OLD | NEW |
1 // Copyright 2014 The Chromium Authors. All rights reserved. | 1 // Copyright 2014 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "mojo/edk/system/transport_data.h" | 5 #include "mojo/edk/system/transport_data.h" |
6 | 6 |
7 #include <string.h> | 7 #include <string.h> |
8 | 8 |
9 #include "base/compiler_specific.h" | 9 #include "base/compiler_specific.h" |
10 #include "base/logging.h" | 10 #include "base/logging.h" |
11 #include "mojo/edk/system/channel.h" | 11 #include "mojo/edk/system/channel.h" |
12 #include "mojo/edk/system/configuration.h" | 12 #include "mojo/edk/system/constants.h" |
13 #include "mojo/edk/system/message_in_transit.h" | 13 #include "mojo/edk/system/message_in_transit.h" |
14 | 14 |
15 namespace mojo { | 15 namespace mojo { |
16 namespace system { | 16 namespace system { |
17 | 17 |
18 // The maximum amount of space needed per platform handle. | 18 // The maximum amount of space needed per platform handle. |
19 // (|{Channel,RawChannel}::GetSerializedPlatformHandleSize()| should always | 19 // (|{Channel,RawChannel}::GetSerializedPlatformHandleSize()| should always |
20 // return a value which is at most this. This is only used to calculate | 20 // return a value which is at most this. This is only used to calculate |
21 // |TransportData::kMaxBufferSize|. This value should be a multiple of the | 21 // |TransportData::kMaxBufferSize|. This value should be a multiple of the |
22 // alignment in order to simplify calculations, even though the actual amount of | 22 // alignment in order to simplify calculations, even though the actual amount of |
23 // space needed need not be a multiple of the alignment. | 23 // space needed need not be a multiple of the alignment. |
24 const size_t kMaxSizePerPlatformHandle = 8; | 24 const size_t kMaxSizePerPlatformHandle = 8; |
25 static_assert(kMaxSizePerPlatformHandle % MessageInTransit::kMessageAlignment == | 25 static_assert(kMaxSizePerPlatformHandle % MessageInTransit::kMessageAlignment == |
26 0, | 26 0, |
27 "kMaxSizePerPlatformHandle not a multiple of alignment"); | 27 "kMaxSizePerPlatformHandle not a multiple of alignment"); |
28 | 28 |
29 STATIC_CONST_MEMBER_DEFINITION const size_t | 29 STATIC_CONST_MEMBER_DEFINITION const size_t |
30 TransportData::kMaxSerializedDispatcherSize; | 30 TransportData::kMaxSerializedDispatcherSize; |
31 STATIC_CONST_MEMBER_DEFINITION const size_t | 31 STATIC_CONST_MEMBER_DEFINITION const size_t |
32 TransportData::kMaxSerializedDispatcherPlatformHandles; | 32 TransportData::kMaxSerializedDispatcherPlatformHandles; |
33 | 33 |
34 // static | 34 // static |
35 size_t TransportData::GetMaxBufferSize() { | 35 const size_t TransportData::kMaxPlatformHandles = |
36 // In additional to the header, for each attached (Mojo) handle there'll be a | 36 kMaxMessageNumHandles * kMaxSerializedDispatcherPlatformHandles; |
37 // handle table entry and serialized dispatcher data. | |
38 return sizeof(Header) + | |
39 GetConfiguration().max_message_num_handles * | |
40 (sizeof(HandleTableEntry) + kMaxSerializedDispatcherSize) + | |
41 GetMaxPlatformHandles() * kMaxSizePerPlatformHandle; | |
42 } | |
43 | 37 |
| 38 // In additional to the header, for each attached (Mojo) handle there'll be a |
| 39 // handle table entry and serialized dispatcher data. |
| 40 // Note: This definition must follow the one for |kMaxPlatformHandles|; |
| 41 // otherwise, we get a static initializer with gcc (but not clang). |
44 // static | 42 // static |
45 size_t TransportData::GetMaxPlatformHandles() { | 43 const size_t TransportData::kMaxBufferSize = |
