← Back to context

Comment by __MatrixMan__

8 hours ago

If only we had a decent capability based OS. Then all processes would have the property you're after. If you want it to be able to write to a disk, dependency inject a disk writing capability. Need to talk to a remote host, provide a handle for just that host.

Don't want these capabilities? Do nothing, that's the default state.

Unfortunately, capabilities based OSes, or written in mostly safe systems programming languages aren't by lack of trying.

However outside mainframes and micro-computers, or niche deployments, adoption has been a challenge.

  • iOS/macos and linux both support capabilities, now the depth of those capabilities in all cases might lack depth but people are moving in this way.

    • Let's take filesystem access on linux for example. You can run as a user without permission, or you can configure something like apparmor/SELinux to stop the program if it attempts do do something not on the list, or you can use containerization to build a limited world for the program to see...

      But isn't this all a bit adhoc? The fundamental presumption is of unrestricted capability and then the OS provides options for restriction.

      Perhaps I've misunderstood it but I think capabilities are inside out from all of that: You need to walk, so here are some legs. You need to swim so here are some fins. As-is it's more like: you can't go over there so here's an ankle monitor.

Not associated with the project but have been following the development, https://5bsd.org/ could be a good answer. Kory’s been adding capability enforcement for the Linux APIs on top of BSD kernel (among other cool features).

Fuchsia is an “option”, although it doesn’t support much hardware without writing your own drivers.