next up previous contents
Next: Inheritage Up: Capabilities Previous: Capabilities   Contents

Assigning a capability to a subtree of the executables tree

Each time a program is executed, we must be able to give him a capabilities set. This capabilities set include the LIDS capabilities, and an inheritance mask to know which capabilities must be transmitted to the children of this process. This set will depend upon the program itself, upon the user executing the program and upon the capabilities and mask of its parent.

This amounts to giving each equivalence class executable or directory we choosed in section [*] to represent a partition of the executables set a list of uid and capabilities/mask.



Biondi Philippe 2000-12-15