Re: Capsicum: Object capabilities for Linux
Bennie Kloosteman <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAJT18ibSrAJhYSPQX50PHRd5XFMRQohnvA3r0ZVkGgD_2fp8BQ@mail.gmail.com> |
On Sun, Oct 13, 2013 at 2:43 PM, Jed Donnelley <capability-iCFHVraI1K1Wk0Htik3J/[email protected]>wrote: > On 10/10/2013 11:57 PM, Bennie Kloosteman wrote: > > > On Fri, Oct 11, 2013 at 12:58 PM, Jed Donnelley <capability-iCFHVraI1K1Wk0Htik3J/[email protected]>wrote: > >> ...I think I can understand the work involved, but not why the amount of >> work depends on the support of non-support of "arbitrary interposition of >> all operations" in the capability interface. >> >> >> I'd love to hear a bit about how directory capabilities work in Capsicum >> - e.g. compared to the way they work in the Tahoe file system or to GNOSIS >> or any of many other interfaces. Driven by Unix symantics no doubt, but >> how does access right "masking" work when referencing through a directory >> capability? How are links (hard and soft) handled? >> > > > I'm not a capsicum designer but have used it for a month about 1-2 years > ago - just trying to help . Suggest you post the why question to the > capsicum list. My use was basically allow app to do lots of dirty stuff > when starting then turn on cap mode and pass to user and then everything is > via the powerbox. > > This model i think is good because existing apps can become cap apps > quite quickly and then mature. > ... > > > Agreed. I'd just like to find out if (and if so why) the Capsicum > capability model can't be "object capability" (arbitrary interposition of > all operations). If it were then it would be able to do more and would > appeal to another group of people (e.g. like me). > Is it because its C and supports C apps ? > > >> There is hope on the desktop though as Capsicum seems to be the >> default and in the Kernel on FreeBSD making FreeBSD attractive as a secure >> platform . >> >> >> ...I could see spending some time contributing work to such a "secure >> platform". However, if the interface doesn't have the arbitrary >> interposition of all operations property then it would take quite a bit of >> wind out of my sails. >> > > Well the Linux world better get there act together as far as im > concernced, they have a worse security design/ model than Andorid/ Windows > Phone 8 ..which is embarrasing. However these new phone APIs are so > limiting it requires complete app redesigns and none of them support 3rd > party servers ( eg Daemons , "services") yet . I think Unix change is > hard and that it requires revolutionary change ( and on Android Windows > Phone touch apis force this) . > > > All I care about is 1. object capability, 2. open source, and 3. Some > place that can grow to add practical value. > Free BSD is probably best .. I tried to start openwinrt as i think its a great api ( and solves a lot of unix problems ) and you can run capability windows 8 apps but it floundered pretty quick. Ben _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk