From sacadmin Mon Oct 12 15:52:52 2009
Received: from tethys.sfbay.sun.com (tethys.SFBay.Sun.COM [129.146.226.92])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n9CMqp7f001142;
	Mon, 12 Oct 2009 15:52:51 -0700 (PDT)
Received: from tethys.sfbay.sun.com (localhost [127.0.0.1])
	by tethys.sfbay.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n9CMl8hM029303;
	Mon, 12 Oct 2009 15:47:08 -0700 (PDT)
Received: (from jg@localhost)
	by tethys.sfbay.sun.com (8.14.3+Sun/8.14.3/Submit) id n9CMl8wE029301;
	Mon, 12 Oct 2009 15:47:08 -0700 (PDT)
Date: Mon, 12 Oct 2009 15:47:08 -0700 (PDT)
From: Jerry Gilliam <jg@tethys.sfbay.sun.com>
Message-Id: <200910122247.n9CMl8wE029301@tethys.sfbay.sun.com>
To: PSARC-record@sac.sfbay.sun.com
Subject: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 FastTrack timeout 10/19/2009]
Status: RO
Content-Length: 567


Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 acpihpd ACPI Hotplug Daemon
    1.2. Name of Document Author/Supplier:
	 Author:  Michael Corcoran
    1.3  Date of This Document:
	12 October, 2009
4. Technical Description
    See the case directory for more detail

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From jerry.gilliam@sun.com Mon Oct 12 16:03:35 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n9CN3Yr9001637
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 12 Oct 2009 16:03:34 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n9CN3Vk8041375;
	Mon, 12 Oct 2009 17:03:32 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KRF00D3NC1V1U00@nwk-avmta-2.sfbay.sun.com>; Mon,
 12 Oct 2009 16:03:31 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KRF007AQC1P6050@nwk-avmta-2.sfbay.sun.com>; Mon,
 12 Oct 2009 16:03:25 -0700 (PDT)
Received: from [129.146.226.92] (tethys.SFBay.Sun.COM [129.146.226.92])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n9CN3OEN710975; Mon, 12 Oct 2009 16:03:24 -0700 (PDT)
Date: Mon, 12 Oct 2009 15:57:41 -0700
From: Jerry Gilliam <jerry.gilliam@sun.com>
Subject: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
To: PSARC-ext@sun.com, Michael Corcoran <Michael.Corcoran@sun.com>,
        Geetanjali Krishna <geetanjali.krishna@intel.com>
Cc: Jiang Liu <jiang.liu@intel.com>, sherry.moore@sun.com,
        Shidokht Yadegari <Shidokht.Yadegari@sun.com>, jerry.gilliam@sun.com
Message-id: <4AD3B465.9090701@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 4335


I'm sponsoring the following fast-track on behalf of Michael
Corcoron with time-out set to 10/19/2009.  The project
requests minor binding only.


Introduction
===========
	Future Intel high-end server platforms support IOH/CPU/memory
hot plug. To enable ACPI based IOH/CPU/memory hot plug, an ACPI hot plug
daemon (acpihpd) is needed to handle events generated by the ACPI subsystem
and maintain state changes.

Release Binding
===============
minor

Dependency
===========
	The acpihpd daemon has dependency on syseventd daemon to relay hot
plug events. It also has dependency on cfgadm framework and sbd plugin to
handle hot plug events. Acpihpd receives hot plug events from syseventd
and invokes cfgadm library to handle these events.

Technical Detail
================
	The acpihpd daemon registers for DR request events and handles them
when they arrive.
	The acpihpd daemon would subscribe to EC_DR/ESC_DR_REQ sysevents
(defined in PSARC/2000/189). When IOH/CPU/memory hot plug events arrive,
the acpihpd parses the DR request and calls into the cfgadm library to
add/remove devices from the system. DR requests are handled by cfgadm
framework.
	The events that the acpihpd is interested in are published by ACPI
virtual nexus driver (acpinex). ACPI BIOS generates ACPI system notifications
when user initiates a device insertion/removal. These notifications will be
forwarded to acpinex driver by the acpica driver. When acpinex driver gets
notifications, it translates the device into Attachment Point and generates
EC_DR/ESC_DR_REQ events.
	When EC_DR/ESC_DR_REQ events are relayed to acpihpd daemon, it invokes
cfgadm library to handle the events. It also takes the responsibility to
udpate other components as part of the DR operation, for example, notify power
management by executing pmconfig command.
	The acpihpd is started and stopped using the standard Solaris service
management facility. The acpihpd is an smf service, and will only be enabled on
the platforms which supports IOH/CPU/memory hot plug.
	The proposed package for the acpihpd and its smf configuration files
is SUNWacpihpd. This package name has not been registered yet.

Interface table and Stability
=============================

	Interface			Classification     Comments
----------------------------------------------------------------------------
/usr/platform/i86pc/lib/acpihpd		Project Private    ACPI HP daemon
/usr/platform/i86pc/lib/amd64/acpihpd	Project Private    ACPI HP daemon
/lib/svc/method/acpihp			Project Private    acpihp service
/var/svc/manifest/platform/i86pc/	Project Private    acpihp manifest
	acpihpd.xml



System Administration Commands                            acpihpd(1M)

NAME
      acpihpd - ACPI hot plug daemon

SYNOPSIS
      /usr/platform/i86pc/lib/acpihpd

DESCRIPTION
      The ACPI hot plug daemon is a daemon process that runs on x86 platforms.
      The daemon is started by the service management facility. It communicates
      with the syseventd and cfgadm sub-systems to handle ACPI events from
      hotpluggable devices.

      The service FMRI for acpihpd is:

      svc:/platform/i86pc/acpihpd:default

OPTIONS
      The acpihpd does not support any options.

ERRORS
      acpihpd uses syslog(3C) to report status and error messages.
      All of the messages are logged with the LOG_DAEMON facility.

      Error messages are logged with the  LOG_ERR  and  LOG_NOTICE
      priorities, and informational messages are logged with the
      LOG_DEBUG priority.   The   default    entries    in    the
      /etc/syslog.conf  file  log all of the DCS error messages to
      the /var/adm/messages log.

ATTRIBUTES

      See attributes(5) for descriptions of the  following  attri-
      butes:
      ____________________________________________________________
     |       ATTRIBUTE TYPE        |       ATTRIBUTE VALUE       |
     |_____________________________|_____________________________|
     | Availability                | SUNWacpihpd                 |
     |_____________________________|_____________________________|

SEE ALSO

      svcs(1), inetadm(1M), svcadm(1M), syslog(3C), syslog.conf(4),
      attributes(5)

NOTES

      The acpihpd service is managed by the service management  facil-
      ity, smf(5), under the service identifier:

      svc:/platform/sun4u/acpihpd:default


From ro@techfak.uni-bielefeld.de Tue Oct 13 07:12:10 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n9DEC8su028102
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 13 Oct 2009 07:12:09 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n9DEBxE3022277;
	Tue, 13 Oct 2009 22:12:02 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KRG00L3DI3Z4R00@brm-avmta-1.central.sun.com>; Tue,
 13 Oct 2009 08:11:59 -0600 (MDT)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KRG00LY4I3XBKE0@brm-avmta-1.central.sun.com>; Tue,
 13 Oct 2009 08:11:58 -0600 (MDT)
Received: from relay13i.sun.com
 (ip123.net129179-4.block1.us.syntegra.com [129.179.4.123])
	by sca-ea-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n9DE9dG3028995;
 Tue, 13 Oct 2009 14:11:57 +0000 (GMT)
Received: from mmp11es.mmp.us.syntegra.com ([160.41.208.11] [160.41.208.11])
 by relay13i.sun.com with ESMTP id BT-MMP-3979869; Tue,
 13 Oct 2009 14:11:56 +0000 (Z)
Received: from relay11i.sun.com (relay11i.sun.com [129.179.4.121])
 by mmp11es.mmp.us.syntegra.com with ESMTP id BT-MMP-138199; Tue,
 13 Oct 2009 14:11:56 +0000 (Z)
Received: from smarthost.TechFak.Uni-Bielefeld.DE
 ([129.70.137.17] [129.70.137.17]) by relay1i.sun.com with ESMTP id
 BT-MMP-9434819; Tue, 13 Oct 2009 14:11:55 +0000 (Z)
Received: from komagatake.TechFak.Uni-Bielefeld.DE
 (komagatake.TechFak.Uni-Bielefeld.DE [129.70.137.126])
	by smarthost.TechFak.Uni-Bielefeld.DE (Postfix) with ESMTP id 9A274A7; Tue,
 13 Oct 2009 16:11:52 +0200 (CEST)
Received: (from ro@localhost)	by komagatake.TechFak.Uni-Bielefeld.DE
 (8.11.7+Sun/8.9.1) id n9DEBqG21383; Tue, 13 Oct 2009 16:11:52 +0200 (MEST)
Date: Tue, 13 Oct 2009 16:11:52 +0200
From: Rainer Orth <ro@techfak.uni-bielefeld.de>
Subject: Re: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
	10/19/2009]
In-reply-to: Jerry Gilliam's message of "Mon, 12 Oct 2009 15:57:41 -0700"
Sender: ro@techfak.uni-bielefeld.de
To: Jerry Gilliam <jerry.gilliam@sun.com>
Cc: PSARC-ext@sun.com, Michael Corcoran <Michael.Corcoran@sun.com>,
        Geetanjali Krishna <geetanjali.krishna@intel.com>,
        Shidokht Yadegari <Shidokht.Yadegari@sun.com>, sherry.moore@sun.com
Message-id: <ydd7huz7593.fsf@komagatake.TechFak.Uni-Bielefeld.DE>
MIME-version: 1.0
X-Mailer: Gnus v5.6.44/Emacs 19.34
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
Lines: 33
References: <4AD3B465.9090701@sun.com>
Status: RO
Content-Length: 1065

Jerry Gilliam <jerry.gilliam@sun.com> writes:

> Interface table and Stability
> =============================
> 
> 	Interface			Classification     Comments
> ----------------------------------------------------------------------------
> /usr/platform/i86pc/lib/acpihpd		Project Private    ACPI HP daemon
> /usr/platform/i86pc/lib/amd64/acpihpd	Project Private    ACPI HP daemon
> /lib/svc/method/acpihp			Project Private    acpihp service
> /var/svc/manifest/platform/i86pc/	Project Private    acpihp manifest
> 	acpihpd.xml
[...]
>       The service FMRI for acpihpd is:
> 
>       svc:/platform/i86pc/acpihpd:default

The FMRI should be an exported interface (and probably Uncomitted).

> NOTES
> 
>       The acpihpd service is managed by the service management  facil-
>       ity, smf(5), under the service identifier:
> 
>       svc:/platform/sun4u/acpihpd:default
		      ^ cut&paste error, it seems :-)

	Rainer

-- 
-----------------------------------------------------------------------------
Rainer Orth, Center for Biotechnology, Bielefeld University


From gww@eng.sun.com Tue Oct 13 13:31:18 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n9DKVHlA009170
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 13 Oct 2009 13:31:17 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n9DKV22I008486
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 13 Oct 2009 21:31:16 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KRG00939ZO31Z00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 13 Oct 2009 13:31:15 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KRG00KDRZO24NE0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 13 Oct 2009 13:31:14 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n9DKVD0D044952; Tue, 13 Oct 2009 13:31:13 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n9DKTnsJ008621; Tue,
 13 Oct 2009 13:29:49 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n9DKTnaV008620; Tue,
 13 Oct 2009 13:29:49 -0700 (PDT)
Date: Tue, 13 Oct 2009 13:29:49 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
To: PSARC-ext@sun.com, Michael.Corcoran@sun.com, geetanjali.krishna@intel.com,
        jerry.gilliam@sun.com
Cc: jiang.liu@intel.com, sherry.moore@sun.com, Shidokht.Yadegari@sun.com
Message-id: <200910132029.n9DKTnaV008620@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 492

> 	The acpihpd is started and stopped using the standard Solaris service
> management facility. The acpihpd is an smf service, and will only be enabled on
> the platforms which supports IOH/CPU/memory hot plug.

	How is the SMF usage policy met?
http://opensolaris.org/os/community/arc/policies/SMF-policy
	Specifically the authorizations, what Rights Profile the authorizations
	will be contained in, method context, ...

	How will this be enabled?  Is it enabled from platform.xml?

Gary..

From Michael.Corcoran@sun.com Wed Oct 14 09:58:16 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n9EGwFEx012303
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 14 Oct 2009 09:58:15 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id n9EGwDIj012432
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 14 Oct 2009 09:58:15 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KRI00201KGJTX00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 14 Oct 2009 09:57:55 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KRI001IKKGHD110@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 14 Oct 2009 09:57:54 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n9EGvrPQ011272	for
 <PSARC-ext@sun.com>; Wed, 14 Oct 2009 16:57:53 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KRI00600K5AH400@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 14 Oct 2009 10:57:53 -0600 (MDT)
Received: from [192.168.0.101]
 (cpe-24-25-218-236.san.res.rr.com [24.25.218.236])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KRI00306KGAPS10@mail-amer.sun.com>; Wed,
 14 Oct 2009 10:57:48 -0600 (MDT)
Date: Wed, 14 Oct 2009 09:57:48 -0700
From: Michael Corcoran <Michael.Corcoran@sun.com>
Subject: Re: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
In-reply-to: <ydd7huz7593.fsf@komagatake.TechFak.Uni-Bielefeld.DE>
Sender: Michael.Corcoran@sun.com
To: Rainer Orth <ro@techfak.uni-bielefeld.de>
Cc: Michael Corcoran <Michael.Corcoran@sun.com>,
        Jerry Gilliam <Jerry.Gilliam@sun.com>, PSARC-ext@sun.com,
        Geetanjali Krishna <geetanjali.krishna@intel.com>,
        Shidokht Yadegari <Shidokht.Yadegari@sun.com>, Sherry.Moore@sun.com
Message-id: <39C0D51D-F997-40EE-A347-5B3D9EEE2C8D@Sun.COM>
MIME-version: 1.0
X-Mailer: Apple Mail (2.936)
Content-type: text/plain; CHARSET=US-ASCII; delsp=yes; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4AD3B465.9090701@sun.com>
 <ydd7huz7593.fsf@komagatake.TechFak.Uni-Bielefeld.DE>
Status: RO
Content-Length: 1221


On Oct 13, 2009, at 7:11 AM, Rainer Orth wrote:

> Jerry Gilliam <jerry.gilliam@sun.com> writes:
>
>> Interface table and Stability
>> =============================
>>
>> 	Interface			Classification     Comments
>> ----------------------------------------------------------------------------
>> /usr/platform/i86pc/lib/acpihpd		Project Private    ACPI HP daemon
>> /usr/platform/i86pc/lib/amd64/acpihpd	Project Private    ACPI HP  
>> daemon
>> /lib/svc/method/acpihp			Project Private    acpihp service
>> /var/svc/manifest/platform/i86pc/	Project Private    acpihp manifest
>> 	acpihpd.xml
> [...]
>>      The service FMRI for acpihpd is:
>>
>>      svc:/platform/i86pc/acpihpd:default
>
> The FMRI should be an exported interface (and probably Uncomitted).

Sounds good.

>
>> NOTES
>>
>>      The acpihpd service is managed by the service management  facil-
>>      ity, smf(5), under the service identifier:
>>
>>      svc:/platform/sun4u/acpihpd:default
> 		      ^ cut&paste error, it seems :-)

Yes, this should be i86pc as above.

Thanks,

Mike

>
> 	Rainer
>
> -- 
> -----------------------------------------------------------------------------
> Rainer Orth, Center for Biotechnology, Bielefeld University
>


