A protocol is reached by name now, not by a compile-time integer. Init is PID 1 and already knows which binary it started, so init serves /protocol as a vfs backend: bind claims a contract with the provider's endpoint attached, open answers with that endpoint as the reply's capability, and readdir lists what is bound with the task and binary behind it. The kernel reserves the prefix — nothing may mount over it, under it, or unmount it — and ServiceId, ipc_register and ipc_lookup are gone, their syscall numbers left vacant. A bind is authorized by who the caller *is*: the kernel-stamped binary together with the supervising task's identity, matched against /system/configuration/protocol.csv. Identity, not spelling — spawn is ungated, so an attacker can run any bundled binary, and a name-only rule would have let it launder grants through an init of its own making. A name a live process holds is refused to everyone else; a dead one's is released. Three review rounds against a hostile ring-3 process found what 108 green tests could not, because the suite contains no attacker. Publishing init's supervision endpoint as the registry put PID 1's mailbox in every process's hands, where two forged bytes reached the shutdown path: privileged traffic is now believed only from the task that holds the contract it speaks for. A capability arriving on a request outlived every path that ignored it, one handle per call until the table was full — in init, and in the harness ten services share — so the arriving capability is owned by the turn and released unless a handler says otherwise. And the kernel let anyone holding an endpoint handle aim signals, timers, exit notices and interrupts at it: binding now requires having created it. Suite 108/108. The new protocol-registry case asserts eleven properties, each one an attack that must fail.
87 lines
4.1 KiB
Zig
87 lines
4.1 KiB
Zig
//! device-list — the `ps` analog for the device tree (docs/device-manager.md
|
|
//! M18.3): asks the device manager for the tree over IPC, prints it, then
|
|
//! subscribes and prints every published add/remove event. The manager is the
|
|
//! one answer to "what devices exist" for user space; nothing here touches a
|
|
//! device_* system call.
|
|
|
|
const std = @import("std");
|
|
const channel = @import("channel");
|
|
const ipc = @import("ipc");
|
|
const time = @import("time");
|
|
const logging = @import("logging");
|
|
const device_manager_protocol = @import("device-manager-protocol");
|
|
|
|
fn writeLine(comptime fmt: []const u8, arguments: anytype) void {
|
|
var line: [96]u8 = undefined;
|
|
_ = logging.write(std.fmt.bufPrint(&line, fmt, arguments) catch return);
|
|
}
|
|
|
|
pub fn main() void {
|
|
var manager: ?ipc.Handle = null;
|
|
var tries: u32 = 0;
|
|
while (manager == null and tries < 200) : (tries += 1) {
|
|
manager = channel.openEndpoint("device-manager");
|
|
if (manager == null) time.sleepMillis(20);
|
|
}
|
|
const h = manager orelse {
|
|
_ = logging.write("device-list: no device manager\n");
|
|
return;
|
|
};
|
|
|
|
// The snapshot — polled briefly, because at boot the bus drivers may still
|
|
// be scanning: an empty first answer usually just means "too early".
|
|
var reply: [device_manager_protocol.message_maximum]u8 = undefined;
|
|
var count: u32 = 0;
|
|
var length: usize = 0;
|
|
tries = 0;
|
|
while (tries < 20) : (tries += 1) {
|
|
const request = device_manager_protocol.Enumerate{};
|
|
length = ipc.call(h, std.mem.asBytes(&request), &reply) catch 0;
|
|
if (length >= @sizeOf(device_manager_protocol.EnumerateReply)) {
|
|
count = std.mem.bytesToValue(device_manager_protocol.EnumerateReply, reply[0..@sizeOf(device_manager_protocol.EnumerateReply)]).count;
|
|
if (count != 0) break;
|
|
}
|
|
time.sleepMillis(100);
|
|
}
|
|
writeLine("device-list: {d} devices\n", .{count});
|
|
var offset: usize = @sizeOf(device_manager_protocol.EnumerateReply);
|
|
var index: u32 = 0;
|
|
while (index < count and offset + @sizeOf(device_manager_protocol.ChildEntry) <= length) : (index += 1) {
|
|
const entry = std.mem.bytesToValue(device_manager_protocol.ChildEntry, reply[offset..][0..@sizeOf(device_manager_protocol.ChildEntry)]);
|
|
writeLine("device-list: device {d} port {d} identity {d}\n", .{ entry.parent, entry.bus_address, entry.identity });
|
|
offset += @sizeOf(device_manager_protocol.ChildEntry);
|
|
}
|
|
|
|
// The subscription: our endpoint rides as the call's capability; events
|
|
// arrive as buffered messages carrying the same structs the bus sends.
|
|
const endpoint = ipc.createIpcEndpoint() orelse {
|
|
_ = logging.write("device-list: no endpoint\n");
|
|
return;
|
|
};
|
|
const subscribe = device_manager_protocol.Subscribe{};
|
|
_ = ipc.callCap(h, std.mem.asBytes(&subscribe), &reply, endpoint) catch {
|
|
_ = logging.write("device-list: subscribe failed\n");
|
|
return;
|
|
};
|
|
_ = logging.write("device-list: subscribed\n");
|
|
|
|
var receive: [device_manager_protocol.message_maximum]u8 = undefined;
|
|
while (true) {
|
|
const got = ipc.replyWait(endpoint, &.{}, &receive, null);
|
|
if (!got.isMessage() or got.len < 1) continue;
|
|
switch (receive[0]) {
|
|
@intFromEnum(device_manager_protocol.Operation.child_added) => {
|
|
if (got.len < device_manager_protocol.child_added_size) continue;
|
|
const event = std.mem.bytesToValue(device_manager_protocol.ChildAdded, receive[0..device_manager_protocol.child_added_size]);
|
|
writeLine("device-list: added (device {d} port {d})\n", .{ event.parent, event.bus_address });
|
|
},
|
|
@intFromEnum(device_manager_protocol.Operation.child_removed) => {
|
|
if (got.len < device_manager_protocol.child_removed_size) continue;
|
|
const event = std.mem.bytesToValue(device_manager_protocol.ChildRemoved, receive[0..device_manager_protocol.child_removed_size]);
|
|
writeLine("device-list: removed (device {d} port {d})\n", .{ event.parent, event.bus_address });
|
|
},
|
|
else => {},
|
|
}
|
|
}
|
|
}
|