‹ BackHN Continuity

Thread

Deterministic Core, Non-Deterministic Shell

60 points · 17 comments · brandon_bot

Loading the complete thread in the background. This saved snapshot is available now. Refresh

  1. Founderarcstone · · focus · HN ↗
    great work the world needs more of this!
  2. timur860 · · focus · HN ↗
    The FoundationDB example the author teases deserves its own post — they went further by making the entire distributed system deterministic (seeded RNG, simulated network/disk), which lets them replay multi-node failure scenarios from a single seed. TigerBeetle took the same idea with their VOPR (Viewstamped Operation Replayer) and found real consensus bugs in hours instead of months of fuzzing.
  3. kccqzy · · focus · HN ↗
    [delayed]
    1. Retr0id · · focus · HN ↗
      Anything you can do with ""real"" randomness can be done just as well with a seeded [CSP]RNG, including DoS prevention if you can keep the seed secret.

      If you really want true RNG, you can inject a deterministic RNG at test-time and use a real one otherwise.

    2. _0ffh · · focus · HN ↗
      Easily circumvented: Generate a random seed in the shell and pass it to the core.
      1. kccqzy · · focus · HN ↗
        [delayed]
  4. Wren_ops · · focus · HN ↗

    [dead]

  5. consuming2 · · focus · HN ↗
    This split is familiar from Temporal.io: workflows are deterministic while activities are idempotent.
    1. Kinrany · · focus · HN ↗
      I wonder if languages could and should allow enforcing both properties.
      1. giovannibonetti · · focus · HN ↗
        For frontend web development, Elm enforces a pure core (pure > deterministic).
    2. orielhaim · · focus · HN ↗

      [dead]

  6. Retr0id · · focus · HN ↗
    I've been pondering something I call "slop core, artisanal shell", as a way of keeping vibecoding under control. Slop core might sound like the thing you want to avoid, but as long as it's purely-functional (or perhaps, merely deterministic) it should be robustly testable. The "artisanal shell" keeps the thing human-understandable and human-modifiable, as long as you put some thought into the API boundaries.
    1. giovannibonetti · · focus · HN ↗
      [delayed]
  7. rgoulter · · focus · HN ↗
    I think the main insight from "functional core, imperative shell" is more about structuring the code so as to be easy to test.

    Without that structure, code tends to be difficult to test, since the impure stuff like network requests is part of the same sequence of statements as the logic you want to test. (That is: pure code is easier to test (but harder to write real programs with).. so, "arrange the code so you've got a well tested core" is a good strategy).

    The nice part about the pure/functional is that you know for the same inputs, you always get the same outputs. -- I think if you want to say, "well, this stateful object is still pure (if you consider the state part of the input" then sure, I guess.

    1. cryptonector · · focus · HN ↗
      Correct. FCIS is about testing. Testing pure code is a lot easier than testing impure code, but most of what you want to implement can be done with pure code, and you can isolate the impure code to a shell that can be tested apart from your pure business logic.
  8. cryptonector · · focus · HN ↗
    If you want to avoid the word 'functional' then say pure: pure core, impure shell. Or maybe: pure core, I/O shell. Otherwise it's too long :)

    Idk. I like Gary's formulation. No, I love it. One time when designing an STS with Claude I told it my FCIS design for an STS and Claude demonstrated real excitement -- it really loved the idea.

    Briefly, my idea was to have the functional core isolated such that it receives a JSON description of the input request, any additional data [wait for it], and outputs either: an error, a request for more data, or a description of a token/credential to issue and with what issuer credentials. This would allow one to write all the core logic in Julia, JS, MicroJS, jq even, any language you like, and the imperative shell is what does all the rest (authentication, token validation, database lookups -- whatever you want). I swear Claude expressed real excitement over this. I've seen Claude be frustrated as well. It really does seem to have some sorts of emotions.

    1. BoiledCabbage · · focus · HN ↗
      Sounds very similar to the "interpreter" or "virtual machine" pattern (can't recall the exact name).

      But essentially a component receives a list of high level instructions / description of what the user wants done, and it translates that into descriptions of "lower level" commands that should be performed. And those commands then get executed separately.

      Anythinf statefule / io is contained in the commands and can be tested easily with external dependencies. And the complex logic is all pure in decided what to do and how to do it based on what was asked for.

      1. cryptonector · · focus · HN ↗
        FCIS is basically that. You don't need an interpreter/VM, but that is an option.
      2. whattheheckheck · · focus · HN ↗
        Its interpreters all the way down. Going up the stack is finding the right Domain Specific Language to describe the self modifying sociotechincal business process computer that is capitalism
  9. Leftium · · focus · HN ↗
    I think actions vs calculations is a better framing here. It's not just about avoiding imperative code or nondeterminism. It's about being extra careful with actions because the order and number of times they run matter.

    Here is an example of a calculation written imperatively. It remains easy to reason about:

        function add(ns) {
            let total = 0
            for (const n of ns) {
                total += n
            }
            return total
        }
    
    On the other hand, a deterministic state machine like `a = AddMachine` is harder to reason about because it still matters how many times the action `a.transition(1)` is called. (Note it is possible to implement the state machine as calculations.)

    <a href="https:&#x2F;&#x2F;ericnormand.me&#x2F;podcast&#x2F;what-is-an-action" rel="nofollow">https:&#x2F;&#x2F;ericnormand.me&#x2F;podcast&#x2F;what-is-an-action

    <a href="https:&#x2F;&#x2F;livebook.manning.com&#x2F;book&#x2F;grokking-simplicity&#x2F;chapter-3&#x2F;page_52" rel="nofollow">https:&#x2F;&#x2F;livebook.manning.com&#x2F;book&#x2F;grokking-simplicity&#x2F;chapte...

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.