46 return GetConfiguration().max_message_num_handles * | 44 sizeof(Header) + |
47 kMaxSerializedDispatcherPlatformHandles; | 45 kMaxMessageNumHandles * |
48 } | 46 (sizeof(HandleTableEntry) + kMaxSerializedDispatcherSize) + |
| 47 kMaxPlatformHandles * kMaxSizePerPlatformHandle; |
49 | 48 |
50 struct TransportData::PrivateStructForCompileAsserts { | 49 struct TransportData::PrivateStructForCompileAsserts { |
51 static_assert(sizeof(Header) % MessageInTransit::kMessageAlignment == 0, | 50 static_assert(sizeof(Header) % MessageInTransit::kMessageAlignment == 0, |
52 "sizeof(MessageInTransit::Header) not a multiple of alignment"); | 51 "sizeof(MessageInTransit::Header) not a multiple of alignment"); |
53 static_assert(kMaxSerializedDispatcherSize % | 52 static_assert(kMaxSerializedDispatcherSize % |
54 MessageInTransit::kMessageAlignment == | 53 MessageInTransit::kMessageAlignment == |
55 0, | 54 0, |
56 "kMaxSerializedDispatcherSize not a multiple of alignment"); | 55 "kMaxSerializedDispatcherSize not a multiple of alignment"); |
57 static_assert(sizeof(HandleTableEntry) % | 56 static_assert(sizeof(HandleTableEntry) % |
58 MessageInTransit::kMessageAlignment == | 57 MessageInTransit::kMessageAlignment == |
(...skipping 25 matching lines...) Expand all Loading... |
84 #endif | 83 #endif |
85 for (size_t i = 0; i < num_handles; i++) { | 84 for (size_t i = 0; i < num_handles; i++) { |
86 if (Dispatcher* dispatcher = (*dispatchers)[i].get()) { | 85 if (Dispatcher* dispatcher = (*dispatchers)[i].get()) { |
87 size_t max_size = 0; | 86 size_t max_size = 0; |
88 size_t max_platform_handles = 0; | 87 size_t max_platform_handles = 0; |
89 Dispatcher::TransportDataAccess::StartSerialize( | 88 Dispatcher::TransportDataAccess::StartSerialize( |
90 dispatcher, channel, &max_size, &max_platform_handles); | 89 dispatcher, channel, &max_size, &max_platform_handles); |
91 | 90 |
92 DCHECK_LE(max_size, kMaxSerializedDispatcherSize); | 91 DCHECK_LE(max_size, kMaxSerializedDispatcherSize); |
93 estimated_size += MessageInTransit::RoundUpMessageAlignment(max_size); | 92 estimated_size += MessageInTransit::RoundUpMessageAlignment(max_size); |
94 DCHECK_LE(estimated_size, GetMaxBufferSize()); | 93 DCHECK_LE(estimated_size, kMaxBufferSize); |
95 | 94 |
96 DCHECK_LE(max_platform_handles, kMaxSerializedDispatcherPlatformHandles); | 95 DCHECK_LE(max_platform_handles, kMaxSerializedDispatcherPlatformHandles); |
97 estimated_num_platform_handles += max_platform_handles; | 96 estimated_num_platform_handles += max_platform_handles; |
98 DCHECK_LE(estimated_num_platform_handles, GetMaxPlatformHandles()); | 97 DCHECK_LE(estimated_num_platform_handles, kMaxPlatformHandles); |
99 | 98 |
100 #if DCHECK_IS_ON | 99 #if DCHECK_IS_ON |
101 all_max_sizes[i] = max_size; | 100 all_max_sizes[i] = max_size; |
102 all_max_platform_handles[i] = max_platform_handles; | 101 all_max_platform_handles[i] = max_platform_handles; |
103 #endif | 102 #endif |
104 } | 103 } |
105 } | 104 } |
106 | 105 |
107 size_t size_per_platform_handle = 0; | 106 size_t size_per_platform_handle = 0; |
108 if (estimated_num_platform_handles > 0) { | 107 if (estimated_num_platform_handles > 0) { |
109 size_per_platform_handle = channel->GetSerializedPlatformHandleSize(); | 108 size_per_platform_handle = channel->GetSerializedPlatformHandleSize(); |
110 DCHECK_LE(size_per_platform_handle, kMaxSizePerPlatformHandle); | 109 DCHECK_LE(size_per_platform_handle, kMaxSizePerPlatformHandle); |
