2011-12-22 15:19:25 +00:00
|
|
|
/*
|
|
|
|
* \brief Policy applied to all children of the init process
|
|
|
|
* \author Norman Feske
|
|
|
|
* \date 2010-04-29
|
|
|
|
*/
|
|
|
|
|
|
|
|
/*
|
2013-01-10 20:44:47 +00:00
|
|
|
* Copyright (C) 2010-2013 Genode Labs GmbH
|
2011-12-22 15:19:25 +00:00
|
|
|
*
|
|
|
|
* This file is part of the Genode OS framework, which is distributed
|
|
|
|
* under the terms of the GNU General Public License version 2.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef _INCLUDE__INIT__CHILD_POLICY_H_
|
|
|
|
#define _INCLUDE__INIT__CHILD_POLICY_H_
|
|
|
|
|
|
|
|
/* Genode includes */
|
|
|
|
#include <base/service.h>
|
|
|
|
#include <base/child.h>
|
|
|
|
#include <base/rpc_server.h>
|
|
|
|
#include <util/arg_string.h>
|
|
|
|
#include <rom_session/connection.h>
|
|
|
|
|
|
|
|
namespace Init {
|
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
class Child_policy_ram_phys;
|
|
|
|
class Child_policy_enforce_labeling;
|
|
|
|
class Child_policy_handle_cpu_priorities;
|
|
|
|
class Child_policy_provide_rom_file;
|
|
|
|
class Child_policy_redirect_rom_file;
|
|
|
|
class Traditional_child_policy;
|
|
|
|
}
|
2015-02-07 20:02:50 +00:00
|
|
|
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
class Init::Child_policy_ram_phys
|
|
|
|
{
|
|
|
|
private:
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
bool _constrain_phys;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
public:
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
Child_policy_ram_phys(bool constrain_phys)
|
|
|
|
: _constrain_phys(constrain_phys) { }
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/**
|
|
|
|
* Filter arguments of session request
|
|
|
|
*
|
2015-03-20 16:50:41 +00:00
|
|
|
* This method removes phys_start and phys_size ram_session
|
2015-03-04 20:12:14 +00:00
|
|
|
* parameters if the child configuration does not explicitly
|
|
|
|
* permits this.
|
|
|
|
*/
|
|
|
|
void filter_session_args(const char *service, char *args,
|
|
|
|
Genode::size_t args_len)
|
|
|
|
{
|
|
|
|
using namespace Genode;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/* intercept only RAM session requests */
|
|
|
|
if (Genode::strcmp(service, "RAM"))
|
|
|
|
return;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
if (_constrain_phys)
|
|
|
|
return;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
Arg_string::remove_arg(args, "phys_start");
|
|
|
|
Arg_string::remove_arg(args, "phys_size");
|
|
|
|
}
|
|
|
|
};
|
2012-10-24 14:27:26 +00:00
|
|
|
|
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/**
|
|
|
|
* Policy for prepending the child name to the 'label' argument
|
|
|
|
*
|
|
|
|
* By applying this policy, the identity of the child becomes imprinted
|
|
|
|
* with each session request.
|
|
|
|
*/
|
|
|
|
class Init::Child_policy_enforce_labeling
|
|
|
|
{
|
|
|
|
const char *_name;
|
|
|
|
|
|
|
|
public:
|
|
|
|
|
|
|
|
Child_policy_enforce_labeling(const char *name) : _name(name) { }
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Filter arguments of session request
|
|
|
|
*
|
2015-03-20 16:50:41 +00:00
|
|
|
* This method modifies the 'label' argument and leaves all other
|
2015-03-04 20:12:14 +00:00
|
|
|
* session arguments intact.
