Re: The auth interface on L4-Hurd

From: Wolfgang Jährling
Subject: Re: The auth interface on L4-Hurd
Date: Thu, 1 Aug 2002 22:52:39 +0200
Wolfgang Jährling <address@hidden> wrote:
> b) The auth server could try to verify that the handle he got from the
>    server is something that refers to the user, but as handles can, like
>    ports, be passed around, this does not work.

I think I was wrong here.  But what we _will_ need is an RPC from auth
to the user to make sure the handle we got from the server is ok.

But, do we maybe have a race condition here?  When the server has made
the RPC to the user to move his handle to auth, but before he does the
auth_server_authenticate, someone else might make the
auth_server_authenticate for him, guessing the correct handle number.  How
can this be prevented?


