library: the harness keeps the subscribers, and an id belongs to whoever opened it
Three services had each written the same thing and got it three different ways: input polled the process list to notice a dead subscriber, and only when someone else subscribed; the power service never noticed at all; the device manager noticed drivers but not subscribers. The harness owns the table now, driven by the events a protocol declares — it registers on the reserved verb, frames each event once, posts to everyone interested without waiting on any of them, and reclaims a slot when the kernel says its owner died. Interest masks moved to the envelope, so a subscriber that wants only mice asks the same way everywhere. Two consequences the plan had not foreseen. The device manager now hears a supervised child's death twice, once as its supervisor and once as a subscriber, so restart backoff counted every crash twice and gave up after half as many; it retires the id before counting. And the kernel's published exit table had eight slots for what is now six subscriptions in a plain boot, so it holds sixteen. The other half is a hole the design named early and left standing: a backend handed out a small integer and then honoured it from anyone. A process that guessed a file's node id read another client's file; a display layer had no owner at all, so any client could reconfigure or destroy any layer; a USB device token was never checked against the client that opened it. Each is now bound to the task that opened it, and a wrong owner gets exactly what an unknown id gets — the refusal must not become the oracle the identical answers elsewhere were designed to remove. Closing a file changed with it: it used to succeed unconditionally, which would have told a caller which ids existed. Suite 111/111, with a new case in which one process holds a file and a layer, hands both ids to a second process, and finds them untouched after that process has tried everything with them.
This commit is contained in:
@@ -148,6 +148,16 @@
|
||||
/test/system/services/input-source, kernel, open, input
|
||||
/test/system/services/input-test, kernel, open, input
|
||||
|
||||
# The guessable-id probe (test/system/services/badge-scope-test) runs as two
|
||||
# processes of one binary: the owner, which the scenario spawns, and the intruder,
|
||||
# which the owner spawns with the ids it holds. Both reach the compositor — the
|
||||
# owner to create the layer, the intruder to be refused it — so the binary is
|
||||
# named twice, once per supervisor. The second row needs no 'supervise'
|
||||
# delegation: the owner was spawned by the KERNEL, which is a chain init can
|
||||
# vouch for on its own.
|
||||
/test/system/services/badge-scope-test, kernel, open, display
|
||||
/test/system/services/badge-scope-test, /test/*, open, display
|
||||
|
||||
# The conformance probe (test/system/services/protocol-conformance-test) asks
|
||||
# every provider its boot bound for the envelope's reserved verbs. It reaches
|
||||
# ONLY the two contracts its own scenario boots a provider for, named one at a
|
||||
|
||||
|
Can't render this file because it contains an unexpected character in line 12 and column 15.
|
Reference in New Issue
Block a user