Skip to content

Use user permissions on socket handles#94

Open
hlef wants to merge 4 commits into
mainfrom
hlefeuvre/user-permissions-on-sockets
Open

Use user permissions on socket handles#94
hlef wants to merge 4 commits into
mainfrom
hlefeuvre/user-permissions-on-sockets

Conversation

@hlef

@hlef hlef commented Jul 2, 2026

Copy link
Copy Markdown
Collaborator

This addresses #91. While at it, it adds some missing documentation (which I realized while documenting the feature), and adds a missing check (which I found out while adding the permission checks).

This comes with a new example to showcase the use of least-privilege socket handles.

@hlef
hlef requested a review from davidchisnall July 2, 2026 21:46
@hlef
hlef force-pushed the hlefeuvre/user-permissions-on-sockets branch from 5f3fe6d to ac07f2c Compare July 3, 2026 16:46
Comment thread examples/06.COMPARTMENTALIZED_HTTP_SERVER/http_server.cc Outdated
Comment thread examples/06.COMPARTMENTALIZED_HTTP_SERVER/http_server.cc Outdated
Comment thread examples/06.COMPARTMENTALIZED_HTTP_SERVER/http_server.cc Outdated
Comment thread examples/06.COMPARTMENTALIZED_HTTP_SERVER/http_server.cc
Comment thread examples/06.COMPARTMENTALIZED_HTTP_SERVER/http_server.cc Outdated
Comment thread examples/06.COMPARTMENTALIZED_HTTP_SERVER/http_server.cc Outdated
Comment thread examples/06.COMPARTMENTALIZED_HTTP_SERVER/http_server.cc Outdated
Comment thread examples/06.COMPARTMENTALIZED_HTTP_SERVER/http_server.cc
Comment thread examples/06.COMPARTMENTALIZED_HTTP_SERVER/http_server.h
Comment thread examples/06.COMPARTMENTALIZED_HTTP_SERVER/send_compartment.cc
Passing an invalid timeout capability currently crashes the network
stack (which is really annoying as it triggers a reset).

Signed-off-by: Hugo Lefeuvre <hugo.lefeuvre@ubc.ca>
@hlef
hlef force-pushed the hlefeuvre/user-permissions-on-sockets branch from ac07f2c to d7e8cef Compare July 10, 2026 17:52
hlef added 2 commits July 10, 2026 11:04
Signed-off-by: Hugo Lefeuvre <hugo.lefeuvre@ubc.ca>
Similar to what we recently did in the allocator and in the message
queue, we can use the three currently-unused bits at the bottom of
sealed socket handles to store permissions.

Having permissions on sockets allows us to encode the right to close a
socket, send, or receive data.

Signed-off-by: Hugo Lefeuvre <hugo.lefeuvre@ubc.ca>
@hlef
hlef force-pushed the hlefeuvre/user-permissions-on-sockets branch from d7e8cef to a3a98ca Compare July 10, 2026 18:05
This extends the HTTP server example to showcase socket and allocator
capability permissions. We can also use that example later to showcase
sub-quotas.

Signed-off-by: Hugo Lefeuvre <hugo.lefeuvre@ubc.ca>
@hlef
hlef force-pushed the hlefeuvre/user-permissions-on-sockets branch from a3a98ca to 8929e20 Compare July 10, 2026 19:02
@hlef

hlef commented Jul 10, 2026

Copy link
Copy Markdown
Collaborator Author

Alright @davidchisnall, addressed all I could and created issues for everything else. Let me know what I broke in that process 🙂

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants