diff --git a/3-cap.typ b/3-cap.typ index c4e416e..0ab1e14 100644 --- a/3-cap.typ +++ b/3-cap.typ @@ -6,10 +6,12 @@ // define a capability Capabilities are the atomic unit of security in Twizzler, acting as tokens of //NOTE: point forward towards security contexts? -protections granted to a process, allowing it to access some object in the ways -it describes. Colloquially a capability is defined as permissions and -a unique object to which those permissions apply, but in Twizzler we add -the signature component to allow the kernel to validate that the security policy was created by an authorized party. +protections that allow a process to access an object in the ways it describes. More +information about how capabilities interact with processes can be found in section 4.2. +Colloquially a capability is defined as permissions and a unique object to which +those permissions apply, but in Twizzler we add the signature component to allow +the kernel to validate that the security policy was created by an authorized +party. Thus, a Capability is represented as follows: @@ -20,7 +22,7 @@ struct Cap { accessor: ObjID, // Security context ID in which this capability resides. prots: Protections, // Specific access rights this capability grants. flags: CapFlags, // Cryptographic configuration for capability validation. - gates: Gates, // Additional constraints on when this capability can be used. + gates: Gates, // Constraints on where permisions are applied. revocation: Revoc, // Specifies when this capability is invalid, i.e. expiration. sig: Signature, // The signature. } @@ -30,9 +32,9 @@ struct Cap { == Signature The signature is what determines the validity of the capability. The only possible signer of some capability is who ever has permissions to read the -signing key object, or the kernel itself. The signature is built up of a array with -a maximum length and a enum representing what type of cryptographic scheme -was used to create it; quite similar to the keys mentioned previously. +signing key object, or the kernel itself. The signature is built up of an array with +a maximum length and an enum representing what type of cryptographic scheme +was used to create it; quite similar to the keys mentioned