From Michael.Corcoran@Sun.COM Thu Oct 15 20:25:37 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n9G3PbQn011679
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 15 Oct 2009 20:25:37 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id n9G3PZaD025354
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 15 Oct 2009 20:25:36 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KRL0010386OZB00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 15 Oct 2009 20:25:36 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KRL00JHU86O9820@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 15 Oct 2009 20:25:36 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n9G3Paeo005453	for
 <PSARC-ext@sun.com>; Fri, 16 Oct 2009 03:25:36 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KRL0030080XX500@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 15 Oct 2009 21:25:35 -0600 (MDT)
Received: from [129.153.89.28] ([unknown] [129.153.89.28])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KRL00KLQ86NUF20@mail-amer.sun.com>; Thu,
 15 Oct 2009 21:25:35 -0600 (MDT)
Date: Thu, 15 Oct 2009 20:26:17 -0700
From: Michael Corcoran <Michael.Corcoran@Sun.COM>
Subject: Re: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
In-reply-to: <200910132029.n9DKTnaV008620@marduk.eng.sun.com>
Sender: Michael.Corcoran@Sun.COM
To: Gary Winiger <gww@eng.sun.com>
Cc: Michael.Corcoran@Sun.COM, PSARC-ext@Sun.COM, geetanjali.krishna@intel.com,
        Jerry.Gilliam@Sun.COM, jiang.liu@intel.com, Sherry.Moore@Sun.COM,
        Shidokht.Yadegari@Sun.COM
Message-id: <1255663577.848.1950.camel@mecos>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200910132029.n9DKTnaV008620@marduk.eng.sun.com>
Status: RO
Content-Length: 1086

Hi Gary,

I'm working with Intel to answer your questions.  Essentially we want to
provide the least amount of access possible for this daemon to do its
job.

For starting the daemon, I'm guessing that we'll have to create
something similar to
usr/src/cmd/svc/profile/platform_SUNW,SPARC-Enterprise.xml
for these x86 machines since we want the service to be enabled by
default on the platforms that support it.  Does anyone have any
recommendation about who to talk to about how to get this done?

Thanks,

Mike

On Tue, 2009-10-13 at 13:29 -0700, Gary Winiger wrote:
> > 	The acpihpd is started and stopped using the standard Solaris service
> > management facility. The acpihpd is an smf service, and will only be enabled on
> > the platforms which supports IOH/CPU/memory hot plug.
> 
> 	How is the SMF usage policy met?
> http://opensolaris.org/os/community/arc/policies/SMF-policy
> 	Specifically the authorizations, what Rights Profile the authorizations
> 	will be contained in, method context, ...
> 
> 	How will this be enabled?  Is it enabled from platform.xml?
> 
> Gary..



From gww@eng.sun.com Fri Oct 16 14:53:49 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n9GLrnJ1014408
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 16 Oct 2009 14:53:49 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id n9GLrn7O023260
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 16 Oct 2009 14:53:49 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KRM00E03NHPXW00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 16 Oct 2009 14:53:49 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KRM0002JNHPG8D0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 16 Oct 2009 14:53:49 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id n9GLrlb2028953; Fri, 16 Oct 2009 14:53:47 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n9GLqI7D012225; Fri,
 16 Oct 2009 14:52:18 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n9GLqI2E012224; Fri,
 16 Oct 2009 14:52:18 -0700 (PDT)
Date: Fri, 16 Oct 2009 14:52:18 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
To: gww@eng.sun.com, Michael.Corcoran@sun.com
Cc: PSARC-ext@sun.com, geetanjali.krishna@intel.com, Jerry.Gilliam@sun.com,
        jiang.liu@intel.com, Sherry.Moore@sun.com, Shidokht.Yadegari@sun.com
Message-id: <200910162152.n9GLqI2E012224@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 2045

Mike,

> I'm working with Intel to answer your questions.  Essentially we want to
> provide the least amount of access possible for this daemon to do its
> job.

	IIRC, my initial question had 3 parts:  How does the project meet
	the SMF requirement for authorizations to manage?  What is the
	Method Context used to start the service? The service is to be
	enabled only on the xxx platform - how is this done?

	I'd like to clarify the first part about authorizations.  When
	we talked I may not have been complete.
	If there are no properties that configure the service as in
	a property group of type application, there is no need for
	value authorizations to manage them.
	If the service is never intended to be enabled/disabled by
	the administrator (but always enabled/started automatically
	at boot time and never disabled), there is no need for
	action/value authorizations to manage the service.
	If both are true and there is no need for defining authorizations
	for the service, there is no need for a service related 
	Rights Profile.

HTH,
Gary..
> 
> For starting the daemon, I'm guessing that we'll have to create
> something similar to
> usr/src/cmd/svc/profile/platform_SUNW,SPARC-Enterprise.xml
> for these x86 machines since we want the service to be enabled by
> default on the platforms that support it.  Does anyone have any
> recommendation about who to talk to about how to get this done?
> 
> Thanks,
> 
> Mike
> 
> On Tue, 2009-10-13 at 13:29 -0700, Gary Winiger wrote:
> > > 	The acpihpd is started and stopped using the standard Solaris service
> > > management facility. The acpihpd is an smf service, and will only be enabled on
> > > the platforms which supports IOH/CPU/memory hot plug.
> > 
> > 	How is the SMF usage policy met?
> > http://opensolaris.org/os/community/arc/policies/SMF-policy
> > 	Specifically the authorizations, what Rights Profile the authorizations
> > 	will be contained in, method context, ...
> > 
> > 	How will this be enabled?  Is it enabled from platform.xml?
> > 
> > Gary..
> 
> 
> 

From jiang.liu@intel.com Sat Oct 24 08:05:03 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n9OF53d4023028
	for <psarc-ext@sac.sfbay.sun.com>; Sat, 24 Oct 2009 08:05:03 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n9OF4uUM013599;
	Sat, 24 Oct 2009 16:04:58 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KS000701XW94K00@brm-avmta-1.central.sun.com>; Sat,
 24 Oct 2009 09:04:57 -0600 (MDT)
Received: from sca-ea-mail-5.sun.com ([192.18.43.14])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KS000CN0XW9MH80@brm-avmta-1.central.sun.com>; Sat,
 24 Oct 2009 09:04:57 -0600 (MDT)
Received: from mga02.intel.com (mga02.intel.com [134.134.136.20])
	by sca-ea-mail-5.sun.com (8.13.7+Sun/8.12.8) with ESMTP id n9OF4uWL012701
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=FAIL); Sat,
 24 Oct 2009 15:04:56 +0000 (GMT)
Received: from orsmga002.jf.intel.com ([10.7.209.21]) by orsmga101.jf.intel.com
 with ESMTP; Sat, 24 Oct 2009 07:48:42 -0700
Received: from pgsmsx602.gar.corp.intel.com ([10.221.43.81])
 by orsmga002.jf.intel.com with ESMTP; Sat, 24 Oct 2009 08:10:29 -0700
Received: from pdsmsx602.ccr.corp.intel.com (172.16.12.184)
 by pgsmsx602.gar.corp.intel.com (10.221.43.81) with Microsoft SMTP Server
 (TLS) id 8.1.358.0; Sat, 24 Oct 2009 23:04:53 +0800
Received: from pdsmsx501.ccr.corp.intel.com ([172.16.12.89])
 by pdsmsx602.ccr.corp.intel.com ([172.16.12.184]) with mapi; Sat,
 24 Oct 2009 23:04:52 +0800
Date: Sat, 24 Oct 2009 22:58:56 +0800
From: "Liu, Jiang" <jiang.liu@intel.com>
Subject: RE: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
In-reply-to: <200910162152.n9GLqI2E012224@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>,
        "Michael.Corcoran@sun.com" <Michael.Corcoran@sun.com>
Cc: "PSARC-ext@sun.com" <PSARC-ext@sun.com>,
        "Krishna, Geetanjali" <geetanjali.krishna@intel.com>,
        "Jerry.Gilliam@sun.com" <Jerry.Gilliam@sun.com>,
        "Sherry.Moore@sun.com" <Sherry.Moore@sun.com>,
        "Shidokht.Yadegari@sun.com" <Shidokht.Yadegari@sun.com>
Message-id: 
 <E2263E4A5B2284449EEBD0AAB751098418E4616EDE@PDSMSX501.ccr.corp.intel.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-language: en-US
Content-transfer-encoding: 7BIT
Accept-Language: en-US
Thread-topic: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
Thread-index: AcpOqzVKyB8JAkUEQWSIlRatnww2tAGDAUTA
acceptlanguage: en-US
X-PMX-Version: 5.4.1.325704
X-ExtLoop1: 1
X-IronPort-AV: E=Sophos;i="4.44,617,1249282800";   d="scan'208";a="460906026"
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
References: <200910162152.n9GLqI2E012224@marduk.eng.sun.com>
Status: RO
Content-Length: 3460

