Sign in

MLabs

@mlabs-consulting.bsky.social
9 followers 1 following 19 posts

Software consultancy. Identity and secrets infrastructure: PKI and certificate lifecycle, managed Keycloak, Vault, OpenBao. We write and verify Haskell, Rust, TypeScript. We write and audit Cardano smart contracts - Aiken, Plutarch, Plinth. www.mlabs.city

PostsRepliesMedia
MLabs @mlabs-consulting.bsky.social · 09/10/2026
Thanks, glad it landed. Koz's point that the exhaustiveness checker still works on a packed Int8 is the bit I keep going back to.
000
MLabs @mlabs-consulting.bsky.social · 09/10/2026
Game of Life in Haskell took 242 ms per update with vector and 11.2 ms with massiv stencils, on the same memory. A 3D cellular automaton went from 418 ms to 39 ms. www.mlabs.city/blog/our-per... #Haskell #FunctionalProgramming
mlabs.city
Our Performance is massiv: Getting the Most Out of Your Hardware in Haskell
Getting real performance out of Haskell with the massiv library - temporal and spatial locality, parallelism, and why arrays make both of them possible.
010
MLabs @mlabs-consulting.bsky.social · 08/10/2026
A three-valued logic packed into an Int8 can still be pattern matched like an ordinary data type, exhaustiveness checks included. Pattern synonyms do it with no Template Haskell, and they work on types you didn't write, like Word8. www.mlabs.city/blog/pattern... #Haskell #FunctionalProgramming
mlabs.city
Patterns and Paradoxes: The Logic of Pattern Synonyms
Pattern synonyms give Haskell the separation of representation and interface that smart constructors promise, without the cost of Template Haskell.
152
MLabs @mlabs-consulting.bsky.social · 07/10/2026
One command boots a VM running a Cardano preview node, with Ogmios answering on localhost port 1337. cardano.nix ships cardano-node, Ogmios, Kupo and db-sync as NixOS modules, each tested in VMs against the real networks. www.mlabs.city/blog/introdu... #Cardano #Nix
mlabs.city
Introducing cardano.nix: Simplifying Cardano Infrastructure Deployment
cardano.nix simplifies deploying Cardano infrastructure - node, ogmios, kupo and db-sync - with consistent configuration, versioning and monitoring.
000
MLabs @mlabs-consulting.bsky.social · 06/10/2026
Map two 20-element arrays on Cardano, then zip them. Through builtin lists, 88.1M CPU units. With Plutarch's pull arrays, 44.1M and half the memory. Longer pipelines skip more intermediate lists. www.mlabs.city/blog/perform... #Cardano #Haskell
mlabs.city
Performance, pull arrays and Plut{arch, us}
Pull arrays bring the performance advantages of spatially local structures to Cardano smart contracts - what works in Plutarch, and what does not.
000
MLabs @mlabs-consulting.bsky.social · 06/10/2026
We only measured the one size, where binding cost 89,319 more CPU units. That overhead stays flat whatever the constant holds, while each inlined copy adds its full bytes to the script and the size fee. So binding wins past some size. We haven't measured where.
010
MLabs @mlabs-consulting.bsky.social · 05/10/2026
A Cardano script compared a big constant with itself. Inlined twice, it cost 578,965 CPU units. Bound to a variable, 668,284. In UPLC every variable needs a lambda and an apply around it, and you pay for both. www.mlabs.city/blog/how-exe... #Cardano #Haskell
mlabs.city
How Execution Budgeting Works for On-Chain Scripts
How the Untyped Plutus Core cost model calculates a script's execution budget on Cardano, and why its CPU and memory units behave nothing like the real thing.
100
MLabs @mlabs-consulting.bsky.social · 05/10/2026
Finding one byte in 2 MiB of Haskell data: 880 μs naive, 123 μs with SWAR, 16.8 μs through C's memchr. Then we used memchr to find every match. It came out about 50% slower than the naive loop. www.mlabs.city/blog/fast-fi... #Haskell
mlabs.city
Fast Findings with SWAR and the FFI: The Good, the Bad, and the Inefficient
When Haskell's FFI helps performance and when it hurts - benchmarking SWAR against C for byte searching, and the call overhead that decides which wins.
000
MLabs @mlabs-consulting.bsky.social · 02/10/2026
