Capsicum: Practical Capabilities for Unix
cl.cam.ac.uk
cl.cam.ac.uk
https://cvsweb.openbsd.org/cgi-bin/cvsweb/~checkout~/ports/a...
And as is typical for FreeBSD, ~7/8 years later these "practical" Capsicum changes were never merged into FreeBSD. :-(
https://github.com/freebsd/freebsd/tree/master/contrib/bzip2
If you read the list of features, it's very clear that they are not talking about what most people think of when they hear "capabilities" in the context of operating systems:
> anonymous shared memory objects - an extension to the POSIX shared memory API to support anonymous swap objects associated with file descriptors (capabilities)
File descriptors are a form of object capabilities.
Meanwhile pledge(2) is protecting a large percentage of the OpenBSD base system, something like 85/90% of all programs. And unlike Capsicum, it is "practical" for developers. And important ports like archivers, and web browsers. The Capsicum project never shipped the much touted Capsicum-ized chrome, but OpenBSD has pledge/unveil chrome packages by default.
For an example of an active project using ocaps see:
https://fuchsia.googlesource.com/fuchsia/ https://sel4.systems/
- - - -
See also "macaroons": "Macaroons: Cookies with Contextual Caveats for Decentralized Authorization in the Cloud"
From the abstract:
> This paper introduces macaroons: flexible authorization credentials for Cloud services that support decentralized delegation between principals. Macaroons are based on a construction that uses nested, chained MACs (e.g., HMACs) in a manner that is highly efficient, easy to deploy, and widely applicable.
> Although macaroons are bearer credentials, like Web cookies, macaroons embed caveats that attenuate and contextually confine when, where, by who, and for what purpose a target service should authorize requests.