|
|
|
|
*/
|
|
|
|
void filter_session_args(const char *, char *args,
|
|
|
|
Genode::size_t args_len)
|
|
|
|
{
|
|
|
|
using namespace Genode;
|
|
|
|
|
|
|
|
char label_buf[Parent::Session_args::MAX_SIZE];
|
|
|
|
Arg_string::find_arg(args, "label").string(label_buf, sizeof(label_buf), "");
|
|
|
|
|
|
|
|
char value_buf[Parent::Session_args::MAX_SIZE];
|
|
|
|
Genode::snprintf(value_buf, sizeof(value_buf),
|
|
|
|
"\"%s%s%s\"",
|
|
|
|
_name,
|
|
|
|
Genode::strcmp(label_buf, "") == 0 ? "" : " -> ",
|
|
|
|
label_buf);
|
|
|
|
|
|
|
|
Arg_string::set_arg(args, args_len, "label", value_buf);
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
class Init::Child_policy_handle_cpu_priorities
|
|
|
|
{
|
|
|
|
/* priority parameters */
|
|
|
|
long _prio_levels_log2;
|
|
|
|
long _priority;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
public:
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
Child_policy_handle_cpu_priorities(long prio_levels_log2, long priority)
|
|
|
|
: _prio_levels_log2(prio_levels_log2), _priority(priority) { }
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
void filter_session_args(const char *service, char *args, Genode::size_t args_len)
|
|
|
|
{
|
|
|
|
using namespace Genode;
|
2014-11-03 13:07:59 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/* intercept only CPU session requests to scale priorities */
|
|
|
|
if (Genode::strcmp(service, "CPU") || _prio_levels_log2 == 0)
|
|
|
|
return;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-27 13:02:04 +00:00
|
|
|
unsigned long priority = Arg_string::find_arg(args, "priority").ulong_value(0);
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/* clamp priority value to valid range */
|
|
|
|
priority = min((unsigned)Cpu_session::PRIORITY_LIMIT - 1, priority);
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
long discarded_prio_lsb_bits_mask = (1 << _prio_levels_log2) - 1;
|
|
|
|
if (priority & discarded_prio_lsb_bits_mask) {
|
|
|
|
PWRN("priority band too small, losing least-significant priority bits");
|
2011-12-22 15:19:25 +00:00
|
|
|
}
|
2015-03-04 20:12:14 +00:00
|
|
|
priority >>= _prio_levels_log2;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/* assign child priority to the most significant priority bits */
|
|
|
|
priority |= _priority*(Cpu_session::PRIORITY_LIMIT >> _prio_levels_log2);
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/* override priority when delegating the session request to the parent */
|
|
|
|
char value_buf[64];
|
|
|
|
Genode::snprintf(value_buf, sizeof(value_buf), "0x%lx", priority);
|
|
|
|
Arg_string::set_arg(args, args_len, "priority", value_buf);
|
|
|
|
}
|
|
|
|
};
|
2011-12-22 15:19:25 +00:00
|
|
|
|
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
class Init::Child_policy_provide_rom_file
|
|
|
|
{
|
|
|
|
private:
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
struct Local_rom_session_component : Genode::Rpc_object<Genode::Rom_session>
|
|
|
|
{
|
|
|
|
Genode::Dataspace_capability ds_cap;
|
Support for dynamic ROM sessions, fix #170
This patch introduces support for ROM sessions that update their
provided data during the lifetime of the session. The 'Rom_session'
interface had been extended with the new 'release()' and 'sigh()'
functions, which are needed to support the new protocol. All ROM
services have been updated to the new interface.
Furthermore, the patch changes the child policy of init
with regard to the handling of configuration files. The 'Init::Child'
used to always provide the ROM dataspace with the child's config file
via a locally implemented ROM service. However, for dynamic ROM
sessions, we need to establish a session to the real supplier of the ROM
data. This is achieved by using a new 'Child_policy_redirect_rom_file'
policy to handle the 'configfile' rather than handling the 'configfile'
case entirely within 'Child_config'.
To see the new facility in action, the new 'os/run/dynamic_config.run'
script provides a simple scenario. The config file of the test program
is provided by a service, which generates and updates the config data
at regular intervals.
In addition, new support has been added to let slaves use dynamic
reconfiguration. By using the new 'Child_policy_dynamic_rom_file', the
configuration of a slave can be changed dynamically at runtime via the
new 'configure()' function.
The config is provided as plain null-terminated string (instead of a
dataspace capability) because we need to buffer the config data anyway.
So there is no benefit of using a dataspace. For buffering configuration
data, a 'Ram_session' must be supplied. If no 'Ram_session' is specified
at construction time of a 'Slave_policy', no config is supplied to the
slave (which is still a common case).
An example for dynamically reconfiguring a slave is provided by
'os/run/dynamic_config_slave.run'.
