[cap-talk] "Ambient capability"

Matej Kosik kosik at fiit.stuba.sk
Fri Jul 10 06:13:06 EDT 2009


Kevin Reid wrote:
> Someone just wrote this page on the erights.org wiki:
> 
>    http://wiki.erights.org/wiki/Ambient_capability
> 
> I've never seen this term before and the description feels a little  
> off. Would the scholars and taxonomists of cap-talk please review/edit  
> this article?

If I understand the term "ambient authority"
http://wiki.erights.org/wiki/Ambient_authority
and "capability"
http://wiki.erights.org/wiki/Capability
correctly, then "ambient capability" is an oxymoron.

I have some questions (towards the author):
http://wiki.erights.org/wiki/Talk:Ambient_authority

What are some concrete examples of `ambient capabilities'?

To make the answers easier, I have also added some explanation of the
difference between
- ambient authority system
- designated authority system
here:
http://wiki.erights.org/wiki/Ambient_authority
and I have tried to improve the definition of the term:
http://wiki.erights.org/wiki/Capability

Those who are knowledeable can improve the latter article
This latter article can be further improved adding some more examples of
capabilities in the KeyKOS, EROS, CapROS, Coyotos systems.
- what can they designate
- what operations do they permit their holder to do with designated object.


More information about the cap-talk mailing list