored in an Adaptive Object-Model that makes it easy to evolve the way a company does their business.
And then [micro-]workflow. (But the site was having trouble today)

Experiments with OVAL

Tom Malone, et al. of MIT Sloan School addressed the long-tail of software some time ago (throughout the 1980's and then some). Their work resulted in more than a handful of useful papers and several generations of useful software written in a few dialects of Lisp (ultimately Macintosh Common Lisp). I wonder what happened to the software.

Demonstrating the range of software that could be addressed with little effort, one of the most ignored reports of all time in software has to be "Experiments with OVAL"...

This paper describes a series of tests of the generality of a "radically tailorable" tool for cooperative work. Users of this system can create applications by combining and modifying four kinds of building blocks: objects, views, agents, and links. We found that user-level tailoring of these primitives can provide most of the functionality found in well-known cooperative work systems such as gIBIS, Coordinator, Lotus Notes, and Information Lens. These primitives, therefore, appear to provide an elementary "tailoring language" out of which a wide variety of integrated information management and collaboration applications can be constructed by end users.
"Objects" in OVAL are essentially just like "objects" in JSON, i.e. they are name/value pairs. The main difference is there is a templating mechanism and one can inherit from another. There are no "methods" associated with objects, but rule-based actions are based on "duck typing", in this case the names and values an object has.

Monday, May 16, 2005

Content and Presentation

Sean McGrath raises the fuzzy boundary between content and presentation. My thoughts on the matter...

The concern about content vs. presentation is based in code maintenance. The model-view-controller design allows the model and the view to change independently (controller has remained a bit of a bear).

This separation is less of a concern on the web, although adapting content to multiple presentations is more than desirable. For example, "micro-formats" that embed content within HTML (which is perhaps 'semi-presentational'?) such that CSS can style based on more content-specific content than HTML itself, and such that automated systems can ignore the presentation and drive actions based on the content.

Supposedly the automated systems should care less if the presentation aspects of the format changes and vice versa. Agile data formats and processors should have less to do with a content/presentation dichotomy, and have more to do with semi-structured data, i.e. whether or not the document has enough information of the expected kind to do useful work.

Not Elegant?

Dynamic ("scripting" in this article) languages continue to gain more attention. Play along at home. Spot the misconceptions...

"Scripting (languages are) just getting more popular and powerful simply because they're easy to use," said Tim Huckaby, CEO of consulting firm and Microsoft partner InterKnowlogy. "It's all about time to market and money, not about how elegant it is underneath."

Another XP Code Sprint

Another Portland code sprint will be held at Free Geek on May 25-26 from 6:30pm each evening. Free Geek has some of their own compute power available if you don't want to mess with your own.

Jeff Freyley, one of the organizers, writes...

This will be a language neutral Sprint, so remember: language wars can only be settled by tree-climbing contests at midnight, not by words.

Wednesday, May 11, 2005

Jython Integers

Moving Python and other dynamic languages to the popular rigid virtual machines should preserve Python behavior while providing access to the host language and platform capabilities.

When I used Jython a couple years ago I guess I did not stress this behavior. And so today I am a bit surprised to see the following in Jython 2.1...

>>> java.lang.Integer.MAX_VALUE
2147483647
>>> n = java.lang.Integer.MAX_VALUE
>>> n
2147483647
>>> n.__class__

>>> n + 1
Traceback (innermost last):
  File "", line 1, in ?
OverflowError: integer addition: 2147483647 + 1
>>>
Comments

It is a correct behavior. Try evaluating "sys.maxint + 1" on CPython 2.1...

If you do "sys.maxint + 1L", (note "L") it works both on CPython 2.1 and Jython 2.1.

End Comments

OK. So the goal becomes getting Jython up to 2.4 or at least the version past CPython 2.1 where both sys.maxint + 1L and sys.maxint + 1 do the (same) right thing.

Thanks

The Age of the Dynamic

Update: It looks like IronPython could become a preferred approach to programming Avalon.

I define a new type in python, with *no properties*. I then dynamically assign anything to the objects with the name "name" and "value"... everything else is Avalon + Python goodness... oh yeah!
What's that buzz I hear?

End Update

Dynamic languages continue their dance with the Big Boyz.

All in due time. All in due time.

Information Overlord?

Philip Greenspun on Longhorn and file systems in general...

The average household user of a personal computer doesn't need anything with many more features than the Palm OS or Microsoft Outlook and probably has far fewer megabytes of documents than he or she has of archived email.
Information overlord?

Empirical Evidence And Analytical Reasoning

Bob Martin writes about the interplay of test-driven development and analytical reasoning.

Techniques such as TDD are valuable empirical techniques that can create the dots; but you need reasoned analysis to connect those dots. A suite of tests shows you that a program behaves as expected for discrete situations. Analytical reasoning tells you how you can generalize those situations.

AJAX

On the Ajaxian blog...

Google is the science fair of Ajax.

