Re: Plash source code; powerboxes in shill (was Re: Shill: capability-based shell)
Scott Moore <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CANCm3+KkCT+99LL3_sFiUz49i5-LU7YCC6f2mFUBt0oOj9PXcg@mail.gmail.com> |
We don't have support for this currently, but adding the functionality to our sandboxing mechanism would be fairly straightforward. The reason we haven't done this is that we would want the ability to add capabilities to other processes to be controlled by capabilities, and we haven't implemented capability-based restrictions on inter-process communication yet. (The current enforcement mechanism is that shill-controlled processes can only interact with their descendants and parents, and may not interact with other processes (other than through capabilities controlled by Shill, i.e. files, pipes, sockets, etc). On Thu, Sep 25, 2014 at 5:06 PM, John Lee <[email protected]> wrote: > Is the plash source code still out there somewhere? > > I think plash provided a way to replace standard desktop file dialogs with > powerboxes in its (chroot) sandboxed processes (via LD_PRELOAD?). Does > shill address the problem of dynamically granting authority in sandboxed > processes? > > Have only scanned the paper, so sorry if this is answered there already! > > > John > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk > _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk