# /system/configuration/protocol.csv — who may claim, and who may reach, a name # under /protocol (docs/os-development/protocol-namespace.md). # # init is the registrar: it serves /protocol, and every bind is checked against # this file. It is AUTHORITATIVE — a name no row grants cannot be bound, and a # missing file means nothing may be bound at all. # # '#' starts a comment (whole-line or trailing); blank lines are ignored. # Whitespace around a field is trimmed, so columns may be padded. Four # comma-separated fields per row: # # binary the claimant's binary path, exactly as the kernel stamped it at # spawn (argv[0]) — unforgeable, read from the process records # supervisor the authorized supervising TASK, written as the binary it runs — # the path init was started as for its own services, the device # manager's path for the drivers it starts. The one word that is not # a path is 'kernel', because a kernel task has no binary; that is # what the test harness's direct spawns look like. # Matched by IDENTITY, not by spelling. Name alone is not identity — # spawn is ungated, so a hostile process can start a granted binary # itself and inherit its grants; and it can equally start its own # instance of the *supervisor's* binary and have that spawn the # granted one, at which point both names read correctly (the # laundering deputy). So init also asks which task the supervisor # is: 'kernel' means supervisor id 0, which only the kernel can # confer; init's own path means this init; any other path means a # task init spawned itself or one the kernel spawned. Task ids are # monotonic and never reused, so an id cannot be borrowed. # permission bind (provide this contract) | open (speak to it) # name the contract, relative to /protocol # # A trailing '*' on any field matches any tail — how a subtree is granted whole. # # NOTE: 'open' rows are parsed but not yet enforced; every open resolves today. # The milestone that turns them into refusals is P3 (docs/security-track-plan.md). # # binary supervisor permission name # --- the services init spawns from init.csv --------------------------------- /system/services/input, /system/services/init, bind, input /system/services/device-manager, /system/services/init, bind, device-manager /system/services/fat, /system/services/init, bind, vfs /system/services/display, /system/services/init, bind, display # The discovery service ships under one neutral name per firmware (docs/discovery.md); # on x86 it is the acpi service, and what it provides is the power contract. /system/services/discovery, /system/services/device-manager, bind, power # --- the drivers, which the device manager spawns --------------------------- /system/drivers/ps2-bus, /system/services/device-manager, bind, ps2-bus /system/drivers/usb-xhci-bus, /system/services/device-manager, bind, usb-transfer /system/drivers/usb-storage, /system/services/device-manager, bind, block /system/drivers/virtio-gpu, /system/services/device-manager, bind, scanout # --- the same providers when the kernel test harness starts them directly --- # A scenario boot spawns its own providers instead of letting init do it # (docs/security-track-plan.md, decision 9), so the same binaries appear with # 'kernel' as the supervisor. Nothing else changes: the binary must still match. /system/services/input, kernel, bind, input /system/services/device-manager, kernel, bind, device-manager /system/services/fat, kernel, bind, vfs /system/services/display, kernel, bind, display /system/services/discovery, kernel, bind, power # --- test fixtures ---------------------------------------------------------- # The subtree rule, dogfooded: anything installed under /test may claim anything # under /protocol/test, and nothing above it — whether the harness spawned it or # another fixture did. /test/*, kernel, bind, test/* /test/*, /test/*, bind, test/*