2 * Copyright (c) 2000-2016 Apple Computer, Inc. All rights reserved.
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
32 * Mach Operating System
33 * Copyright (c) 1991,1990,1989 Carnegie Mellon University
34 * All Rights Reserved.
36 * Permission to use, copy, modify and distribute this software and its
37 * documentation is hereby granted, provided that both the copyright
38 * notice and this permission notice appear in all copies of the
39 * software, derivative works or modified versions, and any portions
40 * thereof, and that both notices appear in supporting documentation.
42 * CARNEGIE MELLON ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS"
43 * CONDITION. CARNEGIE MELLON DISCLAIMS ANY LIABILITY OF ANY KIND FOR
44 * ANY DAMAGES WHATSOEVER RESULTING FROM THE USE OF THIS SOFTWARE.
46 * Carnegie Mellon requests users of this software to return to
48 * Software Distribution Coordinator or Software.Distribution@CS.CMU.EDU
49 * School of Computer Science
50 * Carnegie Mellon University
51 * Pittsburgh PA 15213-3890
53 * any improvements or extensions that they make and grant Carnegie Mellon
54 * the rights to redistribute these changes.
57 * NOTICE: This file was modified by McAfee Research in 2004 to introduce
58 * support for mandatory and extensible security protections. This notice
59 * is included in support of clause 2.2 (b) of the Apple Public License,
65 * File: ipc/ipc_port.h
69 * Definitions for ports.
72 #ifndef _IPC_IPC_PORT_H_
73 #define _IPC_IPC_PORT_H_
75 #ifdef MACH_KERNEL_PRIVATE
77 #include <mach_assert.h>
78 #include <mach_debug.h>
80 #include <mach/mach_types.h>
81 #include <mach/boolean.h>
82 #include <mach/kern_return.h>
83 #include <mach/port.h>
85 #include <kern/assert.h>
86 #include <kern/kern_types.h>
87 #include <kern/turnstile.h>
89 #include <ipc/ipc_types.h>
90 #include <ipc/ipc_object.h>
91 #include <ipc/ipc_mqueue.h>
92 #include <ipc/ipc_space.h>
94 #include <security/_label.h>
97 * A receive right (port) can be in four states:
98 * 1) dead (not active, ip_timestamp has death time)
99 * 2) in a space (ip_receiver_name != 0, ip_receiver points
100 * to the space but doesn't hold a ref for it)
101 * 3) in transit (ip_receiver_name == 0, ip_destination points
102 * to the destination port and holds a ref for it)
103 * 4) in limbo (ip_receiver_name == 0, ip_destination == IP_NULL)
105 * If the port is active, and ip_receiver points to some space,
106 * then ip_receiver_name != 0, and that space holds receive rights.
107 * If the port is not active, then ip_timestamp contains a timestamp
108 * taken when the port was destroyed.
