Skip to content

Commit

Permalink
file-system session: root dir via session label
Browse files Browse the repository at this point in the history
This patch changes the way of how the client-selected sub directory is
communicated to the server. The former opaque session argument is now
passed as last label element, which allows for the flexible tweaking
of this argument by init's session-routing and label-rewriting
mechansims. In particular, it alleviates the need for creating chroot
component instances.

This change requires the following four adaptations at the
configuration level:

- Each file-system session request must now carry a path starting
  with / as last session arguments. Hence, <vfs> <fs> nodes that
  feature a 'label' attributes must extend the attribute value
  with " -> /". For <fs> nodes with no label attribute, "/" is
  used as last label argument by default.

- For matching session-routing rules at init's configuration,
  the matching of full labels should be replaced by 'label_prefix'
  matches, excluding the last (path) argument.

- Wherever a label of a file-system session is rewritten by using
  init's 'label' attribute of a <parent> or <child> target node,
  the new attribute 'identity' should be used instead. This replaces
  the identity part of the label while preserving the client's
  directory argument.

- Analogously to the matching of session-routing rules, server-side
  policy-selection rules that formerly matched a concrete 'label'
  must be changed to match a 'label_prefix' instead.

As a good practice, 'label_prefix' values should end with " ->" if
possible, which clearly delimits the identity part of the label
used by the matching.

Issue genodelabs#5445
  • Loading branch information
nfeske committed Feb 13, 2025
1 parent a928c45 commit 6fa5ec0
Show file tree
Hide file tree
Showing 74 changed files with 382 additions and 368 deletions.
16 changes: 8 additions & 8 deletions repos/base-linux/run/lx_fs_notify.run
Original file line number Diff line number Diff line change
Expand Up @@ -47,10 +47,10 @@ install_config {
<start name="lx_fs" caps="200" ram="4M" ld="no">
<provides> <service name="File_system"/> </provides>
<config>
<policy label_prefix="fs_rom_config" root="/lx_fs_notify" writeable="no"/>
<policy label_prefix="fs_rom_test" root="/lx_fs_notify/test" writeable="no"/>
<policy label_suffix="templates" root="/lx_fs_notify/templates" writeable="yes"/>
<policy label_suffix="test" root="/lx_fs_notify/test" writeable="yes"/>
<policy label_prefix="fs_rom_config" root="/lx_fs_notify" writeable="no"/>
<policy label_prefix="fs_rom_test" root="/lx_fs_notify/test" writeable="no"/>
<policy label_suffix="templates -> /" root="/lx_fs_notify/templates" writeable="yes"/>
<policy label_suffix="test -> /" root="/lx_fs_notify/test" writeable="yes"/>
</config>
</start>

Expand Down Expand Up @@ -117,8 +117,8 @@ set init_run_fwrite_test {
<log/>
<null/>
</dir>
<dir name="templates"> <fs label="templates"/> </dir>
<dir name="test"> <fs label="test"/> </dir>
<dir name="templates"> <fs label="templates -> /"/> </dir>
<dir name="test"> <fs label="test -> /"/> </dir>
</vfs>
<arg value="test-file_writer"/>
<arg value="--fwrite"/>
Expand Down Expand Up @@ -153,8 +153,8 @@ set init_run_write_test {
<log/>
<null/>
</dir>
<dir name="templates"> <fs label="templates"/> </dir>
<dir name="test"> <fs label="test"/> </dir>
<dir name="templates"> <fs label="templates -> /"/> </dir>
<dir name="test"> <fs label="test -> /"/> </dir>
</vfs>
<arg value="test-file_writer"/>
<arg value="--write"/>
Expand Down
14 changes: 7 additions & 7 deletions repos/gems/recipes/pkg/dbg_download/runtime
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@
</config>
<route>
<service name="File_system">
<parent label="used"/>
<parent identity="used"/>
</service>
<any-service> <parent/> </any-service>
</route>
Expand All @@ -74,7 +74,7 @@
</config>
<route>
<service name="File_system">
<parent label="used"/>
<parent identity="used"/>
</service>
<any-service> <parent/> </any-service>
</route>
Expand All @@ -101,10 +101,10 @@
<service name="ROM" label_suffix="installation">
<child name="report_rom" label="depot_download -> installation"/>
</service>
<service name="File_system" label="depot">
<service name="File_system" label_prefix="depot ->">
<child name="depot_rw"/>
</service>
<service name="File_system" label="public">
<service name="File_system" label_prefix="public ->">
<child name="public_rw"/>
</service>
<service name="Report">
Expand All @@ -118,13 +118,13 @@
<config>
<vfs>
<dir name="config">
<fs label="config"/>
<fs label="config -> /"/>
</dir>
</vfs>
</config>
<route>
<service name="File_system" label="config">
<parent label="system_config"/>
<service name="File_system" label_prefix="config ->">
<parent identity="system_config"/>
</service>
<service name="Report">
<child name="report_rom"/>
Expand Down
16 changes: 8 additions & 8 deletions repos/gems/recipes/pkg/file_vault/runtime
Original file line number Diff line number Diff line change
Expand Up @@ -86,17 +86,17 @@
<service name="File_system"/>
</provides>
<config>
<vfs> <dir name="tresor"> <fs label="tresor"/> </dir> </vfs>
<vfs> <dir name="tresor"> <fs label="tresor -> /"/> </dir> </vfs>
</config>
<route>
<service name="ROM" label="ui_config"> <child name="report_rom"/> </service>
<service name="Report" label="ui_report"> <child name="report_rom"/> </service>
<service name="File_system" label="tresor_trust_anchor_vfs -> storage_dir"> <parent label="trust_anchor"/> </service>
<service name="File_system" label="tresor_init -> "> <parent label="data"/> </service>
<service name="File_system" label="tresor"> <parent label="data"/> </service>
<service name="File_system" label="image_fs_query -> "> <parent label="data"/> </service>
<service name="File_system" label="tresor_vfs -> tresor_fs"> <parent label="data"/> </service>
<service name="File_system" label="truncate_file -> tresor"> <parent label="data"/> </service>
<service name="File_system" label_prefix="tresor_trust_anchor_vfs -> storage_dir"> <parent identity="trust_anchor"/> </service>
<service name="File_system" label_prefix="tresor_init -> "> <parent identity="data"/> </service>
<service name="File_system" label_prefix="tresor ->"> <parent identity="data"/> </service>
<service name="File_system" label_prefix="image_fs_query -> "> <parent identity="data"/> </service>
<service name="File_system" label_prefix="tresor_vfs -> tresor_fs"> <parent identity="data"/> </service>
<service name="File_system" label_prefix="truncate_file -> tresor"> <parent identity="data"/> </service>
<service name="Timer"> <parent/> </service>
<service name="PD"> <parent/> </service>
<service name="ROM"> <parent/> </service>
Expand All @@ -111,7 +111,7 @@
<route>
<service name="ROM" label="ui_report"> <child name="report_rom"/> </service>
<service name="Report" label="ui_config"> <child name="report_rom"/> </service>
<service name="File_system" label_last="fonts"> <parent label="fonts"/> </service>
<service name="File_system" label_last="fonts -> /"> <parent identity="fonts"/> </service>
<service name="Gui"> <parent/> </service>
<service name="Timer"> <parent/> </service>
<service name="PD"> <parent/> </service>
Expand Down
37 changes: 19 additions & 18 deletions repos/gems/recipes/pkg/test-file_vault/runtime
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,7 @@
<ram/>
</dir>
</vfs>
<policy label="file_vault -> data" root="/data" writeable="yes"/>
<policy label_prefix="file_vault -> data" root="/data" writeable="yes"/>
</config>
<route>
<service name="PD"> <parent/> </service>
Expand All @@ -104,7 +104,7 @@
<ram/>
</dir>
</vfs>
<policy label="file_vault -> trust_anchor" root="/trust_anchor" writeable="yes"/>
<policy label_prefix="file_vault -> trust_anchor" root="/trust_anchor" writeable="yes"/>
</config>
<route>
<service name="PD"> <parent/> </service>
Expand All @@ -118,26 +118,27 @@
<config>
<vfs>
<dir name="tresor">
<fs label="tresor"/>
<fs label="tresor -> /"/>
</dir>
</vfs>
</config>
<route>
<service name="ROM" label="ui_config"> <child name="dynamic_rom" label="file_vault_ui_config"/> </service>
<service name="Report"> label="ui_report" <child name="report_rom"/> </service>
<service name="File_system" label="tresor_trust_anchor_vfs -> storage_dir"> <child name="trust_anchor_fs" label="file_vault -> trust_anchor"/> </service>
<service name="File_system" label="tresor_init -> "> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="File_system" label="tresor"> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="File_system" label="fs_query -> "> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="File_system" label="image_fs_query -> "> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="File_system" label="tresor_vfs -> tresor_fs"> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="File_system" label="truncate_file -> tresor"> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="Timer"> <parent/> </service>
<service name="PD"> <parent/> </service>
<service name="ROM"> <parent/> </service>
<service name="CPU"> <parent/> </service>
<service name="LOG"> <parent/> </service>
<service name="RM"> <parent/> </service>
<service name="ROM" label="ui_config"> <child name="dynamic_rom" label="file_vault_ui_config"/> </service>
<service name="Report"> <child name="report_rom"/> </service>
<service name="File_system" label_prefix="tresor_trust_anchor_vfs -> storage_dir">
<child name="trust_anchor_fs" identity="file_vault -> trust_anchor"/> </service>
<service name="File_system" label_prefix="tresor_init ->"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="File_system" label_prefix="tresor ->"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="File_system" label_prefix="fs_query ->"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="File_system" label_prefix="image_fs_query ->"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="File_system" label_prefix="tresor_vfs -> tresor_fs"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="File_system" label_prefix="truncate_file -> tresor"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="Timer"> <parent/> </service>
<service name="PD"> <parent/> </service>
<service name="ROM"> <parent/> </service>
<service name="CPU"> <parent/> </service>
<service name="LOG"> <parent/> </service>
<service name="RM"> <parent/> </service>
</route>
</start>

