Re: Capsicum: Object capabilities for Linux
Jed Donnelley <capability-iCFHVraI1K1Wk0Htik3J/[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On 10/10/2013 11:57 PM, Bennie Kloosteman wrote: > > On Fri, Oct 11, 2013 at 12:58 PM, Jed Donnelley > <capability-iCFHVraI1K1Wk0Htik3J/[email protected] <mailto:capability-iCFHVraI1K1Wk0Htik3J/[email protected]>> wrote: > > ...I think I can understand the work involved, but not why the > amount of work depends on the support of non-support of "arbitrary > interposition of all operations" in the capability interface. > > I'd love to hear a bit about how directory capabilities work in > Capsicum - e.g. compared to the way they work in the Tahoe file > system or to GNOSIS or any of many other interfaces. Driven by > Unix symantics no doubt, but how does access right "masking" work > when referencing through a directory capability? How are links > (hard and soft) handled? > > > > I'm not a capsicum designer but have used it for a month about 1-2 > years ago - just trying to help . Suggest you post the why question to > the capsicum list. My use was basically allow app to do lots of > dirty stuff when starting then turn on cap mode and pass to user and > then everything is via the powerbox. > > This model i think is good because existing apps can become cap apps > quite quickly and then mature. > ... Agreed. I'd just like to find out if (and if so why) the Capsicum capability model can't be "object capability" (arbitrary interposition of all operations). If it were then it would be able to do more and would appeal to another group of people (e.g. like me). > >> There is hope on the desktop though as Capsicum seems to be the >> default and in the Kernel on FreeBSD making FreeBSD attractive as >> a secure platform . > > ...I could see spending some time contributing work to such a > "secure platform". However, if the interface doesn't have the > arbitrary interposition of all operations property then it would > take quite a bit of wind out of my sails. > > > Well the Linux world better get there act together as far as im > concernced, they have a worse security design/ model than Andorid/ > Windows Phone 8 ..which is embarrasing. However these new phone APIs > are so limiting it requires complete app redesigns and none of them > support 3rd party servers ( eg Daemons , "services") yet . I think > Unix change is hard and that it requires revolutionary change ( and > on Android Windows Phone touch apis force this) . All I care about is 1. object capability, 2. open source, and 3. Some place that can grow to add practical value. > > Is anybody doing any programming for any of these platforms who > can discuss how "object" these capability models are? > > > The capsicum list and maybe FreeBSD. Capsicum list is about 1 post > per week > > https://lists.cam.ac.uk/mailman/listinfo/cl-capsicum-discuss Thanks. I'll try there. --Jed _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk