From mboxrd@z Thu Jan 1 00:00:00 1970 From: dot@dotat.at (Tony Finch) Date: Mon, 25 Sep 2017 16:45:49 +0100 Subject: [TUHS] UNIX of choice these days? In-Reply-To: <20170925005702.38377156E523@mail.bitblocks.com> References: <20170923091704.GD10152@darioniedermann.it> <20170924140617.GG28606@mcvoy.com> <20170924203621.GA80203@wopr> <49B7FCB8-A086-4FFB-AF3B-4B3BD167EC54@bitblocks.com> <20170925005702.38377156E523@mail.bitblocks.com> Message-ID: Bakul Shah wrote: > > I think a few changes can make Unix much more plan9 like. > Things like: file descriptors are actually capabilities (or > handles, for short) and each process starts with a set of > handles and it can only reach those resources that its handles > allow. It can also gain new handles via operations on existing > handles. Right here you can see that a process is already > sandboxed. You don't need containers or jails! You can opt-in to this way of working by using the capsicum API, http://www.cl.cam.ac.uk/research/security/capsicum/ but that's really intended for programs to discipline themselves rather than as something pervasive. Tony. -- f.anthony.n.finch http://dotat.at/ - I xn--zr8h punycode Portland, Plymouth, Biscay: Northwest 4 or 5, becoming variable 3 or 4 later. Moderate or rough, becoming slight or moderate. Mainly fair. Moderate or good.