I wish the effect system could be used to implement sandboxing.
The stdlib procs that run system calls could be tagged accordingly, and the application's "main" could then set up a sandbox at runtime to allow only the required system calls.
I wish the effect system could be used to implement sandboxing.
The stdlib procs that run system calls could be tagged accordingly, and the application's "main" could then set up a sandbox at runtime to allow only the required system calls.