Skip to content

capdl: fail-closed capability rights in spec - #375

Merged
midnightveil merged 2 commits into
mainfrom
julia/rights-default-none
Oct 1, 2026
Merged

midnightveil merged 2 commits into
mainfrom
julia/rights-default-none

Conversation

@midnightveil

Copy link
Copy Markdown
Contributor

Per seL4's maskCapRights function (and Arch_ variant), only caps
for Endpoints, Notifications, Replies, and Frames have rights
which seL4 cares about (or can be stored inside the capability).

Currently, rust-seL4 does not support setting rights on Reply caps
in the capDL specification, but there is a 'capReplyCanGrant' bit
in the Reply capability which controls capability transfer.

In case we miss more of these, or more are added, default right-less
caps in the spec to being minted with CapRights::none(), which
gives them no rights by default. For most cap types, this does not
actually matter; for cap types where it does matter the rights()
method should return Some() as per the implementation.

Perform a similar change for mint_iospace_cap (internal helper,
not exposed to users, and it does not care about the rights),
and document CapRights::all for copying to the notification bound
to an IRQ (which does need Send/Write permissions).


Then fix the reply cap rights thing.

@midnightveil
midnightveil requested a review from nspin as a code owner September 28, 2026 03:11
@midnightveil midnightveil changed the title Julia/rights default none capdl: fail-closed capability rights in spec Sep 28, 2026
Per seL4's `maskCapRights` function (and `Arch_` variant), only caps
for Endpoints, Notifications, Replies, and Frames have rights
which seL4 cares about (or can be stored inside the capability).

Currently, rust-seL4 does not support setting rights on Reply caps
in the capDL specification, but there is a 'capReplyCanGrant' bit
in the Reply capability which controls capability transfer.

In case we miss more of these, or more are added, default right-less
caps in the spec to being minted with `CapRights::none()`, which
gives them no rights by default. For most cap types, this does not
actually matter; for cap types where it does matter the `rights()`
method should return `Some()` as per the implementation.

Perform a similar change for mint_iospace_cap (internal helper,
not exposed to users, and it does not care about the rights),
and document `CapRights::all` for copying to the notification bound
to an IRQ (which does need Send/Write permissions).

Signed-off-by: Julia Vassiliki <julia.vassiliki@unsw.edu.au>
Only the 'Grant' bit of the Rights means anything for the
Reply Cap, which controls 'capReplyCanGrant' bit.

Signed-off-by: Julia Vassiliki <julia.vassiliki@unsw.edu.au>
@midnightveil
midnightveil force-pushed the julia/rights-default-none branch from f98d2f2 to 12d0fde Compare October 1, 2026 08:23
@midnightveil
midnightveil merged commit a61441c into main Oct 1, 2026
14 checks passed
@midnightveil
midnightveil deleted the julia/rights-default-none branch October 1, 2026 08:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants