]> git.saurik.com Git - apple/xnu.git/blob - osfmk/ipc/ipc_object.h
xnu-3789.70.16.tar.gz
[apple/xnu.git] / osfmk / ipc / ipc_object.h
1 /*
2 * Copyright (c) 2000-2007 Apple Inc. All rights reserved.
3 *
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
14 *
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
17 *
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
25 *
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27 */
28 /*
29 * @OSF_COPYRIGHT@
30 */
31 /*
32 * Mach Operating System
33 * Copyright (c) 1991,1990,1989 Carnegie Mellon University
34 * All Rights Reserved.
35 *
36 * Permission to use, copy, modify and distribute this software and its
37 * documentation is hereby granted, provided that both the copyright
38 * notice and this permission notice appear in all copies of the
39 * software, derivative works or modified versions, and any portions
40 * thereof, and that both notices appear in supporting documentation.
41 *
42 * CARNEGIE MELLON ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS"
43 * CONDITION. CARNEGIE MELLON DISCLAIMS ANY LIABILITY OF ANY KIND FOR
44 * ANY DAMAGES WHATSOEVER RESULTING FROM THE USE OF THIS SOFTWARE.
45 *
46 * Carnegie Mellon requests users of this software to return to
47 *
48 * Software Distribution Coordinator or Software.Distribution@CS.CMU.EDU
49 * School of Computer Science
50 * Carnegie Mellon University
51 * Pittsburgh PA 15213-3890
52 *
53 * any improvements or extensions that they make and grant Carnegie Mellon
54 * the rights to redistribute these changes.
55 */
56 /*
57 * NOTICE: This file was modified by McAfee Research in 2004 to introduce
58 * support for mandatory and extensible security protections. This notice
59 * is included in support of clause 2.2 (b) of the Apple Public License,
60 * Version 2.0.
61 */
62 /*
63 */
64 /*
65 * File: ipc/ipc_object.h
66 * Author: Rich Draves
67 * Date: 1989
68 *
69 * Definitions for IPC objects, for which tasks have capabilities.
70 */
71
72 #ifndef _IPC_IPC_OBJECT_H_
73 #define _IPC_IPC_OBJECT_H_
74
75 #include <mach_rt.h>
76
77 #include <mach/kern_return.h>
78 #include <mach/message.h>
79 #include <kern/locks.h>
80 #include <kern/macro_help.h>
81 #include <kern/assert.h>
82 #include <kern/zalloc.h>
83 #include <ipc/ipc_types.h>
84 #include <libkern/OSAtomic.h>
85
86 typedef natural_t ipc_object_refs_t; /* for ipc/ipc_object.h */
87 typedef natural_t ipc_object_bits_t;
88 typedef natural_t ipc_object_type_t;
89
90 /*
91 * The ipc_object is used to both tag and reference count these two data
92 * structures, and (Noto Bene!) pointers to either of these or the
93 * ipc_object at the head of these are freely cast back and forth; hence
94 * the ipc_object MUST BE FIRST in the ipc_common_data.
95 *
96 * If the RPC implementation enabled user-mode code to use kernel-level
97 * data structures (as ours used to), this peculiar structuring would
98 * avoid having anything in user code depend on the kernel configuration
99 * (with which lock size varies).
100 */
101 struct ipc_object {
102 ipc_object_bits_t io_bits;
103 ipc_object_refs_t io_references;
104 lck_spin_t io_lock_data;
105 };
106
107 /*
108 * If another object type needs to participate in io_kotype()-based
109 * dispatching, it must include a stub structure as the first
110 * element
111 */
112 struct ipc_object_header {
113 ipc_object_bits_t io_bits;
114 #ifdef __LP64__
115 natural_t io_padding; /* pad to natural boundary */
116 #endif
117 };
118
119 /*
120 * Legacy defines. Should use IPC_OBJECT_NULL, etc...
121 */
122 #define IO_NULL ((ipc_object_t) 0)
123 #define IO_DEAD ((ipc_object_t) ~0UL)
124 #define IO_VALID(io) (((io) != IO_NULL) && ((io) != IO_DEAD))
125
126 /*
127 * IPC steals the high-order bits from the kotype to use
128 * for its own purposes. This allows IPC to record facts
129 * about ports that aren't otherwise obvious from the
130 * existing port fields. In particular, IPC can optionally
131 * mark a port for no more senders detection. Any change
132 * to IO_BITS_PORT_INFO must be coordinated with bitfield
133 * definitions in ipc_port.h.
