| From: | "Thomas E. Spanjaard" <tgen@xxxxxxxxxxxxx> |
| Date: | Mon, 03 Jul 2006 18:36:58 +0000 |
Thomas E. Spanjaard wrote:The granularity of capabilities is actually per 'object', not per process necessarily. You can control virtual memory mappings with capabilities too, and that's far more fine-grained than just per process (which would result in an 'everything-or-nothing' approach because of per process capabilities).When a process P wants an access to an object O, ACL's look at the user who P is executing as and decide whether to grant access. Capabilities on the other hand, will make the decision based on P instead. Correct? I don't understand the virtual memory example.
Cheers,
--
Thomas E. Spanjaard
tgen@xxxxxxxxxxxxx
Attachment:
signature.asc
Description: OpenPGP digital signature