The kdbuswreck
The kdbuswreck
Posted Apr 30, 2015 10:54 UTC (Thu) by metux-its (guest, #102293)In reply to: The kdbuswreck by kentonv
Parent article: The kdbuswreck
Well, extending the FD approach a little bit:
* make the FDs/sockets/... appear in the process' filesystem
(using per-process namespaces)
* separate services by security domains (so, choose the granularity of
the service operations in a way that you either allowed to talk
to the service or not)
* let processes pass these fd's selectively to others
* instead of sockets (streams), use directory trees (like in /sys)
* add an simple but generic remote file system for that
Finally, you'll have something like Plan9 or Inferno ...
