Server/driver protocols: no longer allow third-party copies.
Before safecopies, the IO_ENDPT and DL_ENDPT message fields were needed to know which actual process to copy data from/to, as that process may not always be the caller. Now that we have full safecopy support, these fields have become useless for that purpose: the owner of the grant is *always* the caller. Allowing the caller to supply another endpoint is in fact dangerous, because the callee may then end up using a grant from a third party. One could call this a variant of the confused deputy problem. From now on, safecopy calls should always use the caller's endpoint as grant owner. This fully obsoletes the DL_ENDPT field in the inet/ethernet protocol. IO_ENDPT has other uses besides identifying the grant owner though. This patch renames IO_ENDPT to USER_ENDPT, not only because that is a more fitting name (it should never be used for I/O after all), but also in order to intentionally break any old system source code outside the base system. If this patch breaks your code, fixing it is fairly simple: - DL_ENDPT should be replaced with m_source; - IO_ENDPT should be replaced with m_source when used for safecopies; - IO_ENDPT should be replaced with USER_ENDPT for any other use, e.g. when setting REP_ENDPT, matching requests in CANCEL calls, getting DEV_SELECT flags, and retrieving of the real user process's endpoint in DEV_OPEN. The changes in this patch are binary backward compatible.
This commit is contained in:
@@ -1292,7 +1292,7 @@ static void or_writev_s (message * mp, int from_int) {
|
||||
if (i + n > count)
|
||||
n = count - i;
|
||||
|
||||
cps = sys_safecopyfrom(mp->DL_ENDPT, mp->DL_GRANT, iov_offset,
|
||||
cps = sys_safecopyfrom(mp->m_source, mp->DL_GRANT, iov_offset,
|
||||
(vir_bytes) orp->or_iovec_s,
|
||||
n * sizeof(orp->or_iovec_s[0]), D);
|
||||
if (cps != OK)
|
||||
@@ -1304,7 +1304,7 @@ static void or_writev_s (message * mp, int from_int) {
|
||||
printf("Orinoco: invalid pkt size\n");
|
||||
}
|
||||
|
||||
cps = sys_safecopyfrom(mp->DL_ENDPT, iovp->iov_grant,
|
||||
cps = sys_safecopyfrom(mp->m_source, iovp->iov_grant,
|
||||
0, (vir_bytes) databuf + o, s, D);
|
||||
if (cps != OK)
|
||||
printf("orinoco: sys_safecopyfrom failed:%d\n",
|
||||
@@ -1683,7 +1683,7 @@ static void or_readv_s (message * mp, int from_int)
|
||||
if (i + n > count)
|
||||
n = count - i;
|
||||
|
||||
cps = sys_safecopyfrom(mp->DL_ENDPT, mp->DL_GRANT, iov_offset,
|
||||
cps = sys_safecopyfrom(mp->m_source, mp->DL_GRANT, iov_offset,
|
||||
(vir_bytes)orp->or_iovec_s,
|
||||
n * sizeof(orp->or_iovec_s[0]), D);
|
||||
if (cps != OK)
|
||||
@@ -1695,7 +1695,7 @@ static void or_readv_s (message * mp, int from_int)
|
||||
assert (length > size);
|
||||
s = length - size;
|
||||
}
|
||||
cps = sys_safecopyto(mp->DL_ENDPT, iovp->iov_grant, 0,
|
||||
cps = sys_safecopyto(mp->m_source, iovp->iov_grant, 0,
|
||||
(vir_bytes) databuf + o, s, D);
|
||||
if (cps != OK)
|
||||
panic("orinoco: warning: sys_safecopy failed: %d", cps);
|
||||
@@ -1862,7 +1862,7 @@ static void or_getstat_s (message * mp) {
|
||||
|
||||
stats = orp->or_stat;
|
||||
|
||||
r = sys_safecopyto(mp->DL_ENDPT, mp->DL_GRANT, 0,
|
||||
r = sys_safecopyto(mp->m_source, mp->DL_GRANT, 0,
|
||||
(vir_bytes) &stats, sizeof(stats), D);
|
||||
if(r != OK) {
|
||||
panic("or_getstat_s: sys_safecopyto failed: %d", r);
|
||||
|
||||
Reference in New Issue
Block a user