Expand Down
37 changes: 19 additions & 18 deletions repos/gems/recipes/pkg/test-file_vault_no_entropy/runtime
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,7 @@
<ram/>
</dir>
</vfs>
<policy label="file_vault -> data" root="/data" writeable="yes"/>
<policy label_prefix="file_vault -> data" root="/data" writeable="yes"/>
</config>
<route>
<service name="PD"> <parent/> </service>
Expand All @@ -104,7 +104,7 @@
<ram/>
</dir>
</vfs>
<policy label="file_vault -> trust_anchor" root="/trust_anchor" writeable="yes"/>
<policy label_prefix="file_vault -> trust_anchor" root="/trust_anchor" writeable="yes"/>
</config>
<route>
<service name="PD"> <parent/> </service>
Expand All @@ -118,26 +118,27 @@
<config jitterentropy_available="no">
<vfs>
<dir name="tresor">
<fs label="tresor"/>
<fs label="tresor -> /"/>
</dir>
</vfs>
</config>
<route>
<service name="ROM" label="ui_config"> <child name="dynamic_rom" label="file_vault_ui_config"/> </service>
<service name="Report"> label="ui_report" <child name="report_rom"/> </service>
<service name="File_system" label="tresor_trust_anchor_vfs -> storage_dir"> <child name="trust_anchor_fs" label="file_vault -> trust_anchor"/> </service>
<service name="File_system" label="tresor_init -> "> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="File_system" label="tresor"> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="File_system" label="fs_query -> "> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="File_system" label="image_fs_query -> "> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="File_system" label="tresor_vfs -> tresor_fs"> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="File_system" label="truncate_file -> tresor"> <child name="data_fs" label="file_vault -> data"/> </service>
<service name="Timer"> <parent/> </service>
<service name="PD"> <parent/> </service>
<service name="ROM"> <parent/> </service>
<service name="CPU"> <parent/> </service>
<service name="LOG"> <parent/> </service>
<service name="RM"> <parent/> </service>
<service name="ROM" label="ui_config"> <child name="dynamic_rom" label="file_vault_ui_config"/> </service>
<service name="Report"> <child name="report_rom"/> </service>
<service name="File_system" label_prefix="tresor_trust_anchor_vfs -> storage_dir">
<child name="trust_anchor_fs" identity="file_vault -> trust_anchor"/> </service>
<service name="File_system" label_prefix="tresor_init ->"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="File_system" label_prefix="tresor ->"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="File_system" label_prefix="fs_query ->"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="File_system" label_prefix="image_fs_query ->"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="File_system" label_prefix="tresor_vfs -> tresor_fs"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="File_system" label_prefix="truncate_file -> tresor"> <child name="data_fs" identity="file_vault -> data"/> </service>
<service name="Timer"> <parent/> </service>
<service name="PD"> <parent/> </service>
<service name="ROM"> <parent/> </service>
<service name="CPU"> <parent/> </service>
<service name="LOG"> <parent/> </service>
<service name="RM"> <parent/> </service>
</route>
</start>

Expand Down
4 changes: 2 additions & 2 deletions repos/gems/recipes/pkg/touch_keyboard/runtime
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,8 @@
<route>
<service name="ROM" label="layout">
<parent label="touch_keyboard_layout.config"/> </service>
<service name="File_system" label="fonts">
<parent label="fonts"/> </service>
<service name="File_system" label_prefix="fonts ->">
<parent identity="fonts"/> </service>
<any-service> <parent/> </any-service>
</route>
</start>
Expand Down
2 changes: 1 addition & 1 deletion repos/gems/recipes/pkg/trace_recorder/runtime
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@

