← Back to context

Comment by pjmlp

8 hours ago

Unfortunately, capabilities based OSes, or written in mostly safe systems programming languages aren't by lack of trying.

However outside mainframes and micro-computers, or niche deployments, adoption has been a challenge.

iOS/macos and linux both support capabilities, now the depth of those capabilities in all cases might lack depth but people are moving in this way.

  • Let's take filesystem access on linux for example. You can run as a user without permission, or you can configure something like apparmor/SELinux to stop the program if it attempts do do something not on the list, or you can use containerization to build a limited world for the program to see...

    But isn't this all a bit adhoc? The fundamental presumption is of unrestricted capability and then the OS provides options for restriction.

    Perhaps I've misunderstood it but I think capabilities are inside out from all of that: You need to walk, so here are some legs. You need to swim so here are some fins. As-is it's more like: you can't go over there so here's an ankle monitor.