From owner-p4-projects@FreeBSD.ORG Thu Mar 25 10:26:42 2004 Return-Path: Delivered-To: p4-projects@freebsd.org Received: by hub.freebsd.org (Postfix, from userid 32767) id EFFFB16A4D0; Thu, 25 Mar 2004 10:26:41 -0800 (PST) Delivered-To: perforce@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C43F016A4CE for ; Thu, 25 Mar 2004 10:26:41 -0800 (PST) Received: from repoman.freebsd.org (repoman.freebsd.org [216.136.204.115]) by mx1.FreeBSD.org (Postfix) with ESMTP id BD4C643D3F for ; Thu, 25 Mar 2004 10:26:41 -0800 (PST) (envelope-from bb+lists.freebsd.perforce@cyrus.watson.org) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.12.10/8.12.10) with ESMTP id i2PIQfGe096049 for ; Thu, 25 Mar 2004 10:26:41 -0800 (PST) (envelope-from bb+lists.freebsd.perforce@cyrus.watson.org) Received: (from perforce@localhost) by repoman.freebsd.org (8.12.10/8.12.10/Submit) id i2PIQfwj096046 for perforce@freebsd.org; Thu, 25 Mar 2004 10:26:41 -0800 (PST) (envelope-from bb+lists.freebsd.perforce@cyrus.watson.org) Date: Thu, 25 Mar 2004 10:26:41 -0800 (PST) Message-Id: <200403251826.i2PIQfwj096046@repoman.freebsd.org> X-Authentication-Warning: repoman.freebsd.org: perforce set sender to bb+lists.freebsd.perforce@cyrus.watson.org using -f From: Robert Watson To: Perforce Change Reviews Subject: PERFORCE change 49674 for review X-BeenThere: p4-projects@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: p4 projects tree changes List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 25 Mar 2004 18:26:42 -0000 http://perforce.freebsd.org/chv.cgi?CH=49674 Change 49674 by rwatson@rwatson_tislabs on 2004/03/25 10:26:21 Update for BPF fine-grained locking: BPF descriptor lock and not Giant now protects the label. Affected files ... .. //depot/projects/trustedbsd/mac/sys/net/bpf.c#31 edit .. //depot/projects/trustedbsd/mac/sys/net/bpfdesc.h#11 edit .. //depot/projects/trustedbsd/mac/sys/security/mac/mac_net.c#23 edit Differences ... ==== //depot/projects/trustedbsd/mac/sys/net/bpf.c#31 (text+ko) ==== @@ -578,10 +578,12 @@ if (d->bd_hdrcmplt) dst.sa_family = pseudo_AF_HDRCMPLT; - mtx_lock(&Giant); #ifdef MAC + BPFD_LOCK(d); mac_create_mbuf_from_bpfdesc(d, m); + BPFD_UNLOCK(d); #endif + mtx_lock(&Giant); error = (*ifp->if_output)(ifp, m, &dst, (struct rtentry *)0); mtx_unlock(&Giant); /* ==== //depot/projects/trustedbsd/mac/sys/net/bpfdesc.h#11 (text+ko) ==== @@ -102,6 +102,7 @@ #define BPFD_LOCK(bd) mtx_lock(&(bd)->bd_mtx) #define BPFD_UNLOCK(bd) mtx_unlock(&(bd)->bd_mtx) +#define BPFD_LOCK_ASSERT(bd) mtx_assert(&(bd)->bd_mtx, MA_OWNED) /* Test whether a BPF is ready for read(). */ #define bpf_ready(bd) \ ==== //depot/projects/trustedbsd/mac/sys/security/mac/mac_net.c#23 (text+ko) ==== @@ -292,6 +292,8 @@ { struct label *label; + BPFD_LOCK_ASSERT(bpf_d); + label = mac_mbuf_to_label(mbuf); MAC_PERFORM(create_mbuf_from_bpfdesc, bpf_d, bpf_d->bd_label, mbuf, @@ -350,6 +352,8 @@ { int error; + BPFD_LOCK_ASSERT(bpf_d); + if (!mac_enforce_network) return (0);