- Class Capability
Define a security_descriptor structure. Store instances in a shared, content-addressed cache (keyed by descriptor content, not by namespace ancestry) so that identical ACLs are not duplicated across relations. See docs/reactos-ob-comparison.md §5 and §7.
Cache the result of Access() in HandlerManager::handle::granted_access at open time. Per-operation checks should then read from the handle rather than re-evaluating the descriptor on every call. See docs/reactos-ob-comparison.md §4.
- Struct nt::HandlerManager::handle
- Populate granted_access inside HandlerManager::Open from PermissionsManager::Firewall / Access. See docs/reactos-ob-comparison.md §4.
- Member nt::HandlerManager::handle::granted_access
- Populate in HandlerManager::Open.
- Class nt::IdentityManager
- Migrate to type callbacks. Once object_type holds OpenProcedure and CloseProcedure function pointers, CanOpen / CanClose become thin dispatchers that invoke the corresponding procedure — or this manager is absorbed into HandlerManager directly. The function pointer should be accompanied by a const char* name label on object_type so that error logs identify the type without dereferencing the pointer. See docs/reactos-ob-comparison.md §2.
- Member nt::LifecycleManager::Contention (ObjectManager::registry *object)
- Implement: read object_type::exclusive. Return false immediately for non-exclusive objects. For exclusive objects, return false (contention detected) when handle_count > 0 for a write-mode opener. See docs/reactos-ob-comparison.md §6.
- Member nt::LifecycleManager::Pin (ObjectManager::registry *object)
- Implement. See docs/reactos-ob-comparison.md §1.
- Member nt::LifecycleManager::Unmonitor (ObjectManager::registry *object)
- Gate GC on both counters reaching zero, not just handle_count. For deferred compaction, enqueue onto a background GC list rather than freeing inline. See docs/reactos-ob-comparison.md §1 and §7.
- Member nt::LifecycleManager::Unpin (ObjectManager::registry *object)
- Implement. See docs/reactos-ob-comparison.md §1.
- Class nt::NamespaceReferenceManager
Implement Resolve(path) with a reparse loop and cycle depth guard.
Define the reference object type with object_type::exclusive = true and a ParseProcedure that rewrites the resolution path.
Define the batch-update API with all-or-nothing contention semantics. See docs/reactos-ob-comparison.md §8.
- Struct nt::ObjectManager::object_type
Replace methods with typed callback fields: OpenProcedure, CloseProcedure, DeleteProcedure, and ParseProcedure. Store a const char* name label alongside each callback so that logs and assertions can identify which type fired without having to dereference a pointer. IdentityManager::CanOpen / CanClose then become thin dispatchers that invoke the corresponding procedure, or are absorbed into HandlerManager directly. See docs/reactos-ob-comparison.md §2.
Add an exclusive flag for mutable reference objects (branch HEADs, namespace entries). Non-exclusive objects — immutable snapshots, transactions — must skip contention checks entirely. See docs/reactos-ob-comparison.md §6.
- Member nt::ObjectManager::object_type::exclusive
- Wire into LifecycleManager::Contention.
- Member nt::ObjectManager::object_type::methods
- Replace with typed callback function pointers. See class-level todo.
- Member nt::ObjectManager::registry::next
- Replace with a trie whose nodes are per-path-segment hash maps. Each directory level holds a hash map from segment string to child registry*. Find() and Register() walk the trie component-by-component instead of scanning a flat list. Consider pulling a well-tested radix-tree via the Nix flake rather than implementing from scratch. See docs/reactos-ob-comparison.md §3.
- Struct nt::ObjectManager::registry_head
Implement reference_count tracking. Add LifecycleManager::Pin / Unpin. Update LifecycleManager::Unmonitor to gate GC on both counters reaching zero. See docs/reactos-ob-comparison.md §1.
Define and attach a security_descriptor. When added, store it as a pointer into a shared, content-addressed SD cache rather than inline. Permissions are strictly capability-based and must never be inherited from a parent namespace entry. See docs/reactos-ob-comparison.md §5.
- Member nt::ObjectManager::registry_head::reference_count
- Implement via LifecycleManager::Pin / Unpin.
- File RNT_C_API.h
- Implement AUTH_CLAIM::READ/WRITE enforcement in rnt_open_handle once PermissionsManager::Access is wired to a real policy engine. Currently all handles open with full access regardless of the claims parameter.