1f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)// Copyright 2014 The Chromium Authors. All rights reserved.
2f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)// Use of this source code is governed by a BSD-style license that can be
3f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)// found in the LICENSE file.
4f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
5f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)#ifndef SANDBOX_MAC_MACH_MESSAGE_SERVER_H_
6f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)#define SANDBOX_MAC_MACH_MESSAGE_SERVER_H_
7f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
8f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)#include <mach/mach.h>
9f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
10f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)#include "base/mac/scoped_mach_port.h"
11f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)#include "base/mac/scoped_mach_vm.h"
12116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch#include "base/memory/scoped_ptr.h"
13116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch#include "sandbox/mac/message_server.h"
14f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
15f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)namespace sandbox {
16f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
17116680a4aac90f2aa7413d9095a592090648e557Ben Murdochclass DispatchSourceMach;
18f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
19f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)// A Mach message server that operates a receive port. Messages are received
20f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)// and then passed to the MessageDemuxer for handling. The Demuxer
21f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)// can use the server class to send a reply, forward the message to a
22f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)// different port, or reply to the message with a MIG error.
23116680a4aac90f2aa7413d9095a592090648e557Ben Murdochclass MachMessageServer : public MessageServer {
24f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles) public:
256d86b77056ed63eb6871182f42a9fd5f07550f90Torne (Richard Coles)  // Creates a new Mach message server that will send messages to |demuxer|
266d86b77056ed63eb6871182f42a9fd5f07550f90Torne (Richard Coles)  // for handling. If the |server_receive_right| is non-NULL, this class will
276d86b77056ed63eb6871182f42a9fd5f07550f90Torne (Richard Coles)  // take ownership of the port and it will be used to receive messages.
286d86b77056ed63eb6871182f42a9fd5f07550f90Torne (Richard Coles)  // Otherwise the server will create a new receive right.
296d86b77056ed63eb6871182f42a9fd5f07550f90Torne (Richard Coles)  // The maximum size of messages is specified by |buffer_size|.
306d86b77056ed63eb6871182f42a9fd5f07550f90Torne (Richard Coles)  MachMessageServer(MessageDemuxer* demuxer,
316d86b77056ed63eb6871182f42a9fd5f07550f90Torne (Richard Coles)                    mach_port_t server_receive_right,
326d86b77056ed63eb6871182f42a9fd5f07550f90Torne (Richard Coles)                    mach_msg_size_t buffer_size);
33116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  virtual ~MachMessageServer();
34116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch
35116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  // MessageServer:
36116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  virtual bool Initialize() OVERRIDE;
37116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  virtual pid_t GetMessageSenderPID(IPCMessage request) OVERRIDE;
38116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  virtual IPCMessage CreateReply(IPCMessage request) OVERRIDE;
39116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  virtual bool SendReply(IPCMessage reply) OVERRIDE;
40116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  virtual void ForwardMessage(IPCMessage request,
41116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch                              mach_port_t destination) OVERRIDE;
42f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  // Replies to the message with the specified |error_code| as a MIG
43f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  // error_reply RetCode.
44116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  virtual void RejectMessage(IPCMessage request, int error_code) OVERRIDE;
45116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  virtual mach_port_t GetServerPort() const OVERRIDE;
46f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
47f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles) private:
48f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  // Event handler for the |server_source_| that reads a message from the queue
49f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  // and processes it.
50f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  void ReceiveMessage();
51f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
52f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  // The demuxer delegate. Weak.
53f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  MessageDemuxer* demuxer_;
54f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
55f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  // The Mach port on which the server is receiving requests.
56f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  base::mac::ScopedMachReceiveRight server_port_;
57f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
58f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  // The size of the two message buffers below.
59f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  const mach_msg_size_t buffer_size_;
60f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
61f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  // Request and reply buffers used in ReceiveMessage.
62f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  base::mac::ScopedMachVM request_buffer_;
63f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  base::mac::ScopedMachVM reply_buffer_;
64f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
65116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  // MACH_RECV dispatch source that handles the |server_port_|.
66116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch  scoped_ptr<DispatchSourceMach> dispatch_source_;
67116680a4aac90f2aa7413d9095a592090648e557Ben Murdoch
68f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  // Whether or not ForwardMessage() was called during ReceiveMessage().
69f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)  bool did_forward_message_;
70f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)};
71f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
72f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)}  // namespace sandbox
73f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)
74f8ee788a64d60abd8f2d742a5fdedde054ecd910Torne (Richard Coles)#endif  // SANDBOX_MAC_MACH_MESSAGE_SERVER_H_
75