2012-04-04 15:07:19 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/**
|
|
|
|
* Constructor
|
|
|
|
*/
|
|
|
|
Local_rom_session_component(Genode::Dataspace_capability ds)
|
|
|
|
: ds_cap(ds) { }
|
2011-12-22 15:19:25 +00:00
|
|
|
|
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/***************************
|
|
|
|
** ROM session interface **
|
|
|
|
***************************/
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
Genode::Rom_dataspace_capability dataspace() {
|
|
|
|
return Genode::static_cap_cast<Genode::Rom_dataspace>(ds_cap); }
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
void sigh(Genode::Signal_context_capability) { }
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
} _local_rom_session;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
Genode::Rpc_entrypoint *_ep;
|
|
|
|
Genode::Rom_session_capability _rom_session_cap;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
enum { FILENAME_MAX_LEN = 32 };
|
|
|
|
char _filename[FILENAME_MAX_LEN];
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
struct Local_rom_service : public Genode::Service
|
|
|
|
{
|
|
|
|
Genode::Rom_session_capability _rom_cap;
|
|
|
|
bool _valid;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
|
|
|
/**
|
|
|
|
* Constructor
|
2015-03-04 20:12:14 +00:00
|
|
|
*
|
|
|
|
* \param rom_cap capability to return on session requests
|
|
|
|
* \param valid true if local rom service is backed by a
|
|
|
|
* valid dataspace
|
2011-12-22 15:19:25 +00:00
|
|
|
*/
|
2015-03-04 20:12:14 +00:00
|
|
|
Local_rom_service(Genode::Rom_session_capability rom_cap, bool valid)
|
|
|
|
: Genode::Service("ROM"), _rom_cap(rom_cap), _valid(valid) { }
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
Genode::Session_capability session(char const * /*args*/,
|
|
|
|
Genode::Affinity const &)
|
2011-12-22 15:19:25 +00:00
|
|
|
{
|
2015-03-04 20:12:14 +00:00
|
|
|
if (!_valid)
|
|
|
|
throw Invalid_args();
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
return _rom_cap;
|
2011-12-22 15:19:25 +00:00
|
|
|
}
|
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
void upgrade(Genode::Session_capability, const char * /*args*/) { }
|
|
|
|
void close(Genode::Session_capability) { }
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
} _local_rom_service;
|
Support for dynamic ROM sessions, fix #170
This patch introduces support for ROM sessions that update their
provided data during the lifetime of the session. The 'Rom_session'
interface had been extended with the new 'release()' and 'sigh()'
functions, which are needed to support the new protocol. All ROM
services have been updated to the new interface.
Furthermore, the patch changes the child policy of init
with regard to the handling of configuration files. The 'Init::Child'
used to always provide the ROM dataspace with the child's config file
via a locally implemented ROM service. However, for dynamic ROM
sessions, we need to establish a session to the real supplier of the ROM
data. This is achieved by using a new 'Child_policy_redirect_rom_file'
policy to handle the 'configfile' rather than handling the 'configfile'
case entirely within 'Child_config'.
To see the new facility in action, the new 'os/run/dynamic_config.run'
script provides a simple scenario. The config file of the test program
is provided by a service, which generates and updates the config data
at regular intervals.
In addition, new support has been added to let slaves use dynamic
reconfiguration. By using the new 'Child_policy_dynamic_rom_file', the
configuration of a slave can be changed dynamically at runtime via the
new 'configure()' function.
The config is provided as plain null-terminated string (instead of a
dataspace capability) because we need to buffer the config data anyway.
So there is no benefit of using a dataspace. For buffering configuration
data, a 'Ram_session' must be supplied. If no 'Ram_session' is specified
at construction time of a 'Slave_policy', no config is supplied to the
slave (which is still a common case).
An example for dynamically reconfiguring a slave is provided by
'os/run/dynamic_config_slave.run'.
2012-04-04 15:07:19 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
public:
|
Support for dynamic ROM sessions, fix #170
This patch introduces support for ROM sessions that update their
provided data during the lifetime of the session. The 'Rom_session'
interface had been extended with the new 'release()' and 'sigh()'
functions, which are needed to support the new protocol. All ROM
services have been updated to the new interface.
Furthermore, the patch changes the child policy of init
with regard to the handling of configuration files. The 'Init::Child'
used to always provide the ROM dataspace with the child's config file
via a locally implemented ROM service. However, for dynamic ROM
sessions, we need to establish a session to the real supplier of the ROM
data. This is achieved by using a new 'Child_policy_redirect_rom_file'
policy to handle the 'configfile' rather than handling the 'configfile'
case entirely within 'Child_config'.
To see the new facility in action, the new 'os/run/dynamic_config.run'
script provides a simple scenario. The config file of the test program
is provided by a service, which generates and updates the config data
at regular intervals.
In addition, new support has been added to let slaves use dynamic
reconfiguration. By using the new 'Child_policy_dynamic_rom_file', the
configuration of a slave can be changed dynamically at runtime via the
new 'configure()' function.
The config is provided as plain null-terminated string (instead of a
dataspace capability) because we need to buffer the config data anyway.
So there is no benefit of using a dataspace. For buffering configuration
data, a 'Ram_session' must be supplied. If no 'Ram_session' is specified
at construction time of a 'Slave_policy', no config is supplied to the
slave (which is still a common case).
An example for dynamically reconfiguring a slave is provided by
'os/run/dynamic_config_slave.run'.
2012-04-04 15:07:19 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/**
|
|
|
|
* Constructor
|
|
|
|
*/
|
|
|
|
Child_policy_provide_rom_file(const char *filename,
|
|
|
|
Genode::Dataspace_capability ds_cap,
|
|
|
|
Genode::Rpc_entrypoint *ep)
|
|
|
|
:
|
|
|
|
_local_rom_session(ds_cap), _ep(ep),
|
|
|
|
_rom_session_cap(_ep->manage(&_local_rom_session)),
|
|
|
|
_local_rom_service(_rom_session_cap, ds_cap.valid())
|
|
|
|
{
|
|
|
|
Genode::strncpy(_filename, filename, sizeof(_filename));
|
|
|
|
}
|
Support for dynamic ROM sessions, fix #170
This patch introduces support for ROM sessions that update their
provided data during the lifetime of the session. The 'Rom_session'
interface had been extended with the new 'release()' and 'sigh()'
functions, which are needed to support the new protocol. All ROM
services have been updated to the new interface.
Furthermore, the patch changes the child policy of init
with regard to the handling of configuration files. The 'Init::Child'
used to always provide the ROM dataspace with the child's config file
via a locally implemented ROM service. However, for dynamic ROM
sessions, we need to establish a session to the real supplier of the ROM
data. This is achieved by using a new 'Child_policy_redirect_rom_file'
policy to handle the 'configfile' rather than handling the 'configfile'
case entirely within 'Child_config'.
To see the new facility in action, the new 'os/run/dynamic_config.run'
script provides a simple scenario. The config file of the test program
is provided by a service, which generates and updates the config data
at regular intervals.
In addition, new support has been added to let slaves use dynamic
reconfiguration. By using the new 'Child_policy_dynamic_rom_file', the
configuration of a slave can be changed dynamically at runtime via the
new 'configure()' function.
The config is provided as plain null-terminated string (instead of a
dataspace capability) because we need to buffer the config data anyway.
So there is no benefit of using a dataspace. For buffering configuration
data, a 'Ram_session' must be supplied. If no 'Ram_session' is specified
at construction time of a 'Slave_policy', no config is supplied to the
slave (which is still a common case).
An example for dynamically reconfiguring a slave is provided by
'os/run/dynamic_config_slave.run'.
2012-04-04 15:07:19 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/**
|
|
|
|
* Destructor
|
|
|
|
*/
|
|
|
|
~Child_policy_provide_rom_file() { _ep->dissolve(&_local_rom_session); }
|
Support for dynamic ROM sessions, fix #170
This patch introduces support for ROM sessions that update their
provided data during the lifetime of the session. The 'Rom_session'
interface had been extended with the new 'release()' and 'sigh()'
functions, which are needed to support the new protocol. All ROM
services have been updated to the new interface.
Furthermore, the patch changes the child policy of init
with regard to the handling of configuration files. The 'Init::Child'
used to always provide the ROM dataspace with the child's config file
via a locally implemented ROM service. However, for dynamic ROM
sessions, we need to establish a session to the real supplier of the ROM
data. This is achieved by using a new 'Child_policy_redirect_rom_file'
policy to handle the 'configfile' rather than handling the 'configfile'
case entirely within 'Child_config'.
To see the new facility in action, the new 'os/run/dynamic_config.run'
script provides a simple scenario. The config file of the test program
is provided by a service, which generates and updates the config data
at regular intervals.
In addition, new support has been added to let slaves use dynamic
reconfiguration. By using the new 'Child_policy_dynamic_rom_file', the
configuration of a slave can be changed dynamically at runtime via the
new 'configure()' function.
The config is provided as plain null-terminated string (instead of a
dataspace capability) because we need to buffer the config data anyway.
So there is no benefit of using a dataspace. For buffering configuration
data, a 'Ram_session' must be supplied. If no 'Ram_session' is specified
at construction time of a 'Slave_policy', no config is supplied to the
slave (which is still a common case).
An example for dynamically reconfiguring a slave is provided by
'os/run/dynamic_config_slave.run'.
2012-04-04 15:07:19 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
Genode::Service *resolve_session_request(const char *service_name,
|
|
|
|
const char *args)
|
|
|
|
{
|
|
|
|
/* ignore session requests for non-ROM services */
|
|
|
|
if (Genode::strcmp(service_name, "ROM")) return 0;
|
2014-09-12 18:17:47 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/* drop out if request refers to another file name */
|
|
|
|
char buf[FILENAME_MAX_LEN];
|
|
|
|
Genode::Arg_string::find_arg(args, "filename").string(buf, sizeof(buf), "");
|
|
|
|
return !Genode::strcmp(buf, _filename) ? &_local_rom_service : 0;
|
|
|
|
}
|
|
|
|
};
|
Support for dynamic ROM sessions, fix #170
This patch introduces support for ROM sessions that update their
provided data during the lifetime of the session. The 'Rom_session'
interface had been extended with the new 'release()' and 'sigh()'
functions, which are needed to support the new protocol. All ROM
services have been updated to the new interface.
