Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>> You can’t send file handles

> Actually that's exactly how piping works

Also SCM_RIGHTS, which exists exactly for this purpose (see cmsg(3), unix(7) or https://blog.cloudflare.com/know-your-scm_rights/ for a gentler introduction and application).

That's been around since BSD 4.3, which predates the Hater's Handbook 1ed by 4 years or so.



And that's how Unix is secretly a capability system


Yeah I had mentioned UNIX domain sockets. However your post does add a lot of good detail on them which I had left off.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: