Re: [security-discuss] Re: [OpenAFS] Hardware Grants from Sun

2007-02-26 Thread Nicolas Williams
On Sun, Feb 25, 2007 at 06:47:38PM -0800, Henry B. Hotz wrote: > On Feb 23, 2007, at 10:10 PM, Nicolas Williams wrote: > >BTW, a PAG facility that's faithful to the AFS notion of PAGs > >should be > >relatively easy to specify and implement for Solaris, but it will be

Re: [security-discuss] Re: [OpenAFS] Hardware Grants from Sun

2007-02-26 Thread Nicolas Williams
BTW, Solaris tasks approach the semantics of PAGs. See settaskid(2). They're not quite what you want for two reasons: a) they're already in use for something else, so you don't know that someone isn't going to change a process' taskid without doing the AFS thing to keep credentials associated wit

Re: [OpenAFS] Hardware Grants from Sun

2007-02-26 Thread Nicolas Williams
On Sun, Feb 25, 2007 at 02:21:08AM -0500, Marcus Watts wrote: > Going the other way from what Nico proposes, why not have a very > general per-module way for modules to add resources per-process? > > There's really only a few points where the "generic" environment > needs to interact with the modu

Re: [OpenAFS] Hardware Grants from Sun

2007-02-24 Thread Nicolas Williams
On Fri, Feb 23, 2007 at 12:03:58PM -0600, Douglas E. Engert wrote: > Jeffrey Hutzelman wrote: > >On Friday, February 23, 2007 09:23:21 AM -0600 "Douglas E. Engert" > ><[EMAIL PROTECTED]> wrote: > >>So getting 100,000 in equipment is only part of it. If you are > >>willing to state a desire to tage