A protocol is reached by name now, not by a compile-time integer. Init is PID 1 and already knows which binary it started, so init serves /protocol as a vfs backend: bind claims a contract with the provider's endpoint attached, open answers with that endpoint as the reply's capability, and readdir lists what is bound with the task and binary behind it. The kernel reserves the prefix — nothing may mount over it, under it, or unmount it — and ServiceId, ipc_register and ipc_lookup are gone, their syscall numbers left vacant. A bind is authorized by who the caller *is*: the kernel-stamped binary together with the supervising task's identity, matched against /system/configuration/protocol.csv. Identity, not spelling — spawn is ungated, so an attacker can run any bundled binary, and a name-only rule would have let it launder grants through an init of its own making. A name a live process holds is refused to everyone else; a dead one's is released. Three review rounds against a hostile ring-3 process found what 108 green tests could not, because the suite contains no attacker. Publishing init's supervision endpoint as the registry put PID 1's mailbox in every process's hands, where two forged bytes reached the shutdown path: privileged traffic is now believed only from the task that holds the contract it speaks for. A capability arriving on a request outlived every path that ignored it, one handle per call until the table was full — in init, and in the harness ten services share — so the arriving capability is owned by the turn and released unless a handler says otherwise. And the kernel let anyone holding an endpoint handle aim signals, timers, exit notices and interrupts at it: binding now requires having created it. Suite 108/108. The new protocol-registry case asserts eleven properties, each one an attack that must fail.
71 lines
4.7 KiB
CSV
71 lines
4.7 KiB
CSV
# /system/configuration/protocol.csv — who may claim, and who may reach, a name
|
|
# under /protocol (docs/os-development/protocol-namespace.md).
|
|
#
|
|
# init is the registrar: it serves /protocol, and every bind is checked against
|
|
# this file. It is AUTHORITATIVE — a name no row grants cannot be bound, and a
|
|
# missing file means nothing may be bound at all.
|
|
#
|
|
# '#' starts a comment (whole-line or trailing); blank lines are ignored.
|
|
# Whitespace around a field is trimmed, so columns may be padded. Four
|
|
# comma-separated fields per row:
|
|
#
|
|
# binary the claimant's binary path, exactly as the kernel stamped it at
|
|
# spawn (argv[0]) — unforgeable, read from the process records
|
|
# supervisor the authorized supervising TASK, written as the binary it runs —
|
|
# the path init was started as for its own services, the device
|
|
# manager's path for the drivers it starts. The one word that is not
|
|
# a path is 'kernel', because a kernel task has no binary; that is
|
|
# what the test harness's direct spawns look like.
|
|
# Matched by IDENTITY, not by spelling. Name alone is not identity —
|
|
# spawn is ungated, so a hostile process can start a granted binary
|
|
# itself and inherit its grants; and it can equally start its own
|
|
# instance of the *supervisor's* binary and have that spawn the
|
|
# granted one, at which point both names read correctly (the
|
|
# laundering deputy). So init also asks which task the supervisor
|
|
# is: 'kernel' means supervisor id 0, which only the kernel can
|
|
# confer; init's own path means this init; any other path means a
|
|
# task init spawned itself or one the kernel spawned. Task ids are
|
|
# monotonic and never reused, so an id cannot be borrowed.
|
|
# permission bind (provide this contract) | open (speak to it)
|
|
# name the contract, relative to /protocol
|
|
#
|
|
# A trailing '*' on any field matches any tail — how a subtree is granted whole.
|
|
#
|
|
# NOTE: 'open' rows are parsed but not yet enforced; every open resolves today.
|
|
# The milestone that turns them into refusals is P3 (docs/security-track-plan.md).
|
|
#
|
|
# binary supervisor permission name
|
|
|
|
# --- the services init spawns from init.csv ---------------------------------
|
|
/system/services/input, /system/services/init, bind, input
|
|
/system/services/device-manager, /system/services/init, bind, device-manager
|
|
/system/services/fat, /system/services/init, bind, vfs
|
|
/system/services/display, /system/services/init, bind, display
|
|
|
|
# The discovery service ships under one neutral name per firmware (docs/discovery.md);
|
|
# on x86 it is the acpi service, and what it provides is the power contract.
|
|
/system/services/discovery, /system/services/device-manager, bind, power
|
|
|
|
# --- the drivers, which the device manager spawns ---------------------------
|
|
/system/drivers/ps2-bus, /system/services/device-manager, bind, ps2-bus
|
|
/system/drivers/usb-xhci-bus, /system/services/device-manager, bind, usb-transfer
|
|
/system/drivers/usb-storage, /system/services/device-manager, bind, block
|
|
/system/drivers/virtio-gpu, /system/services/device-manager, bind, scanout
|
|
|
|
# --- the same providers when the kernel test harness starts them directly ---
|
|
# A scenario boot spawns its own providers instead of letting init do it
|
|
# (docs/security-track-plan.md, decision 9), so the same binaries appear with
|
|
# 'kernel' as the supervisor. Nothing else changes: the binary must still match.
|
|
/system/services/input, kernel, bind, input
|
|
/system/services/device-manager, kernel, bind, device-manager
|
|
/system/services/fat, kernel, bind, vfs
|
|
/system/services/display, kernel, bind, display
|
|
/system/services/discovery, kernel, bind, power
|
|
|
|
# --- test fixtures ----------------------------------------------------------
|
|
# The subtree rule, dogfooded: anything installed under /test may claim anything
|
|
# under /protocol/test, and nothing above it — whether the harness spawned it or
|
|
# another fixture did.
|
|
/test/*, kernel, bind, test/*
|
|
/test/*, /test/*, bind, test/*
|