134 */
135 #define IO_BITS_PORT_INFO 0x0000f000 /* stupid port tricks */
136 #define IO_BITS_KOTYPE 0x00000fff /* used by the object */
137 #define IO_BITS_OTYPE 0x7fff0000 /* determines a zone */
138 #define IO_BITS_ACTIVE 0x80000000 /* is object alive? */
139
140 #define io_active(io) (((io)->io_bits & IO_BITS_ACTIVE) != 0)
141
142 #define io_otype(io) (((io)->io_bits & IO_BITS_OTYPE) >> 16)
143 #define io_kotype(io) ((io)->io_bits & IO_BITS_KOTYPE)
144
145 #define io_makebits(active, otype, kotype) \
146 (((active) ? IO_BITS_ACTIVE : 0) | ((otype) << 16) | (kotype))
147
148 /*
149 * Object types: ports, port sets, kernel-loaded ports
150 */
151 #define IOT_PORT 0
152 #define IOT_PORT_SET 1
153 #define IOT_NUMBER 2 /* number of types used */
154
155 extern zone_t ipc_object_zones[IOT_NUMBER];
156
157 #define io_alloc(otype) \
158 ((ipc_object_t) zalloc(ipc_object_zones[(otype)]))
159
160 extern void io_free(
161 unsigned int otype,
162 ipc_object_t object);
163
164 /*
165 * Here we depend on the ipc_object being first within the kernel struct
166 * (ipc_port and ipc_pset).
167 */
168 #define io_lock_init(io) \
169 lck_spin_init(&(io)->io_lock_data, &ipc_lck_grp, &ipc_lck_attr)
170 #define io_lock_destroy(io) \
171 lck_spin_destroy(&(io)->io_lock_data, &ipc_lck_grp)
172 #define io_lock(io) \
173 lck_spin_lock(&(io)->io_lock_data)
174 #define io_lock_try(io) \
175 lck_spin_try_lock(&(io)->io_lock_data)
176 #define io_lock_held_kdp(io) \
177 kdp_lck_spin_is_acquired(&(io)->io_lock_data)
178 #define io_unlock(io) \
179 lck_spin_unlock(&(io)->io_lock_data)
180
181 #define _VOLATILE_ volatile
182
183 /* Sanity check the ref count. If it is 0, we may be doubly zfreeing.
184 * If it is larger than max int, it has been corrupted or leaked,
185 * probably by being modified into an address (this is architecture
186 * dependent, but it's safe to assume there cannot really be max int
187 * references unless some code is leaking the io_reference without leaking
188 * object). Saturate the io_reference on release kernel if it reaches
189 * max int to avoid use after free.
190 *
191 * NOTE: The 0 test alone will not catch double zfreeing of ipc_port
192 * structs, because the io_references field is the first word of the struct,
193 * and zfree modifies that to point to the next free zone element.
194 */
195 #define IO_MAX_REFERENCES \
196 (unsigned)(~0 ^ (1 << (sizeof(int)*BYTE_SIZE - 1)))
197
198 static inline void
199 io_reference(ipc_object_t io) {
200 ipc_object_refs_t new_io_references;
201 ipc_object_refs_t old_io_references;
202
203 assert((io)->io_references > 0 &&
204 (io)->io_references < IO_MAX_REFERENCES);
205
206 do {
207 old_io_references = (io)->io_references;
208 new_io_references = old_io_references + 1;
209 if (old_io_references == IO_MAX_REFERENCES) {
210 break;
211 }
212 } while (OSCompareAndSwap(old_io_references, new_io_references,
213 &((io)->io_references)) == FALSE);
214 }
215
216
217 static inline void
218 io_release(ipc_object_t io) {
219 ipc_object_refs_t new_io_references;
220 ipc_object_refs_t old_io_references;
221
222 assert((io)->io_references > 0 &&
223 (io)->io_references < IO_MAX_REFERENCES);
224
225 do {
226 old_io_references = (io)->io_references;
227 new_io_references = old_io_references - 1;
228 if (old_io_references == IO_MAX_REFERENCES) {
229 break;
230 }
231 } while (OSCompareAndSwap(old_io_references, new_io_references,
232 &((io)->io_references)) == FALSE);
233
234 /* If we just removed the last reference count */
235 if (1 == old_io_references) {
236 /* Free the object */
237 io_free(io_otype((io)), (io));
238 }
239 }
240
241 /*
242 * Retrieve a label for use in a kernel call that takes a security
243 * label as a parameter. If necessary, io_getlabel acquires internal
244 * (not io_lock) locks, and io_unlocklabel releases them.
