Re: Joins on capabilities that have passed through different membranes
Kenton Varda <[email protected]> Mon, 4 Jan 2016 19:05:30 -0800
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAOP=4wjWCmX88s6NcOFQA5JybGd4DCoWAR5ZeC_eZpg_rcmV5g@mail.gmail.com> |
--===============5165119676256758629== Content-Type: multipart/alternative; boundary=001a11431cc6c20ff705288d8308 --001a11431cc6c20ff705288d8308 Content-Type: text/plain; charset=UTF-8 I've heard of the "Ask Bob Protocol" mentioned a few times in the context of capability equality, but I don't think I've ever heard exactly what it does / how it works. Is there a good reference doc? It seems hard to Google. -Kenton On Mon, Jan 4, 2016 at 6:24 PM, Bill Frantz <[email protected]> wrote: > On 1/4/16 at 5:53 PM, [email protected] (Kenton Varda) wrote: > > I'm interested to know if you've thought about the following problem: >> > > I see a number of possibilities here. Lets assume that Alice's cap is A , > Bob's is B, and the underling capability is C. > > We can have A merge B, B merge A, or a separate merge utility M. M can > either be in cahoots with the Revoker front ends Ra and Rb or not. > > If R has the authority to look inside other instances of itself, Ra can > look at Rb and determine that the Ra' C is the same as Rb's C and "Do the > right thing"tm. > > If M is in cahoots with Ra and Rb, it can perform the same magic. > > If all are independent, there may be some varient of the Ask Bob Protocol > which applies, bringing C into the act. > > I would say that if either A or B is revoked, then M should not perform a > merge. (I hope A or B are revoked enough that Ra and Rb can't perform a > merge either.) > > The life span of the result of the merge D is interesting. If it has the > same authority as A or B, then either would do as the result of the merge. > If it has more authority, then A and B represent something more than a > revokable version of C. > > Cheers - Bill > > ------------------------------------------------------------------------- > Bill Frantz | Airline peanut bag: "Produced | Periwinkle > (408)356-8506 | in a facility that processes | 16345 Englewood Ave > www.pwpconsult.com | peanuts and other nuts." - Duh | Los Gatos, CA 95032 > > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk > --001a11431cc6c20ff705288d8308 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gmail_quote">I= 9;ve heard of the "Ask Bob Protocol" mentioned a few times in the= context of capability equality, but I don't think I've ever heard = exactly what it does / how it works. Is there a good reference doc? It seem= s hard to Google.<br></div><div class=3D"gmail_quote"><br></div><div class= =3D"gmail_quote">-Kenton</div><div class=3D"gmail_quote"><br></div><div cla= ss=3D"gmail_quote">On Mon, Jan 4, 2016 at 6:24 PM, Bill Frantz <span dir=3D= "ltr"><<a href=3D"mailto:[email protected]" target=3D"_blank">frantz= @pwpconsult.com</a>></span> wrote:<br><blockquote class=3D"gmail_quote" = style=3D"margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:r= gb(204,204,204);border-left-style:solid;padding-left:1ex"><span>On 1/4/16 a= t 5:53 PM, <a href=3D"mailto:[email protected]" target=3D"_blank">kenton@= sandstorm.io</a> (Kenton Varda) wrote:<br> <br> <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-= left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;p= adding-left:1ex"> I'm interested to know if you've thought about the following proble= m:<br> </blockquote> <br></span> I see a number of possibilities here. Lets assume that Alice's cap is A= , Bob's is B, and the underling capability is C.<br> <br> We can have A merge B, B merge A, or a separate merge utility M. M can eith= er be in cahoots with the Revoker front ends Ra and Rb or not.<br> <br> If R has the authority to look inside other instances of itself, Ra can loo= k at Rb and determine that the Ra' C is the same as Rb's C and &quo= t;Do the right thing"tm.<br> <br> If M is in cahoots with Ra and Rb, it can perform the same magic.<br> <br> If all are independent, there may be some varient of the Ask Bob Protocol w= hich applies, bringing C into the act.<br> <br> I would say that if either A or B is revoked, then M should not perform a m= erge. (I hope A or B are revoked enough that Ra and Rb can't perform a = merge either.)<br> <br> The life span of the result of the merge D is interesting. If it has the sa= me authority as A or B, then either would do as the result of the merge. If= it has more authority, then A and B represent something more than a revoka= ble version of C.<br> <br> Cheers - Bill<br> <br> -------------------------------------------------------------------------<b= r> Bill Frantz=C2=A0 =C2=A0 =C2=A0 =C2=A0 | Airline peanut bag: "Produced= =C2=A0 | Periwinkle<br> <a href=3D"tel:%28408%29356-8506" value=3D"+14083568506" target=3D"_blank">= (408)356-8506</a>=C2=A0 =C2=A0 =C2=A0 | in a facility that processes=C2=A0 = =C2=A0| 16345 Englewood Ave<br> <a href=3D"http://www.pwpconsult.com" rel=3D"noreferrer" target=3D"_blank">= www.pwpconsult.com</a> | peanuts and other nuts." - Duh | Los Gatos, C= A 95032<br> <br> _______________________________________________<br> cap-talk mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">cap-talk@mai= l.eros-os.org</a><br> <a href=3D"http://www.eros-os.org/mailman/listinfo/cap-talk" rel=3D"norefer= rer" target=3D"_blank">http://www.eros-os.org/mailman/listinfo/cap-talk</a>= <br> </blockquote></div><br></div></div> --001a11431cc6c20ff705288d8308-- --===============5165119676256758629== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk --===============5165119676256758629==--