diff options
author | jhb <jhb@FreeBSD.org> | 2008-01-08 21:58:16 +0000 |
---|---|---|
committer | jhb <jhb@FreeBSD.org> | 2008-01-08 21:58:16 +0000 |
commit | 8cd9437636744162d1427275b2fe66cf8ccef25c (patch) | |
tree | 49b07dc757aae71e0a64eb4939cde4037af60a24 /sys/security/mac/mac_policy.h | |
parent | 23d78439c96372baa4a3c2847df65f8e11455ae7 (diff) | |
download | FreeBSD-src-8cd9437636744162d1427275b2fe66cf8ccef25c.zip FreeBSD-src-8cd9437636744162d1427275b2fe66cf8ccef25c.tar.gz |
Add a new file descriptor type for IPC shared memory objects and use it to
implement shm_open(2) and shm_unlink(2) in the kernel:
- Each shared memory file descriptor is associated with a swap-backed vm
object which provides the backing store. Each descriptor starts off with
a size of zero, but the size can be altered via ftruncate(2). The shared
memory file descriptors also support fstat(2). read(2), write(2),
ioctl(2), select(2), poll(2), and kevent(2) are not supported on shared
memory file descriptors.
- shm_open(2) and shm_unlink(2) are now implemented as system calls that
manage shared memory file descriptors. The virtual namespace that maps
pathnames to shared memory file descriptors is implemented as a hash
table where the hash key is generated via the 32-bit Fowler/Noll/Vo hash
of the pathname.
- As an extension, the constant 'SHM_ANON' may be specified in place of the
path argument to shm_open(2). In this case, an unnamed shared memory
file descriptor will be created similar to the IPC_PRIVATE key for
shmget(2). Note that the shared memory object can still be shared among
processes by sharing the file descriptor via fork(2) or sendmsg(2), but
it is unnamed. This effectively serves to implement the getmemfd() idea
bandied about the lists several times over the years.
- The backing store for shared memory file descriptors are garbage
collected when they are not referenced by any open file descriptors or
the shm_open(2) virtual namespace.
Submitted by: dillon, peter (previous versions)
Submitted by: rwatson (I based this on his version)
Reviewed by: alc (suggested converting getmemfd() to shm_open())
Diffstat (limited to 'sys/security/mac/mac_policy.h')
-rw-r--r-- | sys/security/mac/mac_policy.h | 28 |
1 files changed, 28 insertions, 0 deletions
diff --git a/sys/security/mac/mac_policy.h b/sys/security/mac/mac_policy.h index 3d494db..c7aef52 100644 --- a/sys/security/mac/mac_policy.h +++ b/sys/security/mac/mac_policy.h @@ -83,6 +83,7 @@ struct pipepair; struct proc; struct sbuf; struct semid_kernel; +struct shmfd; struct shmid_kernel; struct sockaddr; struct socket; @@ -305,6 +306,24 @@ typedef void (*mpo_posixsem_create_t)(struct ucred *cred, typedef void (*mpo_posixsem_destroy_label_t)(struct label *label); typedef void (*mpo_posixsem_init_label_t)(struct label *label); +typedef int (*mpo_posixshm_check_mmap_t)(struct ucred *cred, + struct shmfd *shmfd, struct label *shmlabel, int prot, + int flags); +typedef int (*mpo_posixshm_check_open_t)(struct ucred *cred, + struct shmfd *shmfd, struct label *shmlabel); +typedef int (*mpo_posixshm_check_stat_t)(struct ucred *active_cred, + struct ucred *file_cred, struct shmfd *shmfd, + struct label *shmlabel); +typedef int (*mpo_posixshm_check_truncate_t)(struct ucred *active_cred, + struct ucred *file_cred, struct shmfd *shmfd, + struct label *shmlabel); +typedef int (*mpo_posixshm_check_unlink_t)(struct ucred *cred, + struct shmfd *shmfd, struct label *shmlabel); +typedef void (*mpo_posixshm_create_t)(struct ucred *cred, + struct shmfd *shmfd, struct label *shmlabel); +typedef void (*mpo_posixshm_destroy_label_t)(struct label *label); +typedef void (*mpo_posixshm_init_label_t)(struct label *label); + typedef int (*mpo_priv_check_t)(struct ucred *cred, int priv); typedef int (*mpo_priv_grant_t)(struct ucred *cred, int priv); @@ -733,6 +752,15 @@ struct mac_policy_ops { mpo_posixsem_destroy_label_t mpo_posixsem_destroy_label; mpo_posixsem_init_label_t mpo_posixsem_init_label; + mpo_posixshm_check_mmap_t mpo_posixshm_check_mmap; + mpo_posixshm_check_open_t mpo_posixshm_check_open; + mpo_posixshm_check_stat_t mpo_posixshm_check_stat; + mpo_posixshm_check_truncate_t mpo_posixshm_check_truncate; + mpo_posixshm_check_unlink_t mpo_posixshm_check_unlink; + mpo_posixshm_create_t mpo_posixshm_create; + mpo_posixshm_destroy_label_t mpo_posixshm_destroy_label; + mpo_posixshm_init_label_t mpo_posixshm_init_label; + mpo_priv_check_t mpo_priv_check; mpo_priv_grant_t mpo_priv_grant; |