2 * Copyright (c) 2000-2006 Apple Computer, Inc. All rights reserved.
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
32 * Mach Operating System
33 * Copyright (c) 1991,1990,1989,1988,1987 Carnegie Mellon University
34 * All Rights Reserved.
36 * Permission to use, copy, modify and distribute this software and its
37 * documentation is hereby granted, provided that both the copyright
38 * notice and this permission notice appear in all copies of the
39 * software, derivative works or modified versions, and any portions
40 * thereof, and that both notices appear in supporting documentation.
42 * CARNEGIE MELLON ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS"
43 * CONDITION. CARNEGIE MELLON DISCLAIMS ANY LIABILITY OF ANY KIND FOR
44 * ANY DAMAGES WHATSOEVER RESULTING FROM THE USE OF THIS SOFTWARE.
46 * Carnegie Mellon requests users of this software to return to
48 * Software Distribution Coordinator or Software.Distribution@CS.CMU.EDU
49 * School of Computer Science
50 * Carnegie Mellon University
51 * Pittsburgh PA 15213-3890
53 * any improvements or extensions that they make and grant Carnegie Mellon
54 * the rights to redistribute these changes.
57 * NOTICE: This file was modified by McAfee Research in 2004 to introduce
58 * support for mandatory and extensible security protections. This notice
59 * is included in support of clause 2.2 (b) of the Apple Public License,
67 * Definition of a Mach port
69 * Mach ports are the endpoints to Mach-implemented communications
70 * channels (usually uni-directional message queues, but other types
73 * Unique collections of these endpoints are maintained for each
74 * Mach task. Each Mach port in the task's collection is given a
75 * [task-local] name to identify it - and the the various "rights"
76 * held by the task for that specific endpoint.
78 * This header defines the types used to identify these Mach ports
79 * and the various rights associated with them. For more info see:
81 * <mach/mach_port.h> - manipulation of port rights in a given space
82 * <mach/message.h> - message queue [and port right passing] mechanism
89 #include <sys/cdefs.h>
91 #include <mach/boolean.h>
92 #include <mach/machine/vm_types.h>
95 * mach_port_name_t - the local identity for a Mach port
97 * The name is Mach port namespace specific. It is used to
98 * identify the rights held for that port by the task whose
99 * namespace is implied [or specifically provided].
101 * Use of this type usually implies just a name - no rights.
102 * See mach_port_t for a type that implies a "named right."
106 typedef natural_t mach_port_name_t
;
107 typedef mach_port_name_t
*mach_port_name_array_t
;
112 * mach_port_t - a named port right
114 * In the kernel, "rights" are represented [named] by pointers to
115 * the ipc port object in question. There is no port namespace for the
116 * rights to be collected.
118 * Actually, there is namespace for the kernel task. But most kernel
119 * code - including, but not limited to, Mach IPC code - lives in the
120 * limbo between the current user-level task and the "next" task. Very
121 * little of the kernel code runs in full kernel task context. So very
122 * little of it gets to use the kernel task's port name space.
124 * Because of this implementation approach, all in-kernel rights for
125 * a given port coalesce [have the same name/pointer]. The actual
126 * references are counted in the port itself. It is up to the kernel
127 * code in question to "just remember" how many [and what type of]
128 * rights it holds and handle them appropriately.
132 #ifndef MACH_KERNEL_PRIVATE
134 * For kernel code that resides outside of Mach proper, we opaque the
135 * port structure definition.
139 #endif /* MACH_KERNEL_PRIVATE */
141 typedef struct ipc_port
*ipc_port_t
;
143 #define IPC_PORT_NULL ((ipc_port_t) NULL)
144 #define IPC_PORT_DEAD ((ipc_port_t)~0UL)
145 #define IPC_PORT_VALID(port) \
146 ((port) != IPC_PORT_NULL && (port) != IPC_PORT_DEAD)
148 typedef ipc_port_t mach_port_t
;
151 * Since the 32-bit and 64-bit representations of ~0 are different,
152 * explicitly handle MACH_PORT_DEAD
155 #define CAST_MACH_PORT_TO_NAME(x) ((mach_port_name_t)(uintptr_t)(x))
156 #define CAST_MACH_NAME_TO_PORT(x) ((x) == MACH_PORT_DEAD ? (mach_port_t)IPC_PORT_DEAD : (mach_port_t)(uintptr_t)(x))
161 * mach_port_t - a named port right
163 * In user-space, "rights" are represented by the name of the
164 * right in the Mach port namespace. Even so, this type is
165 * presented as a unique one to more clearly denote the presence
166 * of a right coming along with the name.
168 * Often, various rights for a port held in a single name space
169 * will coalesce and are, therefore, be identified by a single name
170 * [this is the case for send and receive rights]. But not
171 * always [send-once rights currently get a unique name for
176 #include <sys/_types.h>
177 #include <sys/_types/_mach_port_t.h>
181 typedef mach_port_t
*mach_port_array_t
;
184 * MACH_PORT_NULL is a legal value that can be carried in messages.
185 * It indicates the absence of any port or port rights. (A port
186 * argument keeps the message from being "simple", even if the
187 * value is MACH_PORT_NULL.) The value MACH_PORT_DEAD is also a legal
188 * value that can be carried in messages. It indicates
189 * that a port right was present, but it died.
192 #if defined(XNU_KERNEL_PRIVATE) && defined(__cplusplus)
193 #define MACH_PORT_NULL NULL
195 #define MACH_PORT_NULL 0 /* intentional loose typing */
197 #define MACH_PORT_DEAD ((mach_port_name_t) ~0)
198 #define MACH_PORT_VALID(name) \
199 (((name) != MACH_PORT_NULL) && \
200 ((name) != MACH_PORT_DEAD))
204 * For kernel-selected [assigned] port names, the name is
205 * comprised of two parts: a generation number and an index.
206 * This approach keeps the exact same name from being generated
207 * and reused too quickly [to catch right/reference counting bugs].
208 * The dividing line between the constituent parts is exposed so
209 * that efficient "mach_port_name_t to data structure pointer"
210 * conversion implementation can be made. But it is possible
211 * for user-level code to assign their own names to Mach ports.
212 * These are not required to participate in this algorithm. So
213 * care should be taken before "assuming" this model.
219 #define MACH_PORT_INDEX(name) ((name) >> 8)
220 #define MACH_PORT_GEN(name) (((name) & 0xff) << 24)
221 #define MACH_PORT_MAKE(index, gen) \
222 (((index) << 8) | (gen) >> 24)
224 #else /* NO_PORT_GEN */
226 #define MACH_PORT_INDEX(name) (name)
227 #define MACH_PORT_GEN(name) (0)
228 #define MACH_PORT_MAKE(index, gen) (index)
230 #endif /* NO_PORT_GEN */
234 * These are the different rights a task may have for a port.
235 * The MACH_PORT_RIGHT_* definitions are used as arguments
236 * to mach_port_allocate, mach_port_get_refs, etc, to specify
237 * a particular right to act upon. The mach_port_names and
238 * mach_port_type calls return bitmasks using the MACH_PORT_TYPE_*
239 * definitions. This is because a single name may denote
243 typedef natural_t mach_port_right_t
;
245 #define MACH_PORT_RIGHT_SEND ((mach_port_right_t) 0)
246 #define MACH_PORT_RIGHT_RECEIVE ((mach_port_right_t) 1)
247 #define MACH_PORT_RIGHT_SEND_ONCE ((mach_port_right_t) 2)
248 #define MACH_PORT_RIGHT_PORT_SET ((mach_port_right_t) 3)
249 #define MACH_PORT_RIGHT_DEAD_NAME ((mach_port_right_t) 4)
250 #define MACH_PORT_RIGHT_LABELH ((mach_port_right_t) 5) /* obsolete right */
251 #define MACH_PORT_RIGHT_NUMBER ((mach_port_right_t) 6) /* right not implemented */
253 #ifdef MACH_KERNEL_PRIVATE
254 #define MACH_PORT_RIGHT_VALID_TRANSLATE(right) \
255 ((right) >= MACH_PORT_RIGHT_SEND && (right) <= MACH_PORT_RIGHT_DEAD_NAME)
258 typedef natural_t mach_port_type_t
;
259 typedef mach_port_type_t
*mach_port_type_array_t
;
261 #define MACH_PORT_TYPE(right) \
262 ((mach_port_type_t)(((mach_port_type_t) 1) \
263 << ((right) + ((mach_port_right_t) 16))))
264 #define MACH_PORT_TYPE_NONE ((mach_port_type_t) 0L)
265 #define MACH_PORT_TYPE_SEND MACH_PORT_TYPE(MACH_PORT_RIGHT_SEND)
266 #define MACH_PORT_TYPE_RECEIVE MACH_PORT_TYPE(MACH_PORT_RIGHT_RECEIVE)
267 #define MACH_PORT_TYPE_SEND_ONCE MACH_PORT_TYPE(MACH_PORT_RIGHT_SEND_ONCE)
268 #define MACH_PORT_TYPE_PORT_SET MACH_PORT_TYPE(MACH_PORT_RIGHT_PORT_SET)
269 #define MACH_PORT_TYPE_DEAD_NAME MACH_PORT_TYPE(MACH_PORT_RIGHT_DEAD_NAME)
270 #define MACH_PORT_TYPE_LABELH MACH_PORT_TYPE(MACH_PORT_RIGHT_LABELH) /* obsolete */
273 #ifdef MACH_KERNEL_PRIVATE
274 /* Holder used to have a receive right - remembered to filter exceptions */
275 #define MACH_PORT_TYPE_EX_RECEIVE MACH_PORT_TYPE_LABELH
278 /* Convenient combinations. */
280 #define MACH_PORT_TYPE_SEND_RECEIVE \
281 (MACH_PORT_TYPE_SEND|MACH_PORT_TYPE_RECEIVE)
282 #define MACH_PORT_TYPE_SEND_RIGHTS \
283 (MACH_PORT_TYPE_SEND|MACH_PORT_TYPE_SEND_ONCE)
284 #define MACH_PORT_TYPE_PORT_RIGHTS \
285 (MACH_PORT_TYPE_SEND_RIGHTS|MACH_PORT_TYPE_RECEIVE)
286 #define MACH_PORT_TYPE_PORT_OR_DEAD \
287 (MACH_PORT_TYPE_PORT_RIGHTS|MACH_PORT_TYPE_DEAD_NAME)
288 #define MACH_PORT_TYPE_ALL_RIGHTS \
289 (MACH_PORT_TYPE_PORT_OR_DEAD|MACH_PORT_TYPE_PORT_SET)
291 /* Dummy type bits that mach_port_type/mach_port_names can return. */
293 #define MACH_PORT_TYPE_DNREQUEST 0x80000000
294 #define MACH_PORT_TYPE_SPREQUEST 0x40000000
295 #define MACH_PORT_TYPE_SPREQUEST_DELAYED 0x20000000
297 /* User-references for capabilities. */
299 typedef natural_t mach_port_urefs_t
;
300 typedef integer_t mach_port_delta_t
; /* change in urefs */
302 /* Attributes of ports. (See mach_port_get_receive_status.) */
304 typedef natural_t mach_port_seqno_t
; /* sequence number */
305 typedef natural_t mach_port_mscount_t
; /* make-send count */
306 typedef natural_t mach_port_msgcount_t
; /* number of msgs */
307 typedef natural_t mach_port_rights_t
; /* number of rights */
310 * Are there outstanding send rights for a given port?
312 #define MACH_PORT_SRIGHTS_NONE 0 /* no srights */
313 #define MACH_PORT_SRIGHTS_PRESENT 1 /* srights */
314 typedef unsigned int mach_port_srights_t
; /* status of send rights */
316 typedef struct mach_port_status
{
317 mach_port_rights_t mps_pset
; /* count of containing port sets */
318 mach_port_seqno_t mps_seqno
; /* sequence number */
319 mach_port_mscount_t mps_mscount
; /* make-send count */
320 mach_port_msgcount_t mps_qlimit
; /* queue limit */
321 mach_port_msgcount_t mps_msgcount
; /* number in the queue */
322 mach_port_rights_t mps_sorights
; /* how many send-once rights */
323 boolean_t mps_srights
; /* do send rights exist? */
324 boolean_t mps_pdrequest
; /* port-deleted requested? */
325 boolean_t mps_nsrequest
; /* no-senders requested? */
326 natural_t mps_flags
; /* port flags */
327 } mach_port_status_t
;
329 /* System-wide values for setting queue limits on a port */
330 #define MACH_PORT_QLIMIT_ZERO (0)
331 #define MACH_PORT_QLIMIT_BASIC (5)
332 #define MACH_PORT_QLIMIT_SMALL (16)
333 #define MACH_PORT_QLIMIT_LARGE (1024)
334 #define MACH_PORT_QLIMIT_KERNEL (65534)
335 #define MACH_PORT_QLIMIT_MIN MACH_PORT_QLIMIT_ZERO
336 #define MACH_PORT_QLIMIT_DEFAULT MACH_PORT_QLIMIT_BASIC
337 #define MACH_PORT_QLIMIT_MAX MACH_PORT_QLIMIT_LARGE
339 typedef struct mach_port_limits
{
340 mach_port_msgcount_t mpl_qlimit
; /* number of msgs */
341 } mach_port_limits_t
;
343 /* Possible values for mps_flags (part of mach_port_status_t) */
344 #define MACH_PORT_STATUS_FLAG_TEMPOWNER 0x01