111 estimated_size += estimated_num_platform_handles * size_per_platform_handle; | 110 estimated_size += estimated_num_platform_handles * size_per_platform_handle; |
112 estimated_size = MessageInTransit::RoundUpMessageAlignment(estimated_size); | 111 estimated_size = MessageInTransit::RoundUpMessageAlignment(estimated_size); |
113 DCHECK_LE(estimated_size, GetMaxBufferSize()); | 112 DCHECK_LE(estimated_size, kMaxBufferSize); |
114 } | 113 } |
115 | 114 |
116 buffer_.reset(static_cast<char*>( | 115 buffer_.reset(static_cast<char*>( |
117 base::AlignedAlloc(estimated_size, MessageInTransit::kMessageAlignment))); | 116 base::AlignedAlloc(estimated_size, MessageInTransit::kMessageAlignment))); |
118 // Entirely clear out the secondary buffer, since then we won't have to worry | 117 // Entirely clear out the secondary buffer, since then we won't have to worry |
119 // about clearing padding or unused space (e.g., if a dispatcher fails to | 118 // about clearing padding or unused space (e.g., if a dispatcher fails to |
120 // serialize). | 119 // serialize). |
121 memset(buffer_.get(), 0, estimated_size); | 120 memset(buffer_.get(), 0, estimated_size); |
122 | 121 |
123 if (estimated_num_platform_handles > 0) { | 122 if (estimated_num_platform_handles > 0) { |
(...skipping 18 matching lines...) Expand all Loading... |
142 } | 141 } |
143 | 142 |
144 #if DCHECK_IS_ON | 143 #if DCHECK_IS_ON |
145 size_t old_platform_handles_size = | 144 size_t old_platform_handles_size = |
146 platform_handles_ ? platform_handles_->size() : 0; | 145 platform_handles_ ? platform_handles_->size() : 0; |
147 #endif | 146 #endif |
148 | 147 |
149 void* destination = buffer_.get() + current_offset; | 148 void* destination = buffer_.get() + current_offset; |
150 size_t actual_size = 0; | 149 size_t actual_size = 0; |
151 if (Dispatcher::TransportDataAccess::EndSerializeAndClose( | 150 if (Dispatcher::TransportDataAccess::EndSerializeAndClose( |
152 dispatcher, channel, destination, &actual_size, | 151 dispatcher, |
| 152 channel, |
| 153 destination, |
| 154 &actual_size, |
153 platform_handles_.get())) { | 155 platform_handles_.get())) { |
154 handle_table[i].type = static_cast<int32_t>(dispatcher->GetType()); | 156 handle_table[i].type = static_cast<int32_t>(dispatcher->GetType()); |
155 handle_table[i].offset = static_cast<uint32_t>(current_offset); | 157 handle_table[i].offset = static_cast<uint32_t>(current_offset); |
156 handle_table[i].size = static_cast<uint32_t>(actual_size); | 158 handle_table[i].size = static_cast<uint32_t>(actual_size); |
157 // (Okay to not set |unused| since we cleared the entire buffer.) | 159 // (Okay to not set |unused| since we cleared the entire buffer.) |
158 | 160 |
159 #if DCHECK_IS_ON | 161 #if DCHECK_IS_ON |
160 DCHECK_LE(actual_size, all_max_sizes[i]); | 162 DCHECK_LE(actual_size, all_max_sizes[i]); |
161 DCHECK_LE(platform_handles_ | 163 DCHECK_LE(platform_handles_ |
162 ? (platform_handles_->size() - old_platform_handles_size) | 164 ? (platform_handles_->size() - old_platform_handles_size) |
(...skipping 44 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
207 // static | 209 // static |
208 const char* TransportData::ValidateBuffer( | 210 const char* TransportData::ValidateBuffer( |
209 size_t serialized_platform_handle_size, | 211 size_t serialized_platform_handle_size, |
210 const void* buffer, | 212 const void* buffer, |
211 size_t buffer_size) { | 213 size_t buffer_size) { |
212 DCHECK(buffer); | 214 DCHECK(buffer); |
213 DCHECK_GT(buffer_size, 0u); | 215 DCHECK_GT(buffer_size, 0u); |
214 | 216 |