111 typedef unsigned int ipc_port_timestamp_t
;
115 * Initial sub-structure in common with ipc_pset
116 * First element is an ipc_object second is a
119 struct ipc_object ip_object
;
120 struct ipc_mqueue ip_messages
;
123 struct ipc_space
*receiver
;
124 struct ipc_port
*destination
;
125 ipc_port_timestamp_t timestamp
;
129 ipc_kobject_t kobject
;
130 ipc_importance_task_t imp_task
;
131 ipc_port_t sync_inheritor_port
;
132 struct knote
*sync_inheritor_knote
;
133 struct turnstile
*sync_inheritor_ts
;
136 struct ipc_port
*ip_nsrequest
;
137 struct ipc_port
*ip_pdrequest
;
138 struct ipc_port_request
*ip_requests
;
140 struct ipc_kmsg
*premsg
;
141 struct turnstile
*send_turnstile
;
144 struct task_watchport_elem
*ip_watchport_elem
;
146 mach_vm_address_t ip_context
;
148 natural_t ip_sprequests
:1, /* send-possible requests outstanding */
149 ip_spimportant
:1, /* ... at least one is importance donating */
150 ip_impdonation
:1, /* port supports importance donation */
151 ip_tempowner
:1, /* dont give donations to current receiver */
152 ip_guarded
:1, /* port guarded (use context value as guard) */
153 ip_strict_guard
:1, /* Strict guarding; Prevents user manipulation of context values directly */
154 ip_specialreply
:1, /* port is a special reply port */
155 ip_sync_link_state
:3, /* link the port to destination port/ Workloop */
156 ip_sync_bootstrap_checkin
:1,/* port part of sync bootstrap checkin, push on thread doing the checkin */
157 ip_immovable_receive
:1, /* the receive right cannot be moved out of a space, until it is destroyed */
158 ip_no_grant
:1, /* Port wont accept complex messages containing (ool) port descriptors */
159 ip_immovable_send
:1, /* No send(once) rights to this port can be moved out of a space */
160 ip_impcount
:18; /* number of importance donations in nested queue */
162 mach_port_mscount_t ip_mscount
;
163 mach_port_rights_t ip_srights
;
164 mach_port_rights_t ip_sorights
;
168 #define IP_CALLSTACK_MAX 16
169 /* queue_chain_t ip_port_links;*//* all allocated ports */
170 thread_t ip_thread
; /* who made me? thread context */
171 unsigned long ip_timetrack
; /* give an idea of "when" created */
172 uintptr_t ip_callstack
[IP_CALLSTACK_MAX
]; /* stack trace */
173 unsigned long ip_spares
[IP_NSPARES
]; /* for debugging */
174 #endif /* MACH_ASSERT */
175 #if DEVELOPMENT || DEBUG
176 uint8_t ip_srp_lost_link
:1, /* special reply port turnstile link chain broken */
177 ip_srp_msg_sent
:1; /* special reply port msg sent */
182 #define ip_references ip_object.io_references
184 #define ip_receiver_name ip_messages.imq_receiver_name
185 #define ip_in_pset ip_messages.imq_in_pset
186 #define ip_reply_context ip_messages.imq_context
188 #define ip_receiver data.receiver
189 #define ip_destination data.destination
190 #define ip_timestamp data.timestamp
192 #define ip_kobject kdata.kobject
193 #define ip_imp_task kdata.imp_task
194 #define ip_sync_inheritor_port kdata.sync_inheritor_port
195 #define ip_sync_inheritor_knote kdata.sync_inheritor_knote
196 #define ip_sync_inheritor_ts kdata.sync_inheritor_ts
198 #define ip_premsg kdata2.premsg
199 #define ip_send_turnstile kdata2.send_turnstile
201 #define port_send_turnstile(port) (IP_PREALLOC(port) ? (port)->ip_premsg->ikm_turnstile : (port)->ip_send_turnstile)
203 #define set_port_send_turnstile(port, value) \
205 if (IP_PREALLOC(port)) { \
206 (port)->ip_premsg->ikm_turnstile = (value); \
208 (port)->ip_send_turnstile = (value); \
212 #define port_send_turnstile_address(port) \
213 (IP_PREALLOC(port) ? &((port)->ip_premsg->ikm_turnstile) : &((port)->ip_send_turnstile))
215 #define port_rcv_turnstile_address(port) \
220 * SYNC IPC state flags for special reply port/ rcv right.
223 * Special reply port is not linked to any other port
224 * or WL and linkage should be allowed.
226 * PORT_SYNC_LINK_PORT
227 * Special reply port is linked to the port and
228 * ip_sync_inheritor_port contains the inheritor
231 * PORT_SYNC_LINK_WORKLOOP_KNOTE
232 * Special reply port is linked to a WL (via a knote).
233 * ip_sync_inheritor_knote contains a pointer to the knote
234 * the port is stashed on.
236 * PORT_SYNC_LINK_WORKLOOP_STASH
237 * Special reply port is linked to a WL (via a knote stash).