Live Action

James Roberston...

The nice thing is that I could experiment on live data in a running application. Here's a screenshot of the resulting inspector...

Tuesday, May 10, 2005

Navigation in Avalon

Ed Kaim writes about Avalon...

If you look at how the Web works, it's a "Web" because of the way you can hop from one site to another and criss-cross your way from anywhere to anywhere else. The integration isn't complex--it's basically HREFs, POSTs, and GETs. What these enable, however, is a way to write large systems to address business needs in such a way that they are really a set of smaller building block applications that can be glued together (often dynamically).

In contrast, Windows client programming today (Win32, .NET, J2SE, whatever) has a programming model that is much less conducive to integration... While there are tons of sexy features coming in Avalon, my money is on navigation as the single most important feature.

Monday, May 09, 2005

Greasemonkey and the Treaty of Orlando

Babak Nivi suggests...

Greasemonkey is to websites what inheritance is to objects in object-oriented programming.
But of course this is not correct. 8^)

As per Henry Liberman, this is clearly a delegation-based approach using web sites as prototypes.

(via Sam Ruby)

Impeachment Time

Greg Palast, former columnist for Britain's Guardian papers, author of the New York Times bestseller, The Best Democracy Money Can Buy, writes...

Now sharp readers may note they didn't see this memo, in fact, printed in the New York Times. It wasn't. Rather, it was splashed across the front pages of the Times of LONDON on Monday.

But in the US, barely a word. The New York Times covers this hard evidence of Bush's fabrication of a casus belli as some "British" elections story. Apparently, our President's fraud isn't "news fit to print."

The Republicans impeached Bill Clinton over his cigar and Monica's affections. And the US media could print nothing else.

Now, we have the stone, cold evidence of bending intelligence to sell us on death by the thousands, and neither a Republican Congress nor what is laughably called US journalism thought it worth a second look.

My friend Daniel Ellsberg once said that what's good about the American people is that you have to lie to them. What's bad about Americans is that it's so easy to do.

Sunday, May 08, 2005

Trouble Ahead

...or below, depending on the metaphor.

Warren Buffett and Charles Munger, via Philip Greenspun...

Some people seem to think there's no trouble... just because it hasn't happened yet. If you jump out the window at the 42nd floor and you're still doing fine as you pass the 27th floor, that doesn't mean you don't have a serious problem.

Thursday, May 05, 2005

SOA vs. the Long Tail

Phil Windley on SOA.

Knowing about the financials process in some detail, I can attest that spreadsheets are involved in all aspects from forecasting to closing the books. Even when enterprise software is applied, there is a good bit of export to Excel, do the work, import to the enterprise systems.

Now, tie this in with recent efforts like Jotspot, Smallthought, and 37Signals, et al. where they are trying to address that "long tail" of software in a better way than Excel, Access, etc. (Note: in some cases incorporating Excel. Side note: all three of these efforts have embraced dynamic languages.)

This is where the big enterprise companies like SAP, Peoplesoft, etc. could focus some attention. Those of us working with these enterprise systems spend a lot of time at the interfaces of those systems with the rest of the enterprise. They do not support the "long tail" that exists within the enterprise, and moving to J2EE, Indigo, SOA, "portals", etc. is not addressing the *real* problem either.

We don't need a high-tech SOA as much as we need better "long tail" support. SOA is more for geeks than for enterprises. The enterprise vendor that figures out how to make SOA just a bunch of uninteresting plumbing underneath really good "long tail" support could end up a *big* winner.

Tuesday, May 03, 2005

Announcing json-py

Updates from the comments:

Ian Bicking suggests doctest would be more appropriate than unittest. I would have to agree, if I were enough of a Python programmer to know to use doctest. Each unit test is a couple of lines long, so I should move them to doctests with little trouble.

Eric Thompson wonders about support for tuples. The JSON array syntax looks like Python's list syntax, so I chose read to produce lists. JSON only has "objects" (dictionaries) and "arrays" (could be lists or tuples) for data structures. The write function could accept either lists or tuples and produce JSON arrays. Currently only lists are implemented. I'm open to suggestions.

End Update

I wrote a JSON reader and writer in Python over the last few days. Today sourceforge approved and created the project, and the files are ready for download.

It's "pure" Python 2.4 and has no other dependencies. Most of JSON is implemented, which is not much, coming in at about 200 LOC. The missing piece is the \uXXXX notation for hex Unicode characters. There's probably some missing functionality in the writer, e.g. writing escaped characters correctly, because I've mostly needed the reader so far.

There's one other Python implementation I know of and I think this new one is a good bit more correct and complete. There are 40 some unit tests, just enough to get my needs met. They do not exhaustively stress the specification yet.

There are several implementations in other languages. JSON can be used in AJAX-based systems in lieu of XML. In my case I've been using JSON for simple, yet expressive, configuration files. (I had set out to use YAML. Although simpler than XML it is still a good bit more complex than JSON.)

