aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--include/kmi/syscalls.h5
-rw-r--r--src/proc.c4
-rw-r--r--src/uapi/mem.c3
3 files changed, 8 insertions, 4 deletions
diff --git a/include/kmi/syscalls.h b/include/kmi/syscalls.h
index a4d2c52..30e46be 100644
--- a/include/kmi/syscalls.h
+++ b/include/kmi/syscalls.h
@@ -291,7 +291,10 @@ enum sys_cap {
CAP_SIGNAL = (1 << 6),
/** Thread is allowed to request shared memory */
- CAP_SHARED = (1 << 7)
+ CAP_SHARED = (1 << 7),
+
+ /** Thread is allowed to request physical memory */
+ CAP_PHYSICAL = (1 << 8),
};
/**
diff --git a/src/proc.c b/src/proc.c
index 090ae20..0283117 100644
--- a/src/proc.c
+++ b/src/proc.c
@@ -46,9 +46,7 @@ stat_t init_proc(void *fdt, vm_t *proc_fdt, vm_t *proc_initrd)
t->notify_id = t->tid;
/* init process has all capabilities */
- set_caps(t->caps,
- CAP_CAPS | CAP_PROC | CAP_SIGNAL | CAP_POWER | CAP_NOTIFY |
- CAP_SHARED);
+ set_caps(t->caps, ~0);
/* we shall try to map the fdt and initrd into the new address space, so
* save them here before we switch */
diff --git a/src/uapi/mem.c b/src/uapi/mem.c
index 5c18797..561b5eb 100644
--- a/src/uapi/mem.c
+++ b/src/uapi/mem.c
@@ -100,6 +100,9 @@ SYSCALL_DEFINE3(req_pmem)(struct tcb *t, sys_arg_t paddr, sys_arg_t size,
* that keeps track of used regions outside of RAM. We'll see.
*/
struct tcb *r = get_cproc(t);
+ if (!has_cap(r->caps, CAP_PHYSICAL))
+ return_args1(t, ERR_PERM);
+
flags = sanitize_uvflags(flags);
vm_t start = alloc_devmem(r, paddr, size, flags);
if (ERR_CODE(start))