关于锁-钥保护机制的原理及锁与访问权限对应关系的技术问询
Hey everyone, I've been diving into the lock-key protection mechanism from Operating Systems Concepts (9th edition, page 638) and want to make sure I'm interpreting it correctly.
First, here's the book's official description of the mechanism:
The lock–key scheme is a compromise between access lists and capability lists. Each object has a list of unique bit patterns, called locks. Similarly, each domain has a list of unique bit patterns, called keys. A process executing in a domain can access an object only if that domain has a key that matches one of the locks of the object.
I get the core idea, but I'm confused about how specific access rights fit into this model. We all know access to an object isn't just a binary "allowed or not"—a domain might only have read access to an object, for example, without write or execute permissions.
So my question is: Does each lock in an object's list correspond to a specific access right for a specific domain? Like, for object O1, would there be a separate lock for "Domain D1 can read O1", another lock for "Domain D2 can write O1", and so on? Is that how the granularity of permissions is handled here?
备注:内容来源于stack exchange,提问作者AAA