345 #define MACH_PORT_STATUS_FLAG_GUARDED 0x02
346 #define MACH_PORT_STATUS_FLAG_STRICT_GUARD 0x04
347 #define MACH_PORT_STATUS_FLAG_IMP_DONATION 0x08
348 #define MACH_PORT_STATUS_FLAG_REVIVE 0x10
349 #define MACH_PORT_STATUS_FLAG_TASKPTR 0x20
350 #define MACH_PORT_STATUS_FLAG_GUARD_IMMOVABLE_RECEIVE 0x40
351 #define MACH_PORT_STATUS_FLAG_NO_GRANT 0x80
353 typedef struct mach_port_info_ext
{
354 mach_port_status_t mpie_status
;
355 mach_port_msgcount_t mpie_boost_cnt
;
356 uint32_t reserved
[6];
357 } mach_port_info_ext_t
;
359 typedef integer_t
*mach_port_info_t
; /* varying array of natural_t */
361 /* Flavors for mach_port_get/set_attributes() */
362 typedef int mach_port_flavor_t
;
363 #define MACH_PORT_LIMITS_INFO 1 /* uses mach_port_limits_t */
364 #define MACH_PORT_RECEIVE_STATUS 2 /* uses mach_port_status_t */
365 #define MACH_PORT_DNREQUESTS_SIZE 3 /* info is int */
366 #define MACH_PORT_TEMPOWNER 4 /* indicates receive right will be reassigned to another task */
367 #define MACH_PORT_IMPORTANCE_RECEIVER 5 /* indicates recieve right accepts priority donation */
368 #define MACH_PORT_DENAP_RECEIVER 6 /* indicates receive right accepts de-nap donation */
369 #define MACH_PORT_INFO_EXT 7 /* uses mach_port_info_ext_t */
371 #define MACH_PORT_LIMITS_INFO_COUNT ((natural_t) \
372 (sizeof(mach_port_limits_t)/sizeof(natural_t)))
373 #define MACH_PORT_RECEIVE_STATUS_COUNT ((natural_t) \
374 (sizeof(mach_port_status_t)/sizeof(natural_t)))
375 #define MACH_PORT_DNREQUESTS_SIZE_COUNT 1
376 #define MACH_PORT_INFO_EXT_COUNT ((natural_t) \
377 (sizeof(mach_port_info_ext_t)/sizeof(natural_t)))
379 * Structure used to pass information about port allocation requests.
380 * Must be padded to 64-bits total length.
382 typedef struct mach_port_qos
{
383 unsigned int name
:1; /* name given */
384 unsigned int prealloc
:1; /* prealloced message */
389 /* Mach Port Guarding definitions */
392 * Flags for mach_port_options (used for
393 * invocation of mach_port_construct).
394 * Indicates attributes to be set for the newly
397 #define MPO_CONTEXT_AS_GUARD 0x01 /* Add guard to the port */
398 #define MPO_QLIMIT 0x02 /* Set qlimit for the port msg queue */
399 #define MPO_TEMPOWNER 0x04 /* Set the tempowner bit of the port */
400 #define MPO_IMPORTANCE_RECEIVER 0x08 /* Mark the port as importance receiver */
401 #define MPO_INSERT_SEND_RIGHT 0x10 /* Insert a send right for the port */
402 #define MPO_STRICT 0x20 /* Apply strict guarding for port */
403 #define MPO_DENAP_RECEIVER 0x40 /* Mark the port as App de-nap receiver */
404 #define MPO_IMMOVABLE_RECEIVE 0x80 /* Mark the port as immovable; protected by the guard context */
405 #define MPO_FILTER_MSG 0x100 /* Allow message filtering */
406 #define MPO_TG_BLOCK_TRACKING 0x200 /* Track blocking relationship for thread group during sync IPC */
409 * Structure to define optional attributes for a newly
412 typedef struct mach_port_options
{
413 uint32_t flags
; /* Flags defining attributes for port */
414 mach_port_limits_t mpl
; /* Message queue limit for port */
416 uint64_t reserved
[2]; /* Reserved */
417 mach_port_name_t work_interval_port
; /* Work interval port */
419 }mach_port_options_t
;
421 typedef mach_port_options_t
*mach_port_options_ptr_t
;
424 * EXC_GUARD represents a guard violation for both
425 * mach ports and file descriptors. GUARD_TYPE_ is used
426 * to differentiate among them.
