3 ms·
"but can you even pass a file descriptor across a file descriptor in plan9 the way scm_rights lets you do in bsd and linux?" No, the mechanism was even simpler.
by nrr 2y ago
"but can you even pass a file descriptor across a file descriptor in plan9 the way scm_rights lets you do in bsd and linux?" No, the mechanism was even simpler. We had the #s device (usually bound as /srv) for this, whereby you could drop a file in /srv containing a single integer representing a file descriptor, and other processes could open() that file to get another reference to that file descriptor.
My mandatory access control experiments abused the fact that I could have open file descriptors and barely anything bound in the namespace by the time I exec()ed what I wanted to run. What files did those file descriptors reference? You didn't need to know, and you couldn't see them.
- kragen 2y agothanks for explaining! that sounds like, as long as the confined process couldn't mount more devices, it could definitely work, with a whole new set of core utilities that looked at predetermined filenames in the filesystem rather than taking filenames on the command line the #s mechanism sounds considerably less horrific than scm_rights
- nrr 2y agoYeah, that was the subtext that I left unsaid through this. rfork(RFNOMNT|RFCNAMEG) got you both a completely clean namespace and a namespace that denied additional mounts (as well as dereferencing pathnames beginning with #, as in #s). The Plan 9 primitives were refreshingly simple and consistent.
- kragen 2y agoi see, thanks! were you working at cisco at the time? i remember they were having a hard time sourcing video cards with plan9 support because nobody had added pci video card support to it yet i feel like plan9 still tends to pass a lot of ambient authority to new processes by default
- nrr 2y agoNo, I've never worked for Cisco, but I did have my own firewall product at one point. (: That's another story for another day though. Plan 9 is, at its core, still an ambient authority system, and I will never try to misrepresent it otherwise. That said, I've found it does an admirable job emulating what a "familiar" (in the sense of not looking completely alien to someone who only knows ambient authority) object-capability system could look like, kind of like how you can emulate the free monad in Ruby despite it not being a functional programming language. This is possible principally because the mantra of Plan 9 is that everything is a filesystem: if you can bind it into your namespace, you can access it. As a corollary, if you can't bind it into your namespace, you can't access it. It makes shaping one's ambient authority a remarkably productive endeavor.
- kragen 2y agoi appreciate you sharing your knowledge!