238 * ip_sync_inheritor_ts contains a pointer to the turnstile with a +1
239 * the port is stashed on.
241 * PORT_SYNC_LINK_NO_LINKAGE
242 * Message sent to special reply port, do
243 * not allow any linkages till receive is
246 * PORT_SYNC_LINK_RCV_THREAD
247 * Receive right copied out as a part of bootstrap check in,
248 * push on the thread which copied out the port.
250 #define PORT_SYNC_LINK_ANY (0)
251 #define PORT_SYNC_LINK_PORT (0x1)
252 #define PORT_SYNC_LINK_WORKLOOP_KNOTE (0x2)
253 #define PORT_SYNC_LINK_WORKLOOP_STASH (0x3)
254 #define PORT_SYNC_LINK_NO_LINKAGE (0x4)
255 #define PORT_SYNC_LINK_RCV_THREAD (0x5)
257 #define IP_NULL IPC_PORT_NULL
258 #define IP_DEAD IPC_PORT_DEAD
259 #define IP_VALID(port) IPC_PORT_VALID(port)
261 #define ip_object_to_port(io) __container_of(io, struct ipc_port, ip_object)
262 #define ip_to_object(port) (&(port)->ip_object)
263 #define ip_active(port) io_active(ip_to_object(port))
264 #define ip_lock_init(port) io_lock_init(ip_to_object(port))
265 #define ip_lock_held(port) io_lock_held(ip_to_object(port))
266 #define ip_lock(port) io_lock(ip_to_object(port))
267 #define ip_lock_try(port) io_lock_try(ip_to_object(port))
268 #define ip_lock_held_kdp(port) io_lock_held_kdp(ip_to_object(port))
269 #define ip_unlock(port) io_unlock(ip_to_object(port))
271 #define ip_reference(port) io_reference(ip_to_object(port))
272 #define ip_release(port) io_release(ip_to_object(port))
274 /* get an ipc_port pointer from an ipc_mqueue pointer */
275 #define ip_from_mq(mq) \
276 __container_of(mq, struct ipc_port, ip_messages)
278 #define ip_reference_mq(mq) ip_reference(ip_from_mq(mq))
279 #define ip_release_mq(mq) ip_release(ip_from_mq(mq))
281 #define ip_kotype(port) io_kotype(ip_to_object(port))
282 #define ip_is_kobject(port) io_is_kobject(ip_to_object(port))
284 #define ip_full_kernel(port) imq_full_kernel(&(port)->ip_messages)
285 #define ip_full(port) imq_full(&(port)->ip_messages)
288 * JMM - Preallocation flag
289 * This flag indicates that there is a message buffer preallocated for this
290 * port and we should use that when sending (from the kernel) rather than
291 * allocate a new one. This avoids deadlocks during notification message
292 * sends by critical system threads (which may be needed to free memory and
293 * therefore cannot be blocked waiting for memory themselves).
295 #define IP_BIT_PREALLOC 0x00008000 /* preallocated mesg */
296 #define IP_PREALLOC(port) ((port)->ip_object.io_bits & IP_BIT_PREALLOC)
298 #define IP_SET_PREALLOC(port, kmsg) \
300 (port)->ip_object.io_bits |= IP_BIT_PREALLOC; \
301 (port)->ip_premsg = (kmsg); \
304 #define IP_CLEAR_PREALLOC(port, kmsg) \
306 assert((port)->ip_premsg == kmsg); \
307 (port)->ip_object.io_bits &= ~IP_BIT_PREALLOC; \
308 (port)->ip_premsg = IKM_NULL; \
311 /* JMM - address alignment/packing for LP64 */
312 struct ipc_port_request
{
314 struct ipc_port
*port
;
315 ipc_port_request_index_t index
;
319 mach_port_name_t name
;
320 struct ipc_table_size
*size
;
324 #define ipr_next notify.index
325 #define ipr_size name.size
327 #define ipr_soright notify.port
328 #define ipr_name name.name
331 * Use the low bits in the ipr_soright to specify the request type
333 #define IPR_SOR_SPARM_MASK 1 /* send-possible armed */
334 #define IPR_SOR_SPREQ_MASK 2 /* send-possible requested */
335 #define IPR_SOR_SPBIT_MASK 3 /* combo */
336 #define IPR_SOR_SPARMED(sor) (((uintptr_t)(sor) & IPR_SOR_SPARM_MASK) != 0)
337 #define IPR_SOR_SPREQ(sor) (((uintptr_t)(sor) & IPR_SOR_SPREQ_MASK) != 0)
338 #define IPR_SOR_PORT(sor) ((ipc_port_t)((uintptr_t)(sor) & ~IPR_SOR_SPBIT_MASK))
339 #define IPR_SOR_MAKE(p, m) ((ipc_port_t)((uintptr_t)(p) | (m)))
341 extern lck_grp_t ipc_lck_grp
;
342 extern lck_attr_t ipc_lck_attr
;
345 * Taking the ipc_port_multiple lock grants the privilege
346 * to lock multiple ports at once. No ports must locked
350 extern lck_spin_t ipc_port_multiple_lock_data
;
352 #define ipc_port_multiple_lock_init() \
353 lck_spin_init(&ipc_port_multiple_lock_data, &ipc_lck_grp, &ipc_lck_attr)
355 #define ipc_port_multiple_lock() \
356 lck_spin_lock_grp(&ipc_port_multiple_lock_data, &ipc_lck_grp)
358 #define ipc_port_multiple_unlock() \
359 lck_spin_unlock(&ipc_port_multiple_lock_data)
362 * The port timestamp facility provides timestamps
363 * for port destruction. It is used to serialize
364 * mach_port_names with port death.
367 extern ipc_port_timestamp_t ipc_port_timestamp_data
;
369 /* Retrieve a port timestamp value */
370 extern ipc_port_timestamp_t
ipc_port_timestamp(void);
373 * Compares two timestamps, and returns TRUE if one
374 * happened before two. Note that this formulation
375 * works when the timestamp wraps around at 2^32,
376 * as long as one and two aren't too far apart.
379 #define IP_TIMESTAMP_ORDER(one, two) ((int) ((one) - (two)) < 0)
382 require_ip_active(ipc_port_t port
)
384 if (!ip_active(port
)) {
385 panic("Using inactive port %p", port
);
389 static inline kern_return_t
392 mach_port_name_t name
,
393 mach_port_right_t right
,
399 kr
= ipc_object_translate(space
, name
, right
, &object
);
400 *portp
= (kr
== KERN_SUCCESS
) ? ip_object_to_port(object
) : IP_NULL
;
404 #define ipc_port_translate_receive(space, name, portp) \
405 ipc_port_translate((space), (name), MACH_PORT_RIGHT_RECEIVE, portp)
407 #define ipc_port_translate_send(space, name, portp) \
408 ipc_port_translate((space), (name), MACH_PORT_RIGHT_SEND, portp)
410 /* Allocate a notification request slot */
411 #if IMPORTANCE_INHERITANCE
413 ipc_port_request_alloc(
415 mach_port_name_t name
,
417 boolean_t send_possible
,
419 ipc_port_request_index_t
*indexp
,
420 boolean_t
*importantp
);
423 ipc_port_request_alloc(
425 mach_port_name_t name
,
427 boolean_t send_possible
,
429 ipc_port_request_index_t