428 #define GUARD_TYPE_MACH_PORT 0x1
430 /* Reasons for exception for a guarded mach port */
431 enum mach_port_guard_exception_codes
{
432 kGUARD_EXC_DESTROY
= 1u << 0,
433 kGUARD_EXC_MOD_REFS
= 1u << 1,
434 kGUARD_EXC_SET_CONTEXT
= 1u << 2,
435 kGUARD_EXC_UNGUARDED
= 1u << 3,
436 kGUARD_EXC_INCORRECT_GUARD
= 1u << 4,
437 kGUARD_EXC_IMMOVABLE
= 1u << 5,
438 kGUARD_EXC_STRICT_REPLY
= 1u << 6,
439 kGUARD_EXC_MSG_FILTERED
= 1u << 7,
440 /* start of [optionally] non-fatal guards */
441 kGUARD_EXC_INVALID_RIGHT
= 1u << 8,
442 kGUARD_EXC_INVALID_NAME
= 1u << 9,
443 kGUARD_EXC_INVALID_VALUE
= 1u << 10,
444 kGUARD_EXC_INVALID_ARGUMENT
= 1u << 11,
445 kGUARD_EXC_RIGHT_EXISTS
= 1u << 12,
446 kGUARD_EXC_KERN_NO_SPACE
= 1u << 13,
447 kGUARD_EXC_KERN_FAILURE
= 1u << 14,
448 kGUARD_EXC_KERN_RESOURCE
= 1u << 15,
449 kGUARD_EXC_SEND_INVALID_REPLY
= 1u << 16,
450 kGUARD_EXC_SEND_INVALID_VOUCHER
= 1u << 17,
451 kGUARD_EXC_SEND_INVALID_RIGHT
= 1u << 18,
452 kGUARD_EXC_RCV_INVALID_NAME
= 1u << 19,
453 kGUARD_EXC_RCV_GUARDED_DESC
= 1u << 20, /* should never be fatal; for development only */
456 #define MAX_FATAL_kGUARD_EXC_CODE (1u << 6)
459 * These flags are used as bits in the subcode of kGUARD_EXC_STRICT_REPLY exceptions.
461 #define MPG_FLAGS_STRICT_REPLY_INVALID_REPLY_DISP (0x01ull << 56)
462 #define MPG_FLAGS_STRICT_REPLY_INVALID_REPLY_PORT (0x02ull << 56)
463 #define MPG_FLAGS_STRICT_REPLY_INVALID_VOUCHER (0x04ull << 56)
464 #define MPG_FLAGS_STRICT_REPLY_NO_BANK_ATTR (0x08ull << 56)
465 #define MPG_FLAGS_STRICT_REPLY_MISMATCHED_PERSONA (0x10ull << 56)
466 #define MPG_FLAGS_STRICT_REPLY_MASK (0xffull << 56)
469 * Flags for mach_port_guard_with_flags. These flags extend
470 * the attributes associated with a guarded port.
472 #define MPG_STRICT 0x01 /* Apply strict guarding for a port */
473 #define MPG_IMMOVABLE_RECEIVE 0x02 /* Receive right cannot be moved out of the space */
475 #if !__DARWIN_UNIX03 && !defined(_NO_PORT_T_FROM_MACH)
477 * Mach 3.0 renamed everything to have mach_ in front of it.
478 * These types and macros are provided for backward compatibility
479 * but are deprecated.
481 typedef mach_port_t port_t
;
482 typedef mach_port_name_t port_name_t
;
483 typedef mach_port_name_t
*port_name_array_t
;
485 #define PORT_NULL ((port_t) 0)
486 #define PORT_DEAD ((port_t) ~0)
487 #define PORT_VALID(name) \
488 ((port_t)(name) != PORT_NULL && (port_t)(name) != PORT_DEAD)
490 #endif /* !__DARWIN_UNIX03 && !_NO_PORT_T_FROM_MACH */
492 #endif /* _MACH_PORT_H_ */