[cap-talk] Userspace virtual machine for running guest code

Baldur Johannsson zarutian+cap-talk at gmail.com
Sat Nov 29 23:08:21 CST 2008


h'lo cap-talk
I recently came across the vx32 user space virtual machine library
that enables an host application to run untrusted x86 quest code.
The homepage for the vx32 library is http://pdos.csail.mit.edu/~baford/vm/
could this help running legacy code on capability based operating
systems like KeyKos, Eros and Capros?
probably
could this also allow oneself to implement capability based security
where one has only an unprivileged shell account on machine of the
x86 architecture?
yes definitely

I am of the opinion that vx32 might be used by application developers
to bring capability based security to their applications on Unix
deverided systems.

(One example the vx32 paper gives is the VXA an future-proof self
extracting archival fileformat)

Thoughts, comments, ideas are welcome.

-Baldur Jóhannsson


More information about the cap-talk mailing list