[Update: Jeremy Kemper points out in a comment that JSON is a subset of YAML. I think it is a sweet spot.]
Not as feature-rich as XML, I think the intent is to keep JSON per se as simple as it is, and layer conventions using JSON itself to represent more complex information (datetime, location, customer, etc.) and "metadata" (version, author, etc.). Don't let the "O" in JSON throw you. An "Object" in JSON is simply a dictionary in Python (and Map in Java), i.e. a set of name/value pairs.

https://sourceforge.net/projects/json-py

The Architecture of the Mobius Strip

Phil Windley and Don Box are wondering about levels of indirection. But are "levels" the best metaphor for where we are in networking today?

"the costs and benefits of indirection layers are well understood"
Generally I agree we can say there are costs *and* benefits, and we know what to look for in terms of "coupling loosely" and measuring impacts.

But in this case is SOAP *another* level of indirection vs. HTTP or just an *alternate* level of indirection? i.e. should we perhaps expect HTTP in more places than we have it today if we look at HTTP as an application protocol rather than a transport protocol?

For example, consider the Java peer-to-peer sockets project. Any application protocol implemented using sockets can run on some peer-to-peer topology. We seem to be in a world that is more like a mobius strip than the expected seven-layer model!

Is HTTP itself a level of indirection, and is it sufficent for machine-machine coordination on the web? If so, then the cost of SOAP (and so some or all of WS-*) as another level of indirection may have a cost that is too high, actually unnecessary.

Monday, May 02, 2005

More Evidence of Sanity in the World

Spain: Gay Marriage Will Soon Be Authorized
Le Nouvel Observateur

Wednesday 21 April 2005

The Congress has adopted a proposed law authorizing marriage between persons of the same sex as well as adoption. Senators are also expected to give their approval. It is anticipated that the law will be implemented this summer.

Symposium on Dynamic Languages

In conjunction with OOPSLA...

ACM Symposium on Dynamic Languages
October 18, 2005, San Diego, California

The goal of this symposium is to provide a highly visible, international forum for researchers working on dynamic features and languages. We explicitly invite submissions from all kinds of paradigms (object-oriented, functional, logic, ...), as can be seen from the structure of the program committee.

More steam.

Angles

Ryan Dawson ponders Tiger and Longhorn...

Business is consistently coded in angle brackets--where platforms don't matter... we need people who find the real problems... How many times have you read the Clue Train Manifesto?

AJAX + CANVAS = Good enough?

Apparently Mozilla (and so Firefox) are getting the element (similar to Safari) and adopted by WHATWG (and so Opera). Whence IE?

(Via Sam Ruby)

Sunday, May 01, 2005

Web Algebra

Murray Spork writes in a comment on Bill de hÓra's blog...

I've been saying for a while now that what the Semantic Web needs is more algebra and less logic. - for example the "additive" and "subtractive" qualities of RDF that Bill talks about.

Saturday, April 30, 2005

Who I Should Vote For

Who Should You Vote For?

Who should I vote for in Wales?

Your expected outcome:

Green


Your actual outcome:



Labour 5
Conservative -19
Liberal Democrat 49
UKIP 5
Green 75
Plaid Cymru 45


You should vote: Green

The Green Party, which is of course strong on environmental issues, takes a strong position on welfare issues, but was firmly against the war in Iraq. Other key concerns are cannabis, where the party takes a liberal line, and foxhunting, which unsurprisingly the Greens are firmly against. The Greens are also anti-Europe.

Take the test at Who Should You Vote For

Friday, April 29, 2005

Moore's Law

Rich Karlgaard writes in Forbes...

Don Valentine founded Sequoia Capital in 1972 and presided over early investments in Apple, Electronic Arts, Cisco, Yahoo and Google. He once told me the secret to his success: "That's easy. I just follow Moore's Law and make a few guesses about its consequences."
(via Phil Windley)

Too Many "Services"?

Phil Windley wonders...

I'm just not clear on why a simple URL isn't good enough.

Thom Hartmann

Thom Hartmann is now on the air locally in Portland, 6-9am, KPOJ 620 AM, in addition to his national show. Both shows have Internet streams and archives.

XPDX Sprint

I have been out of my office for all but a few days the last four weeks. Somewhere in the middle of that was the XPDX Sprint here in Portland. I was able to attend the first day. Sunday I had to cart a couple of young non-driving men to a couple of malls around town so they could conduct high school psychology experiments.

Catching up on the sprint... I missed the subsequent Tuesday night meeting where a retrospective was conducted. The notes are not making too much sense to me yet.

Here're my recollections from the Saturday... I was in California the week before and back in Oregon about 12 hours, mostly sleeping, before heading downtown to the sprint.

My initial pair was a nice, short, sweet task... we found the source of a core Python bug on Windows that had to do with marshalling and unmarshalling a foating point NaN, in this case an INF. The problem was in the C code though and we had no convenient way to build for windows. Neither did we know what behavior the Python community would want. My partner brought the problem to the sprint so he is going to follow up with the Python email list.

