Server/driver protocols: no longer allow third-party copies.
Before safecopies, the IO_ENDPT and DL_ENDPT message fields were needed to know which actual process to copy data from/to, as that process may not always be the caller. Now that we have full safecopy support, these fields have become useless for that purpose: the owner of the grant is *always* the caller. Allowing the caller to supply another endpoint is in fact dangerous, because the callee may then end up using a grant from a third party. One could call this a variant of the confused deputy problem. From now on, safecopy calls should always use the caller's endpoint as grant owner. This fully obsoletes the DL_ENDPT field in the inet/ethernet protocol. IO_ENDPT has other uses besides identifying the grant owner though. This patch renames IO_ENDPT to USER_ENDPT, not only because that is a more fitting name (it should never be used for I/O after all), but also in order to intentionally break any old system source code outside the base system. If this patch breaks your code, fixing it is fairly simple: - DL_ENDPT should be replaced with m_source; - IO_ENDPT should be replaced with m_source when used for safecopies; - IO_ENDPT should be replaced with USER_ENDPT for any other use, e.g. when setting REP_ENDPT, matching requests in CANCEL calls, getting DEV_SELECT flags, and retrieving of the real user process's endpoint in DEV_OPEN. The changes in this patch are binary backward compatible.
This commit is contained in:
@@ -185,13 +185,13 @@ PUBLIC int block_dev_io(
|
||||
}
|
||||
|
||||
/* By default, these are right. */
|
||||
m.IO_ENDPT = proc_e;
|
||||
m.USER_ENDPT = proc_e;
|
||||
m.ADDRESS = buffer;
|
||||
buf_used = buffer;
|
||||
|
||||
/* Convert parameters to 'safe mode'. */
|
||||
op_used = op;
|
||||
safe = safe_io_conversion(driver_e, &gid, &op_used, gids, &m.IO_ENDPT,
|
||||
safe = safe_io_conversion(driver_e, &gid, &op_used, gids, &m.USER_ENDPT,
|
||||
&buf_used, &vec_grants, bytes);
|
||||
|
||||
/* Set up rest of the message. */
|
||||
@@ -303,7 +303,7 @@ PRIVATE int gen_opcl(
|
||||
|
||||
dev_mess.m_type = op;
|
||||
dev_mess.DEVICE = minor(dev);
|
||||
dev_mess.IO_ENDPT = proc_e;
|
||||
dev_mess.USER_ENDPT = proc_e;
|
||||
dev_mess.COUNT = flags;
|
||||
|
||||
/* Call the task. */
|
||||
@@ -327,7 +327,7 @@ PRIVATE int gen_io(
|
||||
|
||||
int r, proc_e;
|
||||
|
||||
proc_e = mess_ptr->IO_ENDPT;
|
||||
proc_e = mess_ptr->USER_ENDPT;
|
||||
|
||||
r = sendrec(task_nr, mess_ptr);
|
||||
if(r == OK && mess_ptr->REP_STATUS == ERESTART)
|
||||
|
||||
Reference in New Issue
Block a user