From: bakul at bitblocks.com (Bakul Shah)
Subject: [COFF] The MOO problem and set-uid
Date: Thu, 30 Jan 2020 13:51:03 -0800 [thread overview]
Message-ID: <D013943C-153D-4658-B4DC-9374998714FF@bitblocks.com> (raw)
In-Reply-To: <alpine.BSF.2.21.9999.2001310720340.15513@aneurin.horsfall.org>
On Jan 30, 2020, at 12:25 PM, Dave Horsfall <dave at horsfall.org> wrote:
>
> Thanks, all, for the responses; it was driving me nuts! I know the game as "cows and bulls" (or perhaps that's because I'm of British origin).
>
> I like Dennis' observation: "On the other hand, suid these days seems to be a fairly blunt and dangerous instrument". I've often believed that if you thought you needed set-uid (esp. to root!) you can probably get away with set-gid instead.
Capabilities[1] (Dennis, Van Horn, 1966) would have solved the MOO problem.
And the CAP computer project had already started in Cambridge!
[1]
https://www.princeton.edu/~rblee/ELE572Papers/Fall04Readings/ProgramSemantics_DennisvanHorn.pdf
Re-reading this papers decades later it is interesting to see that
the modern object caps are basically not very different from the
original concept! Also interesting to see fork() here.
prev parent reply other threads:[~2020-01-30 21:51 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-01-28 22:18 dave
2020-01-28 23:01 ` bakul
2020-01-29 14:50 ` dot
2020-01-30 20:25 ` dave
2020-01-30 21:51 ` bakul [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=D013943C-153D-4658-B4DC-9374998714FF@bitblocks.com \
--to=coff@minnie.tuhs.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).