next up previous contents
Next: Capability Inheritance Algorithm Up: LinSec Capability Model Previous: Process Capabilities   Contents


Global Bounds

To be able to limit privileges of any process in the system a global bounding capability set is introduced and denoted as gB. gB has system wide effect and describes the maximum possible set of privileges any process can reach during its lifetime in the system. By no means can a process posses, in any of its capability sets (Subsection 4.2.7), a capability which is not in gB. Exactly how gB works can be seen in the Subsection 4.2.9.