Furthermore, the patch changes the child policy of init
with regard to the handling of configuration files. The 'Init::Child'
used to always provide the ROM dataspace with the child's config file
via a locally implemented ROM service. However, for dynamic ROM
sessions, we need to establish a session to the real supplier of the ROM
data. This is achieved by using a new 'Child_policy_redirect_rom_file'
policy to handle the 'configfile' rather than handling the 'configfile'
case entirely within 'Child_config'.
To see the new facility in action, the new 'os/run/dynamic_config.run'
script provides a simple scenario. The config file of the test program
is provided by a service, which generates and updates the config data
at regular intervals.
In addition, new support has been added to let slaves use dynamic
reconfiguration. By using the new 'Child_policy_dynamic_rom_file', the
configuration of a slave can be changed dynamically at runtime via the
new 'configure()' function.
The config is provided as plain null-terminated string (instead of a
dataspace capability) because we need to buffer the config data anyway.
So there is no benefit of using a dataspace. For buffering configuration
data, a 'Ram_session' must be supplied. If no 'Ram_session' is specified
at construction time of a 'Slave_policy', no config is supplied to the
slave (which is still a common case).
An example for dynamically reconfiguring a slave is provided by
'os/run/dynamic_config_slave.run'.
2012-04-04 15:07:19 +00:00
|
|
|
|
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
class Init::Child_policy_redirect_rom_file
|
|
|
|
{
|
|
|
|
private:
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
char const *_from;
|
|
|
|
char const *_to;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
public:
|
2012-10-24 14:27:26 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
Child_policy_redirect_rom_file(const char *from, const char *to)
|
|
|
|
: _from(from), _to(to) { }
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
void filter_session_args(const char *service,
|
|
|
|
char *args, Genode::size_t args_len)
|
|
|
|
{
|
|
|
|
if (!_from || !_to) return;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/* ignore session requests for non-ROM services */
|
|
|
|
if (Genode::strcmp(service, "ROM")) return;
|
2011-12-22 15:19:25 +00:00
|
|
|
|
2015-03-04 20:12:14 +00:00
|
|
|
/* drop out if request refers to another file name */
|
2015-06-16 10:03:39 +00:00
|
|
|
{
|
|
|
|
enum { FILENAME_MAX_LEN = 32 };
|
|
|
|
char buf[FILENAME_MAX_LEN];
|
|
|
|
Genode::Arg_string::find_arg(args, "filename").string(buf, sizeof(buf), "");
|
|
|
|
if (Genode::strcmp(_from, buf) != 0) return;
|
|
|
|
|
|
|
|
/* replace filename argument */
|
|
|
|
Genode::snprintf(buf, sizeof(buf), "\"%s\"", _to);
|
|
|
|
Genode::Arg_string::set_arg(args, args_len, "filename", buf);
|
|
|
|
}
|
2015-03-04 20:12:14 +00:00
|
|
|
|
|
|
|
/* replace characters after last label delimiter by filename */
|
|
|
|
enum { LABEL_MAX_LEN = 200 };
|
|
|
|
char label[LABEL_MAX_LEN];
|
|
|
|
Genode::Arg_string::find_arg(args, "label").string(label, sizeof(label), "");
|
|
|
|
unsigned last_elem = 0;
|
|
|
|
for (unsigned i = 0; i < sizeof(label) - 3 && label[i]; i++)
|
|
|
|
if (Genode::strcmp("-> ", label + i, 3) == 0)
|
|
|
|
last_elem = i + 3;
|
|
|
|
label[last_elem] = 0;
|
|
|
|
|
2015-06-16 10:03:39 +00:00
|
|
|
char buf[LABEL_MAX_LEN];
|
2015-03-04 20:12:14 +00:00
|
|
|
Genode::snprintf(buf, sizeof(buf), "\"%s%s\"", label, _to);
|
|
|
|
Genode::Arg_string::set_arg(args, args_len, "label", buf);
|
|
|
|
}
|
|
|
|
};
|
2011-12-22 15:19:25 +00:00
|
|
|
|
|
|
|
#endif /* _INCLUDE__INIT__CHILD_POLICY_H_ */
|