in section 2. The fields of the capability are serialized and hashed to form the message that gets signed, and then stored in the signature field. Currently we support Blake3 and Sha256 as hashing algorithms. @@ -51,15 +53,16 @@ memory access. // something to think about == Flags -Currently, flags in capabilities are used to specify which hashing algorithm to use to form a message to be signed. We allow for multiple algorithms to be used to -allow for backward capability when newer, more efficient hashing algorithms are created. - -The flags inside a capability is a bitmask providing information about distinct feautures -of that capability. Currently we only use them to mark what hashing algorithm was used to -form the message for the signature, but there's plenty of bits left to use. -We hope for future work to develop more expressive ways of using capabilities, i.e. Decentralized Information Flow Control, as specified in -6.1. - +Currently, flags in capabilities are used to specify which hashing algorithm was +used +to form the message that was signed. We allow multiple algorithms to be used +to allow for backward capability when newer, more efficient hashing algorithms +are created. + +The flags inside a capability is a bitmask providing information about distinct +feautures of that capability. Currently they only convey the hashing algoritmn +but there's plenty of bits left to use. We hope for future work to develop more +expressive ways of using capabilities through the flags. // maybe worth discussing delegations if only to describe how they could be // extended from capabilities (as a future work ofc) // diff --git a/thesis.pdf b/thesis.pdf index e2d46478c2860360b36a5250c634720bf4892a91..5bc4a50e8ab9ff7b38904518983f06487cdc1233 100644 GIT binary patch delta 5431 zcmX@Gk8RdIwuUW?*Cm;aEDfhO7BZ^T-<65Yzq8}x-Th8|d-ugw`*zmuA=o3L zXtJ>C`{$$e`YH9!VcP`5Dzj@pg|k!?fBYbyUjOUImk9|4P#&yl3Z7=Sg$XwqMTqeYQ zt1Zhuv8TYQb-APejrG$V-!qv0^*=tv;5>h=>7mM5hFKo}3m?3HAJkN9)p=~Pj8*kZ z_E<62M1`p)A-epb7cNUo?aN)(&#rNU zvgQsys*iL&zIl7SN3%+N;0+tANbX2 z-SO4q7w5wBe@c%hHF`br{17d8|7lq7@^|*DTRzBhS1ryoKfU?GM78#i&0+5*{C;4hlwCzqi=)j8R!Z;0#>t?