*indexp
);
430 #endif /* IMPORTANCE_INHERITANCE */
432 /* Grow one of a port's tables of notifcation requests */
433 extern kern_return_t
ipc_port_request_grow(
435 ipc_table_elems_t target_size
);
437 /* Return the type(s) of notification requests outstanding */
438 extern mach_port_type_t
ipc_port_request_type(
440 mach_port_name_t name
,
441 ipc_port_request_index_t index
);
443 /* Cancel a notification request and return the send-once right */
444 extern ipc_port_t
ipc_port_request_cancel(
446 mach_port_name_t name
,
447 ipc_port_request_index_t index
);
449 /* Arm any delayed send-possible notification */
450 extern boolean_t
ipc_port_request_sparm(
452 mach_port_name_t name
,
453 ipc_port_request_index_t index
,
454 mach_msg_option_t option
,
455 mach_msg_priority_t override
);
457 /* Make a port-deleted request */
458 extern void ipc_port_pdrequest(
461 ipc_port_t
*previousp
);
463 /* Make a no-senders request */
464 extern void ipc_port_nsrequest(
466 mach_port_mscount_t sync
,
468 ipc_port_t
*previousp
);
470 /* Prepare a receive right for transmission/destruction */
471 extern boolean_t
ipc_port_clear_receiver(
473 boolean_t should_destroy
);
475 /* Initialize a newly-allocated port */
476 extern void ipc_port_init(
479 mach_port_name_t name
);
481 /* Allocate a port */
482 extern kern_return_t
ipc_port_alloc(
484 bool make_send_right
,
485 mach_port_name_t
*namep
,
488 /* Allocate a port, with a specific name */
489 extern kern_return_t
ipc_port_alloc_name(
491 mach_port_name_t name
,
494 /* Generate dead name notifications */
495 extern void ipc_port_dnnotify(
498 /* Generate send-possible notifications */
499 extern void ipc_port_spnotify(
503 extern void ipc_port_destroy(
506 /* Check if queueing "port" in a message for "dest" would create a circular
507 * group of ports and messages */
509 ipc_port_check_circularity(
513 #if IMPORTANCE_INHERITANCE
516 IPID_OPTION_NORMAL
= 0, /* normal boost */
517 IPID_OPTION_SENDPOSSIBLE
= 1, /* send-possible induced boost */
520 /* link the destination port with special reply port */
522 ipc_port_link_special_reply_port(
523 ipc_port_t special_reply_port
,
524 ipc_port_t dest_port
,
525 boolean_t sync_bootstrap_checkin
);
527 #define IPC_PORT_ADJUST_SR_NONE 0
528 #define IPC_PORT_ADJUST_SR_ALLOW_SYNC_LINKAGE 0x1
529 #define IPC_PORT_ADJUST_SR_LINK_WORKLOOP 0x2
530 #define IPC_PORT_ADJUST_UNLINK_THREAD 0x4
531 #define IPC_PORT_ADJUST_SR_RECEIVED_MSG 0x8
532 #define IPC_PORT_ADJUST_SR_ENABLE_EVENT 0x10
533 #define IPC_PORT_ADJUST_RESET_BOOSTRAP_CHECKIN 0x20
536 ipc_special_reply_port_bits_reset(ipc_port_t special_reply_port
);
539 ipc_special_reply_port_msg_sent(ipc_port_t special_reply_port
);
542 ipc_special_reply_port_msg_sent(ipc_port_t special_reply_port
);
544 /* Adjust special reply port linkage */
546 ipc_port_adjust_special_reply_port_locked(
547 ipc_port_t special_reply_port
,
550 boolean_t get_turnstile
);
553 ipc_port_adjust_sync_link_state_locked(
556 turnstile_inheritor_t inheritor
);
558 /* Adjust special reply port linkage */
560 ipc_port_adjust_special_reply_port(
561 ipc_port_t special_reply_port
,
563 boolean_t get_turnstile
);
566 ipc_port_adjust_port_locked(
569 boolean_t sync_bootstrap_checkin
);
572 ipc_port_clear_sync_rcv_thread_boost_locked(
576 ipc_port_add_watchport_elem_locked(
578 struct task_watchport_elem
*watchport_elem
,
579 struct task_watchport_elem
**old_elem
);
