Re: Capsicum: Object capabilities for Linux

Bennie Kloosteman <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <CAJT18ibSrAJhYSPQX50PHRd5XFMRQohnvA3r0ZVkGgD_2fp8BQ@mail.gmail.com>
On Sun, Oct 13, 2013 at 2:43 PM, Jed Donnelley <capability-iCFHVraI1K1Wk0Htik3J/[email protected]>wrote:

>  On 10/10/2013 11:57 PM, Bennie Kloosteman wrote:
>
>
> On Fri, Oct 11, 2013 at 12:58 PM, Jed Donnelley <capability-iCFHVraI1K1Wk0Htik3J/[email protected]>wrote:
>
>> ...I think I can understand the work involved, but not why the amount of
>> work depends on the support of non-support of "arbitrary interposition of
>> all operations" in the capability interface.
>>
>>
>> I'd love to hear a bit about how directory capabilities work in Capsicum
>> - e.g. compared to the way they work in the Tahoe file system or to GNOSIS
>> or any of many other interfaces.  Driven by Unix symantics no doubt, but
>> how does access right "masking" work when referencing through a directory
>> capability?  How are links (hard and soft) handled?
>>
>
>
>  I'm not a capsicum designer but have used it for a month about 1-2 years
> ago - just trying to help . Suggest you post the why question to the
> capsicum list.  My use was basically  allow app to do lots of dirty stuff
> when starting then turn on cap mode and pass to user and then everything is
> via the powerbox.
>
>  This model i think is good because existing apps can become cap apps
> quite quickly  and then mature.
>  ...
>
>
> Agreed.  I'd just like to find out if (and if so why) the Capsicum
> capability model can't be "object capability" (arbitrary interposition of
> all operations).  If it were then it would be able to do more and would
> appeal to another group of people (e.g. like me).
>

Is it because its C and supports C apps ?

>
>
>>   There is hope on the desktop though as Capsicum seems to be the
>> default and in the Kernel on FreeBSD making FreeBSD attractive as a secure
>> platform .
>>
>>
>>  ...I could see spending some time contributing work to such a "secure
>> platform".  However, if the interface doesn't have the arbitrary
>> interposition of all operations property then it would take quite a bit of
>> wind out of my sails.
>>
>
>  Well the Linux world better get there act together as far as im
> concernced, they have a worse security design/ model than Andorid/ Windows
> Phone 8 ..which is embarrasing. However these new phone APIs are so
> limiting it requires complete app redesigns  and none of them support 3rd
> party servers ( eg Daemons , "services") yet .   I think Unix change is
> hard and that  it requires revolutionary change  ( and on Android Windows
> Phone touch apis force this)  .
>
>
> All I care about is 1.  object capability,  2. open source, and 3.  Some
> place that can grow to add practical value.
>


Free BSD is probably best .. I tried to start openwinrt as i think its a
great api ( and solves a lot of unix problems ) and you can run capability
windows 8 apps  but it floundered pretty quick.

Ben

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.