diff options
author | jonathan <jonathan@FreeBSD.org> | 2011-08-18 22:51:30 +0000 |
---|---|---|
committer | jonathan <jonathan@FreeBSD.org> | 2011-08-18 22:51:30 +0000 |
commit | 5ecd1c9d4080f3ae8a48c02523542b308b562160 (patch) | |
tree | ec80efcada771dd68fe28d71eaf850289af0e772 /sys/conf | |
parent | c902e656105666eb86ca08b9d534253d3f831d46 (diff) | |
download | FreeBSD-src-5ecd1c9d4080f3ae8a48c02523542b308b562160.zip FreeBSD-src-5ecd1c9d4080f3ae8a48c02523542b308b562160.tar.gz |
Add experimental support for process descriptors
A "process descriptor" file descriptor is used to manage processes
without using the PID namespace. This is required for Capsicum's
Capability Mode, where the PID namespace is unavailable.
New system calls pdfork(2) and pdkill(2) offer the functional equivalents
of fork(2) and kill(2). pdgetpid(2) allows querying the PID of the remote
process for debugging purposes. The currently-unimplemented pdwait(2) will,
in the future, allow querying rusage/exit status. In the interim, poll(2)
may be used to check (and wait for) process termination.
When a process is referenced by a process descriptor, it does not issue
SIGCHLD to the parent, making it suitable for use in libraries---a common
scenario when using library compartmentalisation from within large
applications (such as web browsers). Some observers may note a similarity
to Mach task ports; process descriptors provide a subset of this behaviour,
but in a UNIX style.
This feature is enabled by "options PROCDESC", but as with several other
Capsicum kernel features, is not enabled by default in GENERIC 9.0.
Reviewed by: jhb, kib
Approved by: re (kib), mentor (rwatson)
Sponsored by: Google Inc
Diffstat (limited to 'sys/conf')
-rw-r--r-- | sys/conf/NOTES | 3 | ||||
-rw-r--r-- | sys/conf/files | 1 | ||||
-rw-r--r-- | sys/conf/options | 1 |
3 files changed, 5 insertions, 0 deletions
diff --git a/sys/conf/NOTES b/sys/conf/NOTES index 4a9ec35..59f02c8 100644 --- a/sys/conf/NOTES +++ b/sys/conf/NOTES @@ -1159,6 +1159,9 @@ options MAC_TEST options CAPABILITIES # fine-grained rights on file descriptors options CAPABILITY_MODE # sandboxes with no global namespace access +# Support for process descriptors +options PROCDESC + ##################################################################### # CLOCK OPTIONS diff --git a/sys/conf/files b/sys/conf/files index 0dc814e..5c5d92d 100644 --- a/sys/conf/files +++ b/sys/conf/files @@ -2412,6 +2412,7 @@ kern/subr_witness.c optional witness kern/sys_capability.c standard kern/sys_generic.c standard kern/sys_pipe.c standard +kern/sys_procdesc.c standard kern/sys_process.c standard kern/sys_socket.c standard kern/syscalls.c standard diff --git a/sys/conf/options b/sys/conf/options index f7026c1..27fdbed 100644 --- a/sys/conf/options +++ b/sys/conf/options @@ -149,6 +149,7 @@ PPC_DEBUG opt_ppc.h PPC_PROBE_CHIPSET opt_ppc.h PPS_SYNC opt_ntp.h PREEMPTION opt_sched.h +PROCDESC opt_procdesc.h QUOTA SCHED_4BSD opt_sched.h SCHED_STATS opt_sched.h |