Another group had already split off to work the rest of the day, and the better part of Sunday as far as I know, on Line of Sight Chess. This is now a sourceforge project. LOSC was run as a mini-XP team with planning, iterations, multiple pairs, etc. It looked like fun when I dropped in on them.

Back in the other room we kind of moved around different ideas that never completely gel'd as projects. Several of us spent time getting MoinMoin installed on Windows (and Cygwin for me). Then we set about exploring how MoinMoin actions, macros, etc. work. We noticed funkiness about MM picking up changes vs. going to its cache, so a couple other folks split off and made a good start at fixing that problem when in development mode. The fix broke some other things, and one big problem was just not having the expertise around to keep us moving quickly. Our afternoon was more of a exploratory spike than a planned iteration.

Along the way several of us spent a half hour or so playing with Seaside and had fun conversations about Wiki's, AJAX, continuations, Smalltalk, Scheme, CL, and dynamic languages in general.

I thought the idea of the sprint was sound and the day was fun. For an XP focus I would want to participate more in a session like the LOSC team. Other than my initial pair the rest of the day had little to do with XP.

Oh, we were located right across the street from Good Dog, Bad Dog so lunch was tasty as we gathered outside at Pioneer Courthouse Square.

World-Wide Semi-Structured Data

Some thoughts on Bill's post:

1. It's funny that AI is disparaged in the world of the fuzzy. I am not so familiar with description logic. What little AI I did was with frame-based languages (Carnegie Representation Language, KnowledgeCraft). The data/objects/rules rather than logic-orientation may have been more naturally supportive of open-world attitudes.

2. My understanding of RDF is that it is a concept with many specific representations. Is there an assumed canonical format for gathering the results of a distributed world-wide query?

3. I assume most data query applications do not need to consider the entire web as does a completely free-text application like Google. Subsets of Google apply just to images, just to news, etc. Presumably "just to calendars" is coming. Whether you centralize or decentralize the query, another interesting question will be the conventions for finding the appropriate data.

4. I keep going back to Tom Malone's Information Lens, Object Lens, OVAL series of projects. This was on a much smaller scale than the world, but he did some interesting work on partially-shared views of distributed semi-structured data. (Via the ACM and elsewhere) We need convenient ways to create and evolve partially-shared world-wide data.

5. The more that subsets of semi-structured world data comes into focus for specific applications, the more "queries" will want to include (fuzzy) calculations. Jim Gray's April 2005 ACM Queue article is another interesting tangent on this theme.

No shortage of interesting problems.

Friday, April 08, 2005

Simplest (Overlooked) Things

Core Data looks like a simple, useful data extension to the Next Step, er, Cocoa, framework. (via Bill Bumgarner)

Objective-C and Cocoa seems to be an ongoing counter-example to Jon Udell's take on Microsoft's apparent dynamic language strategy. Jon wrote...

Jim Hugunin, who created first Jython and then IronPython, may be the world's foremost expert on this topic. When I met with him recently, I asked if he thought we'd see official .NET Framework classes written in IronPython. He said that, although dynamic languages will accelerate the development of the framework, extensions written in Python will likely be rewritten in statically-compiled languages for production use. To some dynamic-language advocates that may sound old-fashioned, but to me it sounds pragmatic.
The counter-example is Objective-C itself and the way Next (now Apple) has developed its frameworks. Objective-C makes C available where developers determine to use it, but the key to its capabilities is the dynamic object language cleanly integrated into C.

Objects in the language are fully dynamic and first-class. They enable C and other static languages to participate easily in the object-oriented frameworks without extensions or modifications to those languages. But they also enable dynamic languages to participate easily as well.

Witness the really neat integrations of Python, Smalltalk, and Lisp with the Next Step frameworks. No contortions or compromises, just simple, straightforward integration of reusable frameworks into your language of choice, static or dynamic.

Objective-C and Next/Apple's use of it is underrated and overlooked in its technical simplicity relative to the struggles of dynamic languages in the C++, C#, and Java environments. Notably, this approach dates back to Next's original effort around 1985. This is a twenty year old approach, which satisfies those of us who live in the past. 8^)

Spreadsheets and Databases

Over on the new Smallthought blog there is a conversation about spreadsheets, databases, and end user programming. I added this in a comment, but want to capture it for my own purposes and your enjoyment...

Databases — I have a friend who made a living for a good number of years on a dbase application he wrote for small businesses. Over the years he added more capabilities. He’d go into a new customer’s site, install it, tweak it, maybe implement some new things, and then take the new stuff back to previous customers that may want it. He had no formal software development education or even formal business education. He was a tinkerer, built his own airplane, his own house, etc.

