Server/driver protocols: no longer allow third-party copies.
Before safecopies, the IO_ENDPT and DL_ENDPT message fields were needed to know which actual process to copy data from/to, as that process may not always be the caller. Now that we have full safecopy support, these fields have become useless for that purpose: the owner of the grant is *always* the caller. Allowing the caller to supply another endpoint is in fact dangerous, because the callee may then end up using a grant from a third party. One could call this a variant of the confused deputy problem. From now on, safecopy calls should always use the caller's endpoint as grant owner. This fully obsoletes the DL_ENDPT field in the inet/ethernet protocol. IO_ENDPT has other uses besides identifying the grant owner though. This patch renames IO_ENDPT to USER_ENDPT, not only because that is a more fitting name (it should never be used for I/O after all), but also in order to intentionally break any old system source code outside the base system. If this patch breaks your code, fixing it is fairly simple: - DL_ENDPT should be replaced with m_source; - IO_ENDPT should be replaced with m_source when used for safecopies; - IO_ENDPT should be replaced with USER_ENDPT for any other use, e.g. when setting REP_ENDPT, matching requests in CANCEL calls, getting DEV_SELECT flags, and retrieving of the real user process's endpoint in DEV_OPEN. The changes in this patch are binary backward compatible.
This commit is contained in:
+5
-5
@@ -361,8 +361,8 @@ static void do_vwrite_s(const message * mp)
|
||||
if (dep->de_flags & DEF_SENDING) /* Is sending in progress? */
|
||||
panic("send already in progress ");
|
||||
|
||||
dep->de_write_iovec.iod_proc_nr = mp->DL_ENDPT;
|
||||
get_userdata_s(mp->DL_ENDPT, mp->DL_GRANT, 0,
|
||||
dep->de_write_iovec.iod_proc_nr = mp->m_source;
|
||||
get_userdata_s(mp->m_source, mp->DL_GRANT, 0,
|
||||
mp->DL_COUNT, dep->de_write_iovec.iod_iovec);
|
||||
dep->de_write_iovec.iod_iovec_s = mp->DL_COUNT;
|
||||
dep->de_write_iovec.iod_grant = (cp_grant_id_t) mp->DL_GRANT;
|
||||
@@ -399,8 +399,8 @@ static void do_vread_s(const message * mp)
|
||||
if (dep->de_flags & DEF_READING) /* Reading in progress */
|
||||
panic("read already in progress");
|
||||
|
||||
dep->de_read_iovec.iod_proc_nr = mp->DL_ENDPT;
|
||||
get_userdata_s(mp->DL_ENDPT, (cp_grant_id_t) mp->DL_GRANT, 0,
|
||||
dep->de_read_iovec.iod_proc_nr = mp->m_source;
|
||||
get_userdata_s(mp->m_source, (cp_grant_id_t) mp->DL_GRANT, 0,
|
||||
mp->DL_COUNT, dep->de_read_iovec.iod_iovec);
|
||||
dep->de_read_iovec.iod_iovec_s = mp->DL_COUNT;
|
||||
dep->de_read_iovec.iod_grant = (cp_grant_id_t) mp->DL_GRANT;
|
||||
@@ -434,7 +434,7 @@ static void do_getstat_s(const message * mp)
|
||||
dep = &de_state;
|
||||
|
||||
if (dep->de_mode == DEM_ENABLED) (*dep->de_getstatsf) (dep);
|
||||
if ((rc = sys_safecopyto(mp->DL_ENDPT, mp->DL_GRANT, 0,
|
||||
if ((rc = sys_safecopyto(mp->m_source, mp->DL_GRANT, 0,
|
||||
(vir_bytes)&dep->de_stat,
|
||||
(vir_bytes) sizeof(dep->de_stat), 0)) != OK)
|
||||
panic(CopyErrMsg, rc);
|
||||
|
||||
+1
-1
@@ -86,7 +86,7 @@ typedef void (*dp_getblock_t) (struct dpeth *, u16_t, int, void *);
|
||||
typedef struct iovec_dat_s {
|
||||
iovec_s_t iod_iovec[IOVEC_NR];
|
||||
int iod_iovec_s;
|
||||
int iod_proc_nr;
|
||||
endpoint_t iod_proc_nr;
|
||||
cp_grant_id_t iod_grant;
|
||||
vir_bytes iod_iovec_offset;
|
||||
} iovec_dat_s_t;
|
||||
|
||||
Reference in New Issue
Block a user