capsicum(4) 맨 페이지 - 윈디하나의 솔라나라

개요

섹션
맨 페이지 이름
검색(S)

capsicum(4)

is a lightweight OS capability and sandbox framework implementing
a  hybrid  capability  system model.  can be used for application
and library compartmentalisation,  the  decomposition  of  larger
bodies  of software into isolated (sandboxed) components in order
to implement security policies and limit the impact  of  software
vulnerabilities.   provides two core kernel primitives: A process
mode, entered by invoking in which access to global OS namespaces
(such as the file system and PID namespaces) is restricted;  only
explicitly  delegated  rights,  referenced  by memory mappings or
file descriptors, may be used.  Once set, the flag  is  inherited
by  future children processes, and may not be cleared.  Limit op‐
erations that can be called on file descriptors.  For example,  a
file descriptor returned by may be refined using so that only and
can be called, but not The complete list of the capability rights
can  be found in the manual page.  In some cases, requires use of
alternatives to traditional POSIX APIs in order to  name  objects
using  capabilities  rather than global namespaces: File descrip‐
tors representing processes, allowing parent processes to  manage
child  processes  without  requiring access to the PID namespace;
described in greater detail in An extension to the  POSIX  shared
memory API to support anonymous swap objects associated with file
descriptors; described in greater detail in In some cases, limits
the  valid values of some parameters to traditional APIs in order
to restrict access to global namespaces: Processes can  only  act
upon their own process ID with syscalls such as first appeared in
and  was developed at the University of Cambridge.  was developed
by and at the University of Cambridge, and and at  Google,  Inc.,
and






































맨 페이지 내용의 저작권은 맨 페이지 작성자에게 있습니다.
RSS ATOM XHTML 5 CSS3