-P z^EBt=)KKM^wNmr-mTqQXTq|~}PT;9*^67h>$5_%|PUu@>CjWuu{rPM89T$z`xEE?L zt4dlunf1L>d4iIG_vZIpj7{79J09~-w*Jd!DYh*A#0<6`gA#wG37Yk3lOFKYo?N&; z`r6^B-D<+TQ9IUrbF5jlkf&XKeb=1&4ITL&&7OyN6mpNhF1i@pD}3x`&P7$8_iz`YeozAhH?ah5AKq33)cxaqh&*&%YK;N(|!(=YAILQD~qM(B^fMeYNeq%R5x>7hC1o zI@j-d_+|61{+SowtYkR6cDbzlLNT|UCUa8r8Xdya@9<4<0Jq%s8Tj}hVvS*Slh41!BEIhrIwczdP#er)5PP|OVDt9ESRvmq`;@St7Ct)H- zR>yp(_L_3m>QdgNm8J`uEq7&JI=y_=BrdlrZil$8Z>SfGJO3lj_tLzi5~oI)ne|SF zT>^z%o1E>LO78{Ozq`gFuX69sykD;wZ)!>x{YtE#|HNmi@8dY<6&la><^1~a^09w^ z?a>gH#Y?}P3f&rTN;>-Zsq8<-JKl9maj)9NrKBBnZK|-|4Y%satJlrF)>x%Ar7ygC zm;H6w%~E+*{nH9p)^kowt=d&7=(!`PcjBepeXIZRKYkp)Z}&C5`3JhKc4YKk;rTxK zZ0FQ3QKH(mTR(PxX>xSbkYBUq$qN3KtjG1rOI|xzPhEGh=kYofPcN>U8j=A#VH3uj6B?npS&aVGrlXXGFDnag7FW#PFhay{Z#hLHEgG2_~(6ZKe^Vtl3R7K z-pC}eJW}NF_1A9S53I94FV||c_|7Jl)a%nWWlQAUOP9N{D5323x{gRb1?P7^@6?&H z^Dyk06m{-y&7F|d$4vDfaWq)o)&q94`#jQIW7yj z=WKKm&dx4tEn8 zTz~z+zdhGQIvR|_w=U~E>L!`ZqyK2Of>rD!jjqs`V>cgd3qH=Y(a0#A`awZ0T@dq_u*7t2!-t=gXVz2Vi zb(1fDYOL6Oqm9?_n|yn^!rL{^);>|$=5Q)1yUACKKb7&x^S71n{ia^}FQT3I^4kpG zRX5Ix%zKlw((-7_jtYzC0r{tX>Xv=KbfaTu*{t&IGAb{x-V$fLoAJ74GN)<5w>n{q6wtL({X4(PF>K54yLt;Xvn!hw=3QHM zWkhGBw$!TgH|2B7COO`mPn9zw#ek^WHY)Im5r-{BkDs zL5X)o6rMEQdC%ZzS&>^;rP2j4xtN0yADFc* zb#I47tPcHtWV5ea-l||Hd9{1N56h0mFI}1_W>m3zNd(8w7*ES1QB`V^PLCLPXXSpb zRl8ny`po;&2^!h^ar5*>S*&Q2;c?``-Cn_$K0c8m zZJ}Ks`95zrbL7&TtjXtRWaPvt_h#@aPn&vwxpKzr7whLQ)chX!>-^p0uXz|Vq|@ij zJIAPgqy1<4nWTBA<<;Npx>1rBE3k_5U60qBr^}4qL^Qj7z4phqUOZ;*RWrvc=Txf? z+ow&t^UTzJWlMZw{7dwxC(AdDL^F($-l8mOVprhQwh%?b91+#K&UWy!LpOLBL z<^1i>0bWzVKMSm#zTW z`DV{oNqy5i{YZ?;3_d}zX`c1!yRUBZjFAx!P0GAs>UZ5ot1B<~{5IzfNAdqY5(m{~ zk0_*h?um6jepN`KFgc~Y)S6?_%cw)}|3lH?S$9Oir*@NdSNaXV`+9{lb%Qy0EN?hRmVD{1yL4tp>b7SE zhAI=A)p})(*aQStoRyqpDe%dTSNHS6Lwoq29X+wvLdBeU^N9q-g5ao`=8S)gUnEU5 zn)6@pLQ4H9Hiu0cqHV9O5qol}yEf)}(A83zLq(D6SC+5rmB^|8@@(3-)G#M?TXu$> z{xQ2kYOI$DRC03c6=PHrEoi-yy!i2ph>Fji?=~%%wbd$l&N404&Zny;b4Qu@S}gzn zJ}vm_%IPn5bkDnY(8})Xh8@3tc+4y3+sF0pOpy9tH|6!a^Xji(wyv%-_KZ?o@7&#@Vy!nm2=yB zw+?@+^IQE@txG?vNj<#9?7cqw;iN64k2R-=Z>l!Dd#X2?EmlCQCAN}b>CTV!jMXyJ z8n3S3(R8>V{v7ku7v?YL){Bbd*iX<{sbXrt5m@nGr9pev*K3~hH8M_#d(2yAImtm- zVzISi(oM_ttd$4<_lPfR43!qp+k9odQC-<%hWKz>YYQ{&_6^_f&!5HhZ_)CCA0`u@ zWYmUV5O8}Tvcgb_MSfL4`TEpVlh-``nt9+qBWuvb|6HkgDa9p4sfoEY8s?q9*g#<4XYD;EC)p-SNH^zx+i~e#;?li^E3UMMEY0$NyU_OQ z{p$$^^Ab5~HM-6wKbxI@?6ah|+MV|rcN4TvuFci4wpBg4cb$CvyL&fYnhL)8`elwt zJ?rF2Tlr7EH=DS4dgcx--?cN%VnPnZZt*{P^sHTLZr+u8TY>wMpui#(Y5!