215 // Always make sure that the buffer size is sane; if it's not, someone's | 217 // Always make sure that the buffer size is sane; if it's not, someone's |
216 // messing with us. | 218 // messing with us. |
217 if (buffer_size < sizeof(Header) || buffer_size > GetMaxBufferSize() || | 219 if (buffer_size < sizeof(Header) || buffer_size > kMaxBufferSize || |
218 buffer_size % MessageInTransit::kMessageAlignment != 0) | 220 buffer_size % MessageInTransit::kMessageAlignment != 0) |
219 return "Invalid message secondary buffer size"; | 221 return "Invalid message secondary buffer size"; |
220 | 222 |
221 const Header* header = static_cast<const Header*>(buffer); | 223 const Header* header = static_cast<const Header*>(buffer); |
222 const size_t num_handles = header->num_handles; | 224 const size_t num_handles = header->num_handles; |
223 | 225 |
224 #if !defined(OS_POSIX) | 226 #if !defined(OS_POSIX) |
225 // On POSIX, we send control messages with platform handles (but no handles) | 227 // On POSIX, we send control messages with platform handles (but no handles) |
226 // attached (see the comments for | 228 // attached (see the comments for |
227 // |TransportData(embedder::ScopedPlatformHandleVectorPtr)|. (This check isn't | 229 // |TransportData(embedder::ScopedPlatformHandleVectorPtr)|. (This check isn't |
228 // important security-wise anyway.) | 230 // important security-wise anyway.) |
229 if (num_handles == 0) | 231 if (num_handles == 0) |
230 return "Message has no handles attached, but secondary buffer present"; | 232 return "Message has no handles attached, but secondary buffer present"; |
231 #endif | 233 #endif |
232 | 234 |
233 // Sanity-check |num_handles| (before multiplying it against anything). | 235 // Sanity-check |num_handles| (before multiplying it against anything). |
234 if (num_handles > GetConfiguration().max_message_num_handles) | 236 if (num_handles > kMaxMessageNumHandles) |
235 return "Message handle payload too large"; | 237 return "Message handle payload too large"; |
236 | 238 |
237 if (buffer_size < sizeof(Header) + num_handles * sizeof(HandleTableEntry)) | 239 if (buffer_size < sizeof(Header) + num_handles * sizeof(HandleTableEntry)) |
238 return "Message secondary buffer too small"; | 240 return "Message secondary buffer too small"; |
239 | 241 |
240 if (header->num_platform_handles == 0) { | 242 if (header->num_platform_handles == 0) { |
241 // Then |platform_handle_table_offset| should also be zero. | 243 // Then |platform_handle_table_offset| should also be zero. |
242 if (header->platform_handle_table_offset != 0) { | 244 if (header->platform_handle_table_offset != 0) { |
243 return "Message has no handles attached, but platform handle table " | 245 return "Message has no handles attached, but platform handle table " |
244 "present"; | 246 "present"; |
(...skipping 90 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
335 const void* source = static_cast<const char*>(buffer) + offset; | 337 const void* source = static_cast<const char*>(buffer) + offset; |
336 (*dispatchers)[i] = Dispatcher::TransportDataAccess::Deserialize( | 338 (*dispatchers)[i] = Dispatcher::TransportDataAccess::Deserialize( |
337 channel, handle_table[i].type, source, size, platform_handles.get()); | 339 channel, handle_table[i].type, source, size, platform_handles.get()); |
338 } | 340 } |
339 | 341 |
340 return dispatchers.Pass(); | 342 return dispatchers.Pass(); |
341 } | 343 } |
342 | 344 |
343 } // namespace system | 345 } // namespace system |
344 } // namespace mojo | 346 } // namespace mojo |
OLD | NEW |