Another story — a friend, MBA in finance, capable of doing decent things with Excel, tried to implement an Access application to track a small golf tournament he was organizing. Nothing ambititous at all. Access presented him with a number of “formal” database concepts that just did not matter to him. He go some things running but mentally associating various tables and forms was not immediately obvious to him, or to me when I looked at it. Maybe it was just us, but even I did not enjoy trying to get Access to do relatively uncomplicated things.

There is a spectrum of choices between a traditional spreadsheet and a traditional database. Perhaps a more usable system in this space would allow someone to begin working more like a spreadsheet and allow shapes to emerge and be supported more like a database, but not expose that support in traditional database terms. The support for those shapes should be more identifiable by the end user programmer without a 20th century software education.

Tuesday, April 05, 2005

New Lisp

Ted Neward wonders...

Is Ruby the next Lisp? And if so, does that make Ruby a "second chance" for widespread acceptance for Lisp?
I would not say Ruby is the next Lisp. Rather, Ruby is one of the most recent Lisp-like languages. Python is a Lisp-like language going back a decade or whatever longer.

Smalltalk is even a Lisp-like language, as has been noted recently, and Kay states Smalltalk was directly influenced by Lisp. (pdf)

Can I learn to be a better Ruby programmer by learning Lisp, or vice versa?
Yes. For that matter, one can learn to be a better C programmer by learning Lisp. Or Ruby.
If one of Lisp's strengths is writing programs to write programs, does that make Lisp a natural candidate for building DSLs?
Absolutely. And has been in practice for 40 years or more. Literally.
And, again, if the Ruby == modern(Lisp) equation holds true, does that make Ruby a candidate for building DSLs?
Ruby would not be *bad* for building DSL's. The difference with Lisp is the syntax and syntactical tools are not as good for doing this in Ruby as they are in Lisp.

DSL's are best built in Lisp and Smalltalk, somewhat less so in Ruby and Python. But Ruby and Python programmers could argue that pretty well with me. I think I know both of them pretty well but not so well as to say I know I know both of them pretty well.

Sunday, April 03, 2005

Python Moving Into the Enterprise

From Slashdot...

"Seems that Python is moving into the enterprise. At the recent PyCon it has become apparent that it's not just Google, GIS, Nokia or even Microsoft anymore. The article points out that Python is increasingly becoming a perfectly viable and even preferred choice for the enterprise. More and more companies are looking at Python as a good alternative to past favorites like Java. Will we finally be able to code for living in a language that's not painful? Exciting times!"

Evolutionary

"There is no such thing as a non-self organizing system." -Esther Derby(?)

Yep

"Poor management can increase software costs more rapidly than any other factor." -Barry Boehm

Buddies, ACL's, and Capabilities

Tim wrote some time ago about making everything network aware, including...

  • If you assume ad-hoc networking, you have to automatically define levels of access. I've always thought that the old Unix UGO (User, Group, Other) three-level permission system was simple and elegant, and if you replace the somewhat arbitrary "group" with "on my buddy list," you get something quite powerful. Which leads me to...
  • Buddy lists ought to be supported as a standard feature of all apps, and in a consistent way. What's more, our address books really ought to make it easy to indicate who is in a "buddy list" and support numerous overlapping lists for different purposes.
Rather than ACLs, I'd like netware to provide me a list of actions it's capabable of doing on the network, along with an easy way of composing new actions. Then I'd like to make several groups of those actions from all my netware. One grouping for myself, others with decreasing capabilities for family, friends, associates, and the world at large.

My buddy list would then include for each member the groups of capabilities I have granted them. As relationships change I would then be able to increase or decrease their reach into my world.

I've not followed the e-rights world for a while. I wonder where this is going.

Saturday, April 02, 2005

Triples, Quads, Quints?

Bill de hÓra writes about RDF, triples, and quads. I think the point is RDF representa triples (X-Y-Z) but he wants to introduce another party into the relationship, e.g. he wants to distinguish (A-(X-Y-Z)) from (B-(X-Y-Z)). Apparently RDF cannot do this concisely, i.e. you need more than A, B, X, Y, and Z in order to denote that A and B relate to the same triple (X-Y-Z) in each in their own way.

Triples, quads, etc. I have to say I've not used RDF at all explicitly.

I guess "quads" are intended to support the (A-(X-Y-Z)) and (B-(X-Y-Z)) relationships concisely.

But, the engineer in me ignorantly wonders, won't we soon run into a desire for a fifth party in this relationship? Why stop at quads?

Quints, hexes, septs. How many is enough?

I wonder if we need a concise way of representing many occurrences of Many-Many relationships. Something like a Star Schema would simplify bulk Many-Many relationships. Bonus, it implies certain expectations about the contents of the relatonships, i.e. you can speak of measurements, occurrences, hierarchies, allocations, headers / details.

Star schemas can be seen as a shorthand notation for many implied individual RDF triples. Bonus, they are proven to be incredibly scalable and support high performance with fairly simple database implementations. The column-based storage approach goes back at least to the 1970's. Another example is Kdb, although "array based" and columnar, it's not explicitly star schema based.