$NEh6%}+(&wZDn+eXTGlVEdc4t^X(4>rRMzYcuys z*5NgedN+4%`L_1oS(yd_)$nll*SXp^xI^7evl!?axv;)U`|we9N~nwE(K_}`M-4aso9BM+$UE+HOf1Y+ z7iCNzi_K`_Z>pbmF6pew-Lv!WPq?^u-e$*NA;L$MOpe^2^O>P^0bgv1^mN~+=UR^$ zX{(rr%~;v~-o3s2v7oKY&+3{6ZiJZElV42imWq~u|4 zW`L>C9MckWOG6CbSs0jLc*MfU2sx<1A#Gu7f)d4`@VB%uF^9MY$uSmYW*EU`fhC$O zEHN#yG%&$%prw&9hGQ&^E$cBXu{6c>ouwIO7PmAvL-C1$fq|u^g(X^)7#bKDpr?LA z0|O&y@Eg>_a;KqzfiZdz8X6dwSYR4xW{Q?Q4Gj#;QBt*mfq|icfrTZS=L`)D4bVcm z9+Y8?4A6qc(7@0bJ-7@F3{6ciEH*Sn&z^<`hGwX7404Pi76%$xm>Eo8F^|#H0BdpV bXltvfpn+9ty5f9BF-`+>V=h%ySARDE(KN?; delta 5472 zcmbQWkL|!dwuUW?*Cm+@Ev6g#F{;+zl{uX!v-9J+^%=Hq^Dg#SoHe($R4JIC5TU@X z&eo(d_wcF4?_1cCes8MZ|HgcEgi3W<%IP?Xc@vK$ZM>%=wt9B>*8ks6{A~}OV|jhY ztGnmJ|L=eFmtlR$;Vm1YZa+}x|M2Y95BtUSzkWQ{zq;E$y!7kKyX~tV$5*I^eEs(K z>g()qV&ye9{(>}d}Y*q+9v$l%*FB}`B)DZ z&uyc_<=P&foZ>?^xKB(eUil(lIWa21M|o0!3PaR04vDfEjw>!KNlW>=t-efHua)P+ zFP;7kpMTt1+skuNb7r2Go}N@%*2Nn~k2WsI&QMCe!*OlvoXq7ti=B0(_Nh-X))dI; zTew*yNx}6XOIb9NvfGKf;u`l=p3i$Ym4i_d6Ej9k;@8m%8n1HfV18vNfd4 zzMkjYmM47tCp$w|OkESO(xbgm??ib0q^>4Umy_aC6HmP;*nRhWn9Ph#<)ztEOcqHj z5>&a+$KlE}DRhp^GQnG}XWLIiY||CA3gYx^TYo`Z;KVAC2TBt!W-eF~VI6nq)9NA7cJ8G%>LdHuNy&0xgJKH0x;MG5a@l<=p#b zN8aEUG{3B$KKB;qYEDP97yS;izh99z&raf3yjZ*E4&Tg7qeovZ|Fb+jbCv$jnr=@0 zXZ!Y*{Q2^6`SN{Rj?9@96P37X7H8trb+w(R{=e|~Uf(UD?Z2r=XVtSSQxlK9bc+&Q zy>9N}THEj`$MS7^^;u`FxFNbu*>dx_%4sj3PSe$U;APTPoNcx4m;98k_BY?{Hv7ml z?drLT>?L6pb8`FEE(zzpwj=7M(%ytg$%m}Ynp(bQUKsU1{^y_F%x^<>xf!c{^_`?* z@woSao@#|)#p4A}>JK*0Q~JAZ+PUM#DaM-&b6af{zrK+9Yu+9=YnoG#R%7DJdvi)$ z|F-Zpa-ZHYE#^YWc|(oBtgmUAp~^=(W9$>nn{yavp4rp2t*=i}a6(*+Vt_6C%#&;n zCBpv8B<f?HAl7H#+8pq%Z3#yMSihbXAI4JbT zaoeX09$tLu8dEuqZ`18WKEo-WTvTUdt$F;4)n=li?P7sP=U<3;rP``3Y_UmI)=pu& zyZuzqWR7dMR~jH1m{<^WL@B#wPCl&(GPETT~yxi`h2(h!ZRA%blh%kUG_$*ZT9zx>{~Tv z*ly8In#OoyLbcuYcwI(jhV@I#p5|SXU*(!SOT1wF>lvSxi+{A3t(dZQcJ1+Z&&v%B zqlN0{+6Re=&PuY|sFJP2ulVTA%&srH6pq$(vE5!jFG6pIfTGN^slt1hL~PGa^53~q z-`cF#>{Du&IwQY>a>GZnRGkvntJ9ln6#eHvIJJ-CwRTdZe;KQjrvE?RXEXh$9IcPG zn;fOs!Ld_UKkTVN#r6;7?8l}z>pHW<>}WNMO=tXG&)O^g(YK&u>HFACs*hVX|1@6r z*9^{gTu4 zY*GF*Yp!g1|N8B&xSc6V`!q8n*8a^sbxG6uRaKtQ0^Y0fFJInr-MsOC|MhdpduH8A zJ-+S+zrma5I$X#Qm{jJ`Q zPUkK<%hJA1N3&|~oKw@^=WhJZmGs8G?7YJ**SCoWx8}D^*?Nsd+N!UT@ksga!ukNw zOZ9!C+dIwX1cx|ojTOuLKK1kLcEd(*yJ+G0m*k3bQ*PZ&ny^4RXLdcS$>O!krK47K zcB`kK_@NY=WXN8{I=!&_c&?=S&3jyqo6}~zGivkbC|fk=-|~HvMc=mYtD02m&R6L8 z9JMHDo2~Ai&gX9no^%B)xDfg&dj3hSiy7N3-Wk7{Fz2^)VfgHx(@Y!}ws15x`<>f4 z)0x{+rq#k?kAAO5!J`}MNy5*9>jSd(ST}bawmIW8h5brFiHFhw+nEc+*Qsc~6OZ$* z^)3?^)ySK_zEV@R%A-|Pcr%C0`@oVO|5?cgB~8uOCZqIVwnyuB%OfAJu{mBVH&_DBJi6Q25x3f2ir68Y*TZfj`QsjNBQRIhO^kK6Yphm0bNWs=+Em&Qr@m)gCj zPMZ+6C`Dw)+^iXo&mEb$yl?8&AlZ|;9|gR_>MJ*{@y<7X=;)->mX_b+;g;0Zq_sx5 zN4d!=iA6{Er@_x7okyOTUh3GUoHY4IvPJW@&VRp+O`h79$k)HMi*x625U)J+@}*2( zo2_2`F`fEjC%-2i)7xzO;?|EjYYU$>MZNs$*?MWCSC7`BkJ3y*Qv>c=gh>m}x%W>b zvPe3db!S41N4hcpgyjdgB2EZyNS4vi6?Bw)sIg2@$imlTehJsq!ydvDXK(WLw^^9g zIRA|6in{y#Z_WiAHeM>m@%paoGQ;+~AGd{<-sv=&pw_0zS>G71a`&O4`{i59J%ztb zoOYyW-Tc#kT5~Ub$lIRFBz}AjFPy7qy70vGw1b;f@5vbdUX&G{#kD%=q}Pk)V^0)XfqrueuDe zW+xgRs=v^yw{KOPwfkEC6VEP9Uo$6T#q6X@`BReJ+QZEPf2HnDpMEz*@%Iyt*|qk* zSzdGAI!#!^`&8SIBY6IszDJUMm-$uo7Uyy`DzaNYa}B?^CgVqk@y@5SE!HVMS3?Ty~gyYkxw zl=K)EZdW<5gz4Rc=$sNwE3WsBov~seo5Rw3J_qeoF^n%Y^4qkmaC*s$yYoXzU#VKn zTlBoXJiL$JQKVe{^~uf0TJn$Y+Hu8m-wltlx}-Z_R!zKrc9PhM*8&Q%GX*ZZ+$wNt z_a&Dn_vUdbZZ2PBn0@hHw}V-;<&oWDJp9%PN3J+!dn;r-^Sl}pm9u<$*?G}0o!`ZV zqL-v@S#?Yd758eLd+5|G$;b-(rRz(iBelDgVjWrDPqUh^jV+ID`Tg_00{dUxmD!i9Vi|S+voVX3m0^}h z@wr{6uHM}}`<24O4ze*RA_Eb7x=l^fsMgtg14JYx1la z?ceNv*Vza=ota)%ZTIIv(T$Z_^*u`KH>T~nwnDu2x^C+B4S6?@s`k#Ux-(VP>d#K! zYOTlXul%XAw^zJf^OQw_>xkQ3^Oqgv=ef9c+U@>pqW#saG^W;m)yFz}Jw|z_9gHbA zFLxK{v3=gQdGgd70$4Lt#Me5V6F3z4Jux5!! zS^2y@&+eaHX*@rdcUe#N(nlZJo;uCp;cQ}_c#}tC^5oZQX(BhZ9-Wd{*q_g*yrA>1 z&(R+Oobz^FIAf3=zPYecmY37zv+>m3XMHsu2HQrxS$~=*PP=rU#hu&kPqQzq{h%e6 z;={sK-M}3GtN!PY#?yBX+AC^F_qvD&x2k6UQL{T%oFZ~PCL_vueMMUC2PuYK9|f$h z)!hEZQTk(F_p6<2%H#6)G%%$%FE0M;d+6t0hr-R%@^im7Uzh2#Fj#vny)|~mrS9z; zr*02yf1kT1uI_s2n))p#xSP_o8+f;`KU!t;`m@oIN1__nJGXWl_e!Kb_hOi}Qp`mB z@vcOthUmPvi>|)iZY*o}#ozJt8bk5iwI-KZl9qNxy}9Sh)&Hx^{3<9FZ-1uAn3K$6 zWMFDBJ*<~e0nFN7)ywF`B%0!478y`j6<*>TVxF5_>7SctmQ^zSW)AU}Xf*xaB*u;P#+F8ClICW{ z1_o$i76!(qhUj9(24?2yVx}gB=$2VnSem1YS(+G|g6$PBFhID<%*4=eyWA8;HYO$u zlkIBL7@soNn;M&-*V_|N95nL8nqRGM%(-KPq3k(NZ8ku7_#?r*N9>Wq#Q%v7knqg*f zOA7-OpBNYzSXx>dp+$+Ifq@}<>NhknFoFiZK|L&Y8X6cFqX(g(fq|(Zrh#VYMT((; zfdxvcHUQabU}=ozIYR?OL$r{tH!w6XG%`U88bbp^WAxxMG%z%^Kr0sv4GhiDvnNOl zHI6}!F~s6PBMVE5=}q$(J^is3$BwqPnhF{?rDD14?6`_c5{pVIic-_K3=ND84Gp