Checking a buffer is ASCII in Haskell, one byte at a time, ran at about 2.2 GiB/s worst case. Masking the high bit of 8 bytes per word got 13.75 GiB/s. Theory said eight times faster. We measured about six. www.mlabs.city/blog/checkin... #Haskell #Performance
mlabs.city
The 'A' is for 'Accelerated': Checking ASCII with SWAR
Using SIMD-within-a-register (SWAR) to speed up ASCII validation in Haskell, and how far performance can be pushed without ever leaving the language.
000
MLabs @mlabs-consulting.bsky.social · 02/10/2026
Thanks for passing it on.
010
MLabs @mlabs-consulting.bsky.social · 29/09/2026
One Cardano transaction can spend several script outputs at once. If each validator only checks that it got paid, a single payment can satisfy all of them. That's multiple satisfaction, and our audit write-up walks through one. www.mlabs.city/blog/from-bu... #Cardano
mlabs.city
From Bugs to Breakthroughs: Auditing Cardano Smart Contracts
Why Cardano smart contracts need independent auditing, the risks that subtle on-chain interactions create, and how a rigorous audit finds them first.
100
MLabs @mlabs-consulting.bsky.social · 28/09/2026
A failing QuickCheck property is only as useful as its counter-example. Without a shrinker, a random failure can be too big to read. With one, QuickCheck cuts it down to a small input that still fails. www.mlabs.city/blog/masteri... #Haskell #QuickCheck
mlabs.city
Mastering QuickCheck: Advanced yet Practical Techniques for Property-Based Testing
Practical techniques for property-based testing in Haskell with QuickCheck, and how to avoid the pitfalls that make it harder to use than it should be.
000
MLabs @mlabs-consulting.bsky.social · 25/09/2026
That was the design rule for the ProofTap contracts. A scan has to verify from chain data alone, so nobody needs to trust whoever runs the endpoint, us included. And the tag has a 1:1 cryptographic proof, so you don't need to trust the tag either.
010
MLabs @mlabs-consulting.bsky.social · 24/09/2026
If checking an item needs an API to answer, the API's operator is the trust anchor and the blockchain is decoration. That rule shaped ProofTap, an NFC-to-Cardano verification app whose smart contracts we wrote. www.mlabs.city/blog/proofta... #Cardano #SmartContracts
mlabs.city
Cardano smart contracts behind ProofTap — MLabs case study
MLabs wrote the Cardano smart contracts behind ProofTap, an NFC platform that links physical items to publicly verifiable records. What an on-chain record has to do before a stranger's tap means anyth...
100
MLabs @mlabs-consulting.bsky.social · 23/09/2026
Review was built for code that looks wrong when it is wrong. Agent-written code compiles and reads cleanly, so it passes a skim. The bugs that survive are the plausible ones. They surface when the code runs against a QuickCheck property someone stated.
000
MLabs @mlabs-consulting.bsky.social · 21/09/2026
Verification is a claim about strangers. If checking a record needs an API to answer, that operator is the trust anchor and the chain is decoration. Whether you write it in Aiken or Plutarch, the question is the same: what has to be true with nobody's server involved?
000
MLabs @mlabs-consulting.bsky.social · 14/09/2026
Buen punto. En pruebas de federación LDAPS, un certificado no confiable rompe Keycloak por completo y reporta SocketReset, sin mención a certificados. Con KC_TRUSTSTORE_PATHS vacío devuelve cero usuarios. Con el CA en el truststore, tres. El dueño del ciclo no se deduce del error.
000
MLabs @mlabs-consulting.bsky.social · 14/09/2026
We tried to reproduce the Keycloak upgrade horror story. We killed the migration mid-run twice. No lock was left behind; the next start finished in 13s. What broke it 3/3 was PgBouncer in transaction pooling, the common default. The migration log said success; the version record never moved.
mlabs.city
The Keycloak upgrade failure everyone describes, and its real cause
We could not reproduce Keycloak
000
MLabs @mlabs-consulting.bsky.social · 14/09/2026
We're a software consultancy. We maintain the security infrastructure your team owns but nobody owns: PKI and certificate lifecycle, managed Keycloak, Vault, OpenBao. We write and verify codebases in Haskell, Rust, TypeScript. We write and audit smart contracts.
161