<!-- example, must be refined and enabled -->
<config period_ms="5000" enable="no">
<vfs> <fs label="target"/> </vfs>
<vfs> <fs label="target -> /"/> </vfs>

<default-policy policy="ctf0">
<ctf/>
Expand Down
4 changes: 2 additions & 2 deletions repos/gems/recipes/pkg/window_layouter/runtime
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@
<provides> <service name="Report"/> </provides>
<config> <vfs> <fs/> </vfs> </config>
<route>
<service name="File_system"> <parent label="recall"/> </service>
<service name="File_system"> <parent identity="recall"/> </service>
<any-service> <parent/> </any-service>
</route>
</start>
Expand All @@ -42,7 +42,7 @@
<provides> <service name="ROM"/> </provides>
<config/>
<route>
<service name="File_system"> <parent label="recall"/> </service>
<service name="File_system"> <parent identity="recall"/> </service>
<any-service> <parent/> </any-service>
</route>
</start>
Expand Down
14 changes: 7 additions & 7 deletions repos/gems/recipes/raw/depot_download/depot_download.config
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@
<provides> <service name="File_system"/> </provides>
<config> <default-policy path="/" writeable="no"/> </config>
<route>
<service name="File_system"> <parent label="depot"/> </service>
<service name="File_system"> <parent identity="depot"/> </service>
<any-service> <parent/> </any-service>
</route>
</start>
Expand All @@ -71,7 +71,7 @@
<provides> <service name="File_system"/> </provides>
<config> <default-policy path="/" writeable="no"/> </config>
<route>
<service name="File_system"> <parent label="public"/> </service>
<service name="File_system"> <parent identity="public"/> </service>
<any-service> <parent/> </any-service>
</route>
</start>
Expand Down Expand Up @@ -99,11 +99,11 @@
<route>
<service name="ROM" label="config"> <child name="report_rom"/> </service>
<service name="Report"> <child name="report_rom"/> </service>
<service name="File_system" label="depot"> <child name="depot_ro"/> </service>
<service name="File_system" label="depot_rw"> <parent label="depot"/> </service>
<service name="File_system" label="public"> <child name="public_ro"/> </service>
<service name="File_system" label="public_rw"> <parent label="public"/> </service>
<service name="File_system" label="tcpip"> <child name="tcpip"/> </service>
<service name="File_system" label_prefix="depot ->"> <child name="depot_ro"/> </service>
<service name="File_system" label_prefix="depot_rw ->"> <parent identity="depot"/> </service>
<service name="File_system" label_prefix="public ->"> <child name="public_ro"/> </service>
<service name="File_system" label_prefix="public_rw ->"> <parent identity="public"/> </service>
<service name="File_system" label_prefix="tcpip ->"> <child name="tcpip"/> </service>
<any-service> <parent/> <any-child/> </any-service>
</route>
</start>
Expand Down
10 changes: 5 additions & 5 deletions repos/gems/recipes/raw/download_coreplus/init.config
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
<null/>
</dir>
<dir name="vm">
<fs label="target"/>
<fs label="target -> /"/>
</dir>
<inline name=".profile">
cp /machine.vbox /disk0.vmdk /vm
Expand All @@ -38,8 +38,8 @@ cp /machine.vbox /disk0.vmdk /vm
<default-policy root="/" writeable="yes"/>
</config>
<route>
<service name="File_system" label="target">
<parent label="target"/> </service>
<service name="File_system" label_prefix="target ->">
<parent identity="target"/> </service>
<any-service> <parent/> </any-service>
</route>
</start>
Expand Down Expand Up @@ -82,7 +82,7 @@ cp /machine.vbox /disk0.vmdk /vm
<vfs> <dir name="fonts"> <fs/> </dir> </vfs>
</config>
<route>
<service name="File_system"> <parent label="fonts"/> </service>
<service name="File_system"> <parent identity="fonts"/> </service>
<any-service> <parent/> </any-service>
</route>
</start>
Expand Down Expand Up @@ -126,7 +126,7 @@ cp /machine.vbox /disk0.vmdk /vm
</config>
<route>
<service name="File_system" label="target">
<parent label="target"/> </service>
<parent label="target -> /"/> </service>
<service name="LOG"> <parent/> </service>
<service name="Report"> <child name="report"/> </service>
<any-service> <parent/> </any-service>
Expand Down
Loading

0 comments on commit 6fa5ec0

Please sign in to comment.