l4-hurd
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: cap exchange race with map/unmap


From: Espen Skoglund
Subject: Re: cap exchange race with map/unmap
Date: Tue, 18 Oct 2005 23:14:39 +0200

[Jonathan S Shapiro]
> In the absence of any authority to fabricate new capabilities, the
> following chain of mappings is now in effect after the exchange:

>       RevCopy                RevCopy
>    A ----------> CapServer -----------> B

> If process A now exits, all of its capabilities are revoked. In
> consequence the Cap held by CapServer is revoked. In consequence the
> Cap held by B is revoked.

> Can somebody explain what authority or feature in the system design
> gives the CapServer sufficient power that it can create a capability
> that does not depend on A's continued existence?

If CapServer can identify that it posesses an identical capability it
can map this capability to B.

        eSk




reply via email to

[Prev in Thread] Current Thread [Next in Thread]