summaryrefslogtreecommitdiffstats
path: root/sys/security/mac/mac_policy.h
diff options
context:
space:
mode:
authorjhb <jhb@FreeBSD.org>2008-01-08 21:58:16 +0000
committerjhb <jhb@FreeBSD.org>2008-01-08 21:58:16 +0000
commit8cd9437636744162d1427275b2fe66cf8ccef25c (patch)
tree49b07dc757aae71e0a64eb4939cde4037af60a24 /sys/security/mac/mac_policy.h
parent23d78439c96372baa4a3c2847df65f8e11455ae7 (diff)
downloadFreeBSD-src-8cd9437636744162d1427275b2fe66cf8ccef25c.zip
FreeBSD-src-8cd9437636744162d1427275b2fe66cf8ccef25c.tar.gz
Add a new file descriptor type for IPC shared memory objects and use it to
implement shm_open(2) and shm_unlink(2) in the kernel: - Each shared memory file descriptor is associated with a swap-backed vm object which provides the backing store. Each descriptor starts off with a size of zero, but the size can be altered via ftruncate(2). The shared memory file descriptors also support fstat(2). read(2), write(2), ioctl(2), select(2), poll(2), and kevent(2) are not supported on shared memory file descriptors. - shm_open(2) and shm_unlink(2) are now implemented as system calls that manage shared memory file descriptors. The virtual namespace that maps pathnames to shared memory file descriptors is implemented as a hash table where the hash key is generated via the 32-bit Fowler/Noll/Vo hash of the pathname. - As an extension, the constant 'SHM_ANON' may be specified in place of the path argument to shm_open(2). In this case, an unnamed shared memory file descriptor will be created similar to the IPC_PRIVATE key for shmget(2). Note that the shared memory object can still be shared among processes by sharing the file descriptor via fork(2) or sendmsg(2), but it is unnamed. This effectively serves to implement the getmemfd() idea bandied about the lists several times over the years. - The backing store for shared memory file descriptors are garbage collected when they are not referenced by any open file descriptors or the shm_open(2) virtual namespace. Submitted by: dillon, peter (previous versions) Submitted by: rwatson (I based this on his version) Reviewed by: alc (suggested converting getmemfd() to shm_open())
Diffstat (limited to 'sys/security/mac/mac_policy.h')
-rw-r--r--sys/security/mac/mac_policy.h28
1 files changed, 28 insertions, 0 deletions
diff --git a/sys/security/mac/mac_policy.h b/sys/security/mac/mac_policy.h
index 3d494db..c7aef52 100644
--- a/sys/security/mac/mac_policy.h
+++ b/sys/security/mac/mac_policy.h
@@ -83,6 +83,7 @@ struct pipepair;
struct proc;
struct sbuf;
struct semid_kernel;
+struct shmfd;
struct shmid_kernel;
struct sockaddr;
struct socket;
@@ -305,6 +306,24 @@ typedef void (*mpo_posixsem_create_t)(struct ucred *cred,
typedef void (*mpo_posixsem_destroy_label_t)(struct label *label);
typedef void (*mpo_posixsem_init_label_t)(struct label *label);
+typedef int (*mpo_posixshm_check_mmap_t)(struct ucred *cred,
+ struct shmfd *shmfd, struct label *shmlabel, int prot,
+ int flags);
+typedef int (*mpo_posixshm_check_open_t)(struct ucred *cred,
+ struct shmfd *shmfd, struct label *shmlabel);
+typedef int (*mpo_posixshm_check_stat_t)(struct ucred *active_cred,
+ struct ucred *file_cred, struct shmfd *shmfd,
+ struct label *shmlabel);
+typedef int (*mpo_posixshm_check_truncate_t)(struct ucred *active_cred,
+ struct ucred *file_cred, struct shmfd *shmfd,
+ struct label *shmlabel);
+typedef int (*mpo_posixshm_check_unlink_t)(struct ucred *cred,
+ struct shmfd *shmfd, struct label *shmlabel);
+typedef void (*mpo_posixshm_create_t)(struct ucred *cred,
+ struct shmfd *shmfd, struct label *shmlabel);
+typedef void (*mpo_posixshm_destroy_label_t)(struct label *label);
+typedef void (*mpo_posixshm_init_label_t)(struct label *label);
+
typedef int (*mpo_priv_check_t)(struct ucred *cred, int priv);
typedef int (*mpo_priv_grant_t)(struct ucred *cred, int priv);
@@ -733,6 +752,15 @@ struct mac_policy_ops {
mpo_posixsem_destroy_label_t mpo_posixsem_destroy_label;
mpo_posixsem_init_label_t mpo_posixsem_init_label;
+ mpo_posixshm_check_mmap_t mpo_posixshm_check_mmap;
+ mpo_posixshm_check_open_t mpo_posixshm_check_open;
+ mpo_posixshm_check_stat_t mpo_posixshm_check_stat;
+ mpo_posixshm_check_truncate_t mpo_posixshm_check_truncate;
+ mpo_posixshm_check_unlink_t mpo_posixshm_check_unlink;
+ mpo_posixshm_create_t mpo_posixshm_create;
+ mpo_posixshm_destroy_label_t mpo_posixshm_destroy_label;
+ mpo_posixshm_init_label_t mpo_posixshm_init_label;
+
mpo_priv_check_t mpo_priv_check;
mpo_priv_grant_t mpo_priv_grant;
OpenPOWER on IntegriCloud