I'm just thinking RDF triples are probably too primitive, and thinking out loud about what might be more expressive. Mostly I am confused about a triple to quad to (?) progression trying to represent increasingly complex relationships. Star schemas encourage a discipline, style, and simplicity into complex relationships that can scale and evolve.

I'll have to learn more about the triple / quad issue and think about this before I can become more coherent on comparing these modeling approaches.

Friday, April 01, 2005

JINI and JavaSpaces

JINI (and therefore JavaSpaces) in action, not inaction, via Tim Bray...

Jini has the fingerprints of Bill Joy and Jim Waldo all over its architecture, and these are obviously two of the Real Smart Guys. Rob Gingell, another one of them, said “Those who do not use Jini are doomed to re-invent it.”

Jini is not just a theoretical triumph; it’s being deployed in large mission-critical applications at places including Orbitz, Orange (the mobile-phone company), Raytheon, and the U.S. Army.

Must (Try) to Understand This?

Sean McGrath writes about "must understand" rules in loosely coupled message passing...

Whatever about the pros and cons of REST versus SOAP, I think it is abundantly clear that the mustUnderstand model [1] is a key concept in developing loosely coupled systems that can evolve independently.
I need April 2 asap.

One thought this does provoke though, for real, is that a sender probably has no business telling a receiver what it must understand or to what degree. I'm all for ways for receivers to describe, more or less formally, what they will understand and how they will understand it. Senders just send messages and set their expectations as best as possible. Hopefully both senders and receivers have robust fallback capabilities.

Thursday, March 31, 2005

They Are Principles

Kent Beck writes...

If we abandon our principles at the first sign of trouble, our principles must not be worth much.

I think integrity and accountability are particularly important in a climate of fear.

Democracy Inaction

John Robb wonders...

What we may end up with as part of this push towards "democracy" in the Middle East is civil war. Lebanon, Iraq, and Palestine are all on the brink of it now. Are we better off with this?
Yeah, I think the next chapter is still being written while people rush to chalk up an "ends must justify the means" scenario for democracy breaking out in the mideast.

There are so many directions this could go. Think of this as a complex system that is not very well understood with more than a few elements of chaos.

This is not a "guzinta-guzoutta" simple equation. And no, Bill Maher. I agree Bush stumbled into something, but a fresh pile of democracy in the mideast is not yet clearly the pile he stepped into.

Wednesday, March 30, 2005

That's the Way of the World

"That's the Way of the World" has been one of my favorite songs for about 30 years. Not one of EW&F's funkier tunes though. "Shining Star" too. A little bit funkier.

(Blaine Buxton likes funk.)

Hubris

Unfortunately, Truly says, the prevailing wisdom at the Pentagon is that "fuel efficiency is for sissies."
(via John Robb)

Hubris. Marines don't eat granola, they just kick the shit out of haj's. Scary when the stereotypes show up in reality.

What Goes Around

(via John Robb)

The MS 13 sprang up in the late 1980s, created by the children of Salvadoran immigrants who fled to California during a bloody civil war.
Can we not think in terms of systems? Everything is compartmentalized and treated as independent, discrete actions. Not only does every action have a reaction, but the systems we are creators of, and participants in, are far more complex than we ever think about in the moment.

Has science taught us nothing about society?

Know(n)Now as AJAX

From FoRK on the AJAX controversy...

"Yeah, I liked that idea the first time around.
When it was called 'KnowNow'."
See also mod_pubsub.

We Build Our Own

The misunderstanding about XP and "doing the simplest thing" is more often than I'd like taken to absurd extremes. For example I encountered a developer recently repeating a claim that an XP team would not use a framework that had been built to simplify a certain style of software development.

Certainly the XP team would want to understand their experience with the framework, the maturity of the framework, and the nature of the problem's suitability for the framework. But not use it, period?

Gack.

So how far does this go?

"I'm not sure we need a computer for this project, but when we do we'll dig up the coal to forge the steel to make the rack to mount the motherboard."

"I'm not sure we need a high-level programming language. We'll use assembly language and see what patterns emerge, then let the higher-level language evolve."

I think there is a spirit and a letter to the law, and the same goes for XP values. Just work in small pieces with concrete feedback. Avoid too much prediction and too many assumptions. Common sense works wonders.

Tuesday, March 29, 2005

Whence Dynamic Languages

Ryan Tomayko projects what might be necessary to get better late-bound languages acceptance in early-bound organizations...

I think we need something to break through on one of the VMs if we're ever going to move this into the enterprise. There's no way I could bring Python into my place of business on any serious level. This really comes down to it not being blessed as Enterprise Class (blech!) by Sun. It seems we need the VM to get in the door and then maybe we can just move quietly toward CPython with a Java/CLR bridge?
Maybe. The IT industry seems kind of in a "standardization" phase still, following the irrational exhuberence of the "anything goes" phase of the dot.com days. That can translate into the desire to choose one language to standardize on developer resources. I'm not sure getting CPython in would be any more difficult than Jython or IronPython.