582 ipc_port_clear_watchport_elem_internal_conditional_locked(
584 struct task_watchport_elem
*watchport_elem
);
587 ipc_port_replace_watchport_elem_conditional_locked(
589 struct task_watchport_elem
*old_watchport_elem
,
590 struct task_watchport_elem
*new_watchport_elem
);
592 struct task_watchport_elem
*
593 ipc_port_clear_watchport_elem_internal(
597 ipc_port_send_turnstile_prepare(ipc_port_t port
);
600 ipc_port_send_turnstile_complete(ipc_port_t port
);
603 ipc_port_rcv_turnstile_waitq(struct waitq
*waitq
);
605 /* apply importance delta to port only */
606 extern mach_port_delta_t
607 ipc_port_impcount_delta(
609 mach_port_delta_t delta
,
612 /* apply importance delta to port, and return task importance for update */
614 ipc_port_importance_delta_internal(
617 mach_port_delta_t
*deltap
,
618 ipc_importance_task_t
*imp_task
);
620 /* Apply an importance delta to a port and reflect change in receiver task */
622 ipc_port_importance_delta(
625 mach_port_delta_t delta
);
626 #endif /* IMPORTANCE_INHERITANCE */
628 /* Make a naked send right from a receive right - port locked and active */
629 extern ipc_port_t
ipc_port_make_send_locked(
632 /* Make a naked send right from a receive right */
633 extern ipc_port_t
ipc_port_make_send(
636 /* Make a naked send right from another naked send right - port locked and active */
637 extern void ipc_port_copy_send_locked(
640 /* Make a naked send right from another naked send right */
641 extern ipc_port_t
ipc_port_copy_send(
644 /* Copyout a naked send right */
645 extern mach_port_name_t
ipc_port_copyout_send(
649 #endif /* MACH_KERNEL_PRIVATE */
653 /* Release a (valid) naked send right */
654 extern void ipc_port_release_send(
657 extern void ipc_port_reference(
660 extern void ipc_port_release(
663 #endif /* KERNEL_PRIVATE */
665 #ifdef MACH_KERNEL_PRIVATE
667 /* Make a naked send-once right from a locked and active receive right */
668 extern ipc_port_t
ipc_port_make_sonce_locked(
671 /* Make a naked send-once right from a receive right */
672 extern ipc_port_t
ipc_port_make_sonce(
675 /* Release a naked send-once right */
676 extern void ipc_port_release_sonce(
679 /* Release a naked (in limbo or in transit) receive right */
680 extern void ipc_port_release_receive(
683 /* finalize the destruction of a port before it gets freed */
684 extern void ipc_port_finalize(
687 /* Allocate a port in a special space */
688 extern ipc_port_t
ipc_port_alloc_special(
691 /* Deallocate a port in a special space */
692 extern void ipc_port_dealloc_special(
697 /* Track low-level port deallocation */
698 extern void ipc_port_track_dealloc(
701 /* Initialize general port debugging state */
702 extern void ipc_port_debug_init(void);
703 #endif /* MACH_ASSERT */
705 extern void ipc_port_recv_update_inheritor(ipc_port_t port
,
706 struct turnstile
*turnstile
,
707 turnstile_update_flags_t flags
);
709 extern void ipc_port_send_update_inheritor(ipc_port_t port
,
710 struct turnstile
*turnstile
,
711 turnstile_update_flags_t flags
);
713 #define ipc_port_alloc_kernel() \
714 ipc_port_alloc_special(ipc_space_kernel)
715 #define ipc_port_dealloc_kernel(port) \
716 ipc_port_dealloc_special((port), ipc_space_kernel)
718 #define ipc_port_alloc_reply() \
719 ipc_port_alloc_special(ipc_space_reply)
720 #define ipc_port_dealloc_reply(port) \
721 ipc_port_dealloc_special((port), ipc_space_reply)
723 #endif /* MACH_KERNEL_PRIVATE */
725 #endif /* _IPC_IPC_PORT_H_ */