Skip to content
NorscodeNorscode

Why the runtime says no

ArticleBy the Norscode project

A short explanation of the capability model, and why it is on from the very start.

The most common question new users have is why a program stops with manglar capability when it obviously just wants to read a file or open a port. The answer is that Norscode flips a default setting most other languages take for granted — and once you understand it, the error message becomes a helper, not an obstacle.

The program starts with no access

In most languages, a program inherits the access of the user who starts it: the whole disk, the whole network, all environment variables. A dependency deep down in the tree can read your keys without anyone noticing. In Norscode, the program gets nothing until you give it — and the error message manglar capability simply means the code asked for something it was not given.

How you grant access

You specify the capabilities when you start the program, through environment variables:

NORSCODE_VM_CAPABILITIES="disk.read,net.tcp" NORSCODE_VM_DISK_ROOT="/srv/data" nc run rapport.no

Here the program can read under /srv/data and use the network — not write to disk, not read the environment. The most common capabilities are disk.read, disk.write, net.tcp, env.read and env.write. In addition, you can narrow where the access applies: NORSCODE_VM_DISK_ROOT restricts disk access to specific directories, and NORSCODE_VM_NET_SCOPE which hosts the program is allowed to talk to.

The boundary cannot be negotiated away

The important thing is that the program cannot ask for more access while it is running. The boundary is set once, by whoever starts it. That means you can run code you have not read every line of — a third-party module, an example you found online — and still know exactly what it can do at most.

A little extra work, much in return

The model costs a few lines when you start the service. In return, you have a concise, honest list of what the program is allowed to do — readable by a human, not hidden in a thousand lines of code. In a world where most security holes are about something being allowed to do more than it needed, that is cheap insurance.

Related

Back to the overview