245 */
246
247 struct label;
248 extern struct label *io_getlabel (ipc_object_t obj);
249 #define io_unlocklabel(obj)
250
251 /*
252 * Exported interfaces
253 */
254
255 /* Take a reference to an object */
256 extern void ipc_object_reference(
257 ipc_object_t object);
258
259 /* Release a reference to an object */
260 extern void ipc_object_release(
261 ipc_object_t object);
262
263 /* Look up an object in a space */
264 extern kern_return_t ipc_object_translate(
265 ipc_space_t space,
266 mach_port_name_t name,
267 mach_port_right_t right,
268 ipc_object_t *objectp);
269
270 /* Look up two objects in a space, locking them in the order described */
271 extern kern_return_t ipc_object_translate_two(
272 ipc_space_t space,
273 mach_port_name_t name1,
274 mach_port_right_t right1,
275 ipc_object_t *objectp1,
276 mach_port_name_t name2,
277 mach_port_right_t right2,
278 ipc_object_t *objectp2);
279
280 /* Allocate a dead-name entry */
281 extern kern_return_t
282 ipc_object_alloc_dead(
283 ipc_space_t space,
284 mach_port_name_t *namep);
285
286 /* Allocate a dead-name entry, with a specific name */
287 extern kern_return_t ipc_object_alloc_dead_name(
288 ipc_space_t space,
289 mach_port_name_t name);
290
291 /* Allocate an object */
292 extern kern_return_t ipc_object_alloc(
293 ipc_space_t space,
294 ipc_object_type_t otype,
295 mach_port_type_t type,
296 mach_port_urefs_t urefs,
297 mach_port_name_t *namep,
298 ipc_object_t *objectp);
299
300 /* Allocate an object, with a specific name */
301 extern kern_return_t ipc_object_alloc_name(
302 ipc_space_t space,
303 ipc_object_type_t otype,
304 mach_port_type_t type,
305 mach_port_urefs_t urefs,
306 mach_port_name_t name,
307 ipc_object_t *objectp);
308
309 /* Convert a send type name to a received type name */
310 extern mach_msg_type_name_t ipc_object_copyin_type(
311 mach_msg_type_name_t msgt_name);
312
313 /* Copyin a capability from a space */
314 extern kern_return_t ipc_object_copyin(
315 ipc_space_t space,
316 mach_port_name_t name,
317 mach_msg_type_name_t msgt_name,
318 ipc_object_t *objectp);
319
320 /* Copyin a naked capability from the kernel */
321 extern void ipc_object_copyin_from_kernel(
322 ipc_object_t object,
323 mach_msg_type_name_t msgt_name);
324
325 /* Destroy a naked capability */
326 extern void ipc_object_destroy(
327 ipc_object_t object,
328 mach_msg_type_name_t msgt_name);
329
330 /* Destroy a naked destination capability */
331 extern void ipc_object_destroy_dest(
332 ipc_object_t object,
333 mach_msg_type_name_t msgt_name);
334
335 /* Copyout a capability, placing it into a space */
336 extern kern_return_t ipc_object_copyout(
337 ipc_space_t space,
338 ipc_object_t object,
339 mach_msg_type_name_t msgt_name,
340 boolean_t overflow,
341 mach_port_name_t *namep);
342
343 /* Copyout a capability with a name, placing it into a space */
344 extern kern_return_t ipc_object_copyout_name(
345 ipc_space_t space,
346 ipc_object_t object,
347 mach_msg_type_name_t msgt_name,
348 boolean_t overflow,
349 mach_port_name_t name);
350
351 /* Translate/consume the destination right of a message */
352 extern void ipc_object_copyout_dest(
353 ipc_space_t space,
354 ipc_object_t object,
355 mach_msg_type_name_t msgt_name,
356 mach_port_name_t *namep);
357
358 /* Rename an entry in a space */
359 extern kern_return_t ipc_object_rename(
360 ipc_space_t space,
361 mach_port_name_t oname,
362 mach_port_name_t nname);
363
364 #endif /* _IPC_IPC_OBJECT_H_ */