We used to have these things called skunkworks. Do such things exist anymore where you can demonstrate value before being judged prematurely on cost? I think maybe but you may need radar detectors along the way.

Monday, March 28, 2005

Frameworks and Plug-ins and Loose Coupling

From ACM Queue about frameworks and plug-ins...

This article identifies some of the concepts around the foundation of pure plug-in architectures and how they affect various stakeholders when taking a plug-in approach. The intention is to discuss the general issues involved, but the article also presents some lessons learned from Eclipse (www.eclipse.org) to better illustrate some of the concepts.
The main problem with a framework like Eclipse is that so many unnecessary dependencies are forced on plug-in developers. You have to buy the full Eclipse approach to get even half the benefits.

What lessons have we learned in the last 15 years of building frameworks like this? Are we having trouble understanding what is important, what has been learned already in the software industry?

Why build a framework like Eclipse in the 21st century when you could build a framework like FIELD which was built in the 1980s? Certainly the full benefits of Eclipse could be built *using* an approach like FIELD's. Plug-ins that did not or could not support the full benefits of Eclipse would then have fall-back positions. New approaches could evolve that stretch beyond the imaginary boundaries of the current Eclipse framework.

What is it about FIELD? Well FIELD is based on integrated components loosely coupled via asynchronous message passing.

That may ring a bell for 21st century programmers.

Reconciling Modal Web Apps and Rest

Mark Baker comments on how continuation-based modal web applications fit the REST style...

"This is how most web applications work.". Actually, it isn't. Most Web applications are stateless. Of those that aren't, the vast majority are only stateful for authentication purposes.
Here's how I've started to view the relationship of the modal web app style and the REST style:
  • Work-in-pogress interactions seem to be programmed AJAX-style, GOTO-style, Modal-style, or "richer-client" style.
  • Modal web applications simplify programming controllers for work-in-progress over HTTP.
  • Continuation-based interactions are not necessarily RESTful.
  • As work-in-progress is "published" those pieces of work become resources with various representations, etc.
  • Publishing (perhaps partially as a "proposal") completed work as resources can be RESTful.
  • Accessing (perhaps partially) completed work as resources can be RESTful.
So I think modal and RESTful can be seen as somewhat complementary styles or at least aimed at different purposes. Perhaps they don't have to be completely unified if they meet their purposes with little risk of interference between implementations.

Extreme Refactoring

Again Keith Ray, this time on design, refactoring, and language choice...

Brian Button decided to explore refactoring by taking the Video Store example from Martin Fowler's book and refactoring it into methods one line long, no private methods, and aggressively removing all duplication, particularly duplication of iteration over containers.

His starting point (and Fowler's ending point) is the class named "Customer", containing a list of rentals. It has private methods for calculating rental cost and "frequent renter points", and a large method for printing the customer's statement. Brian's ending point is seven classes: Customer, RentalStatement, RentalCollection, Collector, LineItemPrinter, FrequentPointsTotaller, RentalCostTotaller.

If he had been programming in Ruby or Smalltalk instead of C#, he probably could have met his goals with only first two classes. Blocks and iteration methods built into Smalltalk/Ruby collection classes would have eliminated the need to create the other five classes.

Agile Data

Keith Ray writes about agile data...

He asked audience members to raise their hands if they could make a simple change (like renaming a column of a table) and re-deploy their database and associated apps in the same day. Only one guy, in a large room filled with database people, raised his hand (I bet that guy worked at Yahoo, Amazon, or Google.) That guy's DB had terabytes of data and 37 apps depending on it, but he could deploy a change in less than one day.

Ambler also asked audience members to raise their hands if their database and associated apps had extensive automated testing. The same guy raised his hand, and maybe one other.

Sunday, March 27, 2005

Bill Maher

I saw Bill Maher live last night. He was recording an HBO special and DVD in Portland. Maher is a good observer and funny commentator of American politics, religion, and culture. He is irreverent and holds nothing back. He's more of a traditional humorist like Mark Twain or Woody Guthrie than Jon Stewart. But he goes beyond Stewart and Lewis Black topically and stylistically. (I missed seeing Black on stage when he was in Portland a few months ago.)

These three along with Harry Shearer are four people worth listening to for insight into the state of the union with varying degrees of subtlety and style.

Boo and IronPython

Edd Dumbill tried IronPython and now prefers Boo. Another Python friend was thinking of trying Boo too. The problem I have with that is I'd rather the bulk of my code not be tied to a specific platform, which Boo seems to do. Boo runs on MSFT dotnet as well as Mono, but still requires the CLR platform.

Edd raises significant concerns about IronPython. Rather than a somewhat handcuffed Boo, I would think a Python programmer would be very well off with regular CPython and bridging to dotnet via the Python.Net dll's.

