Re: Joins on capabilities that have passed through different membranes

Kenton Varda <[email protected]> Mon, 4 Jan 2016 19:05:30 -0800
Newsgroups gmane.comp.capabilities.general
Message-ID <CAOP=4wjWCmX88s6NcOFQA5JybGd4DCoWAR5ZeC_eZpg_rcmV5g@mail.gmail.com>
--===============5165119676256758629==
Content-Type: multipart/alternative; boundary=001a11431cc6c20ff705288d8308

--001a11431cc6c20ff705288d8308
Content-Type: text/plain; charset=UTF-8

I've heard of the "Ask Bob Protocol" mentioned a few times in the context
of capability equality, but I don't think I've ever heard exactly what it
does / how it works. Is there a good reference doc? It seems hard to Google.

-Kenton

On Mon, Jan 4, 2016 at 6:24 PM, Bill Frantz <[email protected]> wrote:

> On 1/4/16 at 5:53 PM, [email protected] (Kenton Varda) wrote:
>
> I'm interested to know if you've thought about the following problem:
>>
>
> I see a number of possibilities here. Lets assume that Alice's cap is A ,
> Bob's is B, and the underling capability is C.
>
> We can have A merge B, B merge A, or a separate merge utility M. M can
> either be in cahoots with the Revoker front ends Ra and Rb or not.
>
> If R has the authority to look inside other instances of itself, Ra can
> look at Rb and determine that the Ra' C is the same as Rb's C and "Do the
> right thing"tm.
>
> If M is in cahoots with Ra and Rb, it can perform the same magic.
>
> If all are independent, there may be some varient of the Ask Bob Protocol
> which applies, bringing C into the act.
>
> I would say that if either A or B is revoked, then M should not perform a
> merge. (I hope A or B are revoked enough that Ra and Rb can't perform a
> merge either.)
>
> The life span of the result of the merge D is interesting. If it has the
> same authority as A or B, then either would do as the result of the merge.
> If it has more authority, then A and B represent something more than a
> revokable version of C.
>
> Cheers - Bill
>
> -------------------------------------------------------------------------
> Bill Frantz        | Airline peanut bag: "Produced  | Periwinkle
> (408)356-8506      | in a facility that processes   | 16345 Englewood Ave
> www.pwpconsult.com | peanuts and other nuts." - Duh | Los Gatos, CA 95032
>
> _______________________________________________
> cap-talk mailing list
> [email protected]
> http://www.eros-os.org/mailman/listinfo/cap-talk
>

--001a11431cc6c20ff705288d8308
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gmail_quote">I&#3=
9;ve heard of the &quot;Ask Bob Protocol&quot; mentioned a few times in the=
 context of capability equality, but I don&#39;t think I&#39;ve ever heard =
exactly what it does / how it works. Is there a good reference doc? It seem=
s hard to Google.<br></div><div class=3D"gmail_quote"><br></div><div class=
=3D"gmail_quote">-Kenton</div><div class=3D"gmail_quote"><br></div><div cla=
ss=3D"gmail_quote">On Mon, Jan 4, 2016 at 6:24 PM, Bill Frantz <span dir=3D=
"ltr">&lt;<a href=3D"mailto:[email protected]" target=3D"_blank">frantz=
@pwpconsult.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" =
style=3D"margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:r=
gb(204,204,204);border-left-style:solid;padding-left:1ex"><span>On 1/4/16 a=
t 5:53 PM, <a href=3D"mailto:[email protected]" target=3D"_blank">kenton@=
sandstorm.io</a> (Kenton Varda) wrote:<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;p=
adding-left:1ex">
I&#39;m interested to know if you&#39;ve thought about the following proble=
m:<br>
</blockquote>
<br></span>
I see a number of possibilities here. Lets assume that Alice&#39;s cap is A=
 , Bob&#39;s is B, and the underling capability is C.<br>
<br>
We can have A merge B, B merge A, or a separate merge utility M. M can eith=
er be in cahoots with the Revoker front ends Ra and Rb or not.<br>
<br>
If R has the authority to look inside other instances of itself, Ra can loo=
k at Rb and determine that the Ra&#39; C is the same as Rb&#39;s C and &quo=
t;Do the right thing&quot;tm.<br>
<br>
If M is in cahoots with Ra and Rb, it can perform the same magic.<br>
<br>
If all are independent, there may be some varient of the Ask Bob Protocol w=
hich applies, bringing C into the act.<br>
<br>
I would say that if either A or B is revoked, then M should not perform a m=
erge. (I hope A or B are revoked enough that Ra and Rb can&#39;t perform a =
merge either.)<br>
<br>
The life span of the result of the merge D is interesting. If it has the sa=
me authority as A or B, then either would do as the result of the merge. If=
 it has more authority, then A and B represent something more than a revoka=
ble version of C.<br>
<br>
Cheers - Bill<br>
<br>
-------------------------------------------------------------------------<b=
r>
Bill Frantz=C2=A0 =C2=A0 =C2=A0 =C2=A0 | Airline peanut bag: &quot;Produced=
=C2=A0 | Periwinkle<br>
<a href=3D"tel:%28408%29356-8506" value=3D"+14083568506" target=3D"_blank">=
(408)356-8506</a>=C2=A0 =C2=A0 =C2=A0 | in a facility that processes=C2=A0 =
=C2=A0| 16345 Englewood Ave<br>
<a href=3D"http://www.pwpconsult.com" rel=3D"noreferrer" target=3D"_blank">=
www.pwpconsult.com</a> | peanuts and other nuts.&quot; - Duh | Los Gatos, C=
A 95032<br>
<br>
_______________________________________________<br>
cap-talk mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">cap-talk@mai=
l.eros-os.org</a><br>
<a href=3D"http://www.eros-os.org/mailman/listinfo/cap-talk" rel=3D"norefer=
rer" target=3D"_blank">http://www.eros-os.org/mailman/listinfo/cap-talk</a>=
<br>
</blockquote></div><br></div></div>

--001a11431cc6c20ff705288d8308--

--===============5165119676256758629==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk

--===============5165119676256758629==--