Attitudes Toward SISC and Continuations

Chris Double used SISC running in the JVM to build a continuation-based modal web server. He wrote of the manager's and developers' experiences...

This approach has worked well for me and the performance is quite usable. Although I do get constant requests from the project manager to find a way to rewrite things in Java as he never was a fan of using Scheme and is concerned it may put customers of the system off it. The developers on the other hand seem to have enjoyed learning Scheme and consider it an advantage over Java.
Listen.

The Secret Sauce

(via Blaine Buxton) Eliot Miranda divulges...

VisualWorks and VW/GemStone combinations are used in sectors such as cpu manufacture, container shipping and derivatives trading on a world scale (i.e. they handle a substantial fraction of the world's activities in these sectors). But for nearly two decades the corporations who have built these applications have viewed their use of Smalltalk as a strategic advantage, and hence prevented the vendors from using the applications in marketing material.

Friday, March 25, 2005

Python Performance

Good news, but let's not get too sweaty over this...

IronPython is markedly faster on PyStone than CPython.
...remembering the CPython VM does not really push the envelope of VM techniques.

IronPython at PyCon

Technorati has dug up a list of items on IronPython at PyCon this week. I've not consumed any of them yet, but hopefully they will be enjoyable.

It looks like the new release of IronPython depends on the Yukon CLR. So for now it looks like CPython with the Python.Net assembly bridge is the approach of choice for "real" uses. With a bit of care Python code could then port over to IronPython.

Not sure what the language level of IronPython will be vs. CPython when Yukon is released.

Alan Kay (again) on Software Engineering

Kay's interview has made the rounds more than once, but with recent posts on software as engineering or craft, let's go back to the guru...

If you look at software today, through the lens of the history of engineering, it’s certainly engineering of a sort—but it’s the kind of engineering that people without the concept of the arch did. Most software today is very much like an Egyptian pyramid with millions of bricks piled on top of each other, with no structural integrity, but just done by brute force and thousands of slaves...

I would compare the Smalltalk stuff that we did in the ’70s with something like a Gothic cathedral. We had two ideas, really. One of them we got from Lisp: late binding. The other one was the idea of objects. Those gave us something a little bit like the arch, so we were able to make complex, seemingly large structures out of very little material, but I wouldn’t put us much past the engineering of 1,000 years ago...

I finally understood that the half page of code on the bottom of page 13 of the Lisp 1.5 manual was Lisp in itself. These were “Maxwell’s Equations of Software!” This is the whole world of programming in a few lines that I can put my hand over...

All of these ideas could be part of both software engineering and computer science, but I fear—as far as I can tell—that most undergraduate degrees in computer science these days are basically Java vocational training...

In a history of Smalltalk I wrote for ACM, I characterized one way of looking at languages in this way: a lot of them are either the agglutination of features or they’re a crystallization of style. Languages such as APL, Lisp, and Smalltalk are what you might call style languages, where there’s a real center and imputed style to how you’re supposed to do everything. Other languages such as PL/I and, indeed, languages that try to be additive without consolidation have often been more successful. I think the style languages appeal to people who have a certain mathematical laziness to them. Laziness actually pays off later on, because if you wind up spending a little extra time seeing that “oh, yes, this language is going to allow me to do this really, really nicely, and in a more general way than I could do it over here,” usually that comes back to help you when you’ve had a new idea a year down the road. The agglutinative languages, on the other hand, tend to produce agglutinations and they are very, very difficult to untangle when you’ve had that new idea.

One clear implication is that language you use has a significant impact on your ability to do software engineering. Your language is your most highly used tool.

Do Good for America - Use Lisp

(via Lemonodor)

François-René Rideau implores...

The obsession with parsing and syntax in computer science curricula is hurting America.

SPLJ Part 2.

Mark Baker suggests...

The resource oriented (RESTful) solution would exhibit greater degrees of architectural properties such as scalability, visibility, and simplicity than the service oriented solution, because RESTful solutions embody architectural constraints which induce those properties.

SPLJ

In the raw...

Applications remain largely discrete things, whether they’re wired together with RPC, SOAP or REST. Only slightly, (particularly around the blogosphere) are we seeing the pieces joining together.

Thursday, March 24, 2005

Preventing Death

Somewhere around 13,000 children die of hunger-related causes every day around the world. I wonder when the US congress will subpoena them to come testify. Certainly they will get at least a snack on the airplane.

Certainly the congress can do something to save at least one of those lives each day. That's at least 364 more lives saved each year than can be saved in the case in Florida.

How much longer can our "culture of life" continue to ignore millions of deaths a year?

Blog Archive

About Me

Portland, Oregon, United States
I'm usually writing from my favorite location on the planet, the pacific northwest of the u.s. I write for myself only and unless otherwise specified my posts here should not be taken as representing an official position of my employer. Contact me at my gee mail account, username patrickdlogan.