Hi Gary,
	Thanks for your comments and sorry for later reply because it
costed me some time to get more background knowledge about SMF
on Solaris. Basically we use the simplest service manifest file for the
acpihpd service and haven't defined any security relative properties
in the service manifest file.
	Please also refer to inline comments below.
	Thanks!
	--Gerry

Gary Winiger <mailto:gww@eng.sun.com> wrote:
> Mike,
> 
>> I'm working with Intel to answer your questions.  Essentially we
>> want to provide the least amount of access possible for this daemon
>> to do its job.
> 
> 	IIRC, my initial question had 3 parts:  How does the project meet
> 	the SMF requirement for authorizations to manage?  What is the
> 	Method Context used to start the service? The service is to be
We haven't defined any method_environment, method_profile, 
method_credential or method_context properties in the manifest file.
So it should use the default configuration, is that OK?

> 	enabled only on the xxx platform - how is this done?
The service will be enabled on all x86 platforms. We provide an x86
specific package named SUNWacpihpd, which includes the service 
manifest file for acpihpd. When installing the package, the acpihpd 
service should be installed and enabled. So seems we don't need to
touch the platform profile file, is that true?

> 
> 	I'd like to clarify the first part about authorizations.  When
> 	we talked I may not have been complete.
> 	If there are no properties that configure the service as in
> 	a property group of type application, there is no need for
> 	value authorizations to manage them.
Currently acpihpd service doesn't define any properties of category
"application", so seems we don't need to define the "modify_authorization",
"value_authorization" and "read_authorization" security properties.
Is that true?

> 	If the service is never intended to be enabled/disabled by
> 	the administrator (but always enabled/started automatically
> 	at boot time and never disabled), there is no need for
> 	action/value authorizations to manage the service.
The service should always be enabled and not intended to be managed
by administrators.

> 	If both are true and there is no need for defining authorizations
> 	for the service, there is no need for a service related
> 	Rights Profile.
So, seems there is no security relative properties needed for such a service.

> 
> HTH,
> Gary..
>> 
>> For starting the daemon, I'm guessing that we'll have to create
>> something similar to
>> usr/src/cmd/svc/profile/platform_SUNW,SPARC-Enterprise.xml 
>> for these x86 machines since we want the service to be enabled by
>> default on the platforms that support it.  Does anyone have any
>> recommendation about who to talk to about how to get this done?
>> 
>> Thanks,
>> 
>> Mike
>> 
>> On Tue, 2009-10-13 at 13:29 -0700, Gary Winiger wrote:
>>>> 	The acpihpd is started and stopped using the standard Solaris
>>>> service management facility. The acpihpd is an smf service, and
>>>> will only be enabled on the platforms which supports
>>>> IOH/CPU/memory hot plug. 
>>> 
>>> 	How is the SMF usage policy met?
>>> http://opensolaris.org/os/community/arc/policies/SMF-policy
>>> 	Specifically the authorizations, what Rights Profile the
>>> 	authorizations will be contained in, method context, ...
>>> 
>>> 	How will this be enabled?  Is it enabled from platform.xml?
>>> 
>>> Gary..

Liu Jiang (Gerry)
OpenSolaris, OTC, SSG, Intel

From gww@eng.sun.com Mon Nov 16 15:26:42 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAGNQgmG027174
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 16 Nov 2009 15:26:42 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id nAGNQenN008826
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 16 Nov 2009 16:26:41 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KT800L036GGXJ00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 16 Nov 2009 15:26:40 -0800 (PST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KT800JY86GG8P80@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 16 Nov 2009 15:26:40 -0800 (PST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nAGNQdGr005417; Mon, 16 Nov 2009 15:26:39 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id nAGNQJ3c012668; Mon,
 16 Nov 2009 15:26:19 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id nAGNQJ8I012667; Mon,
 16 Nov 2009 15:26:19 -0800 (PST)
Date: Mon, 16 Nov 2009 15:26:19 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: RE: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
To: gww@eng.sun.com, Michael.Corcoran@sun.com, jiang.liu@intel.com
Cc: PSARC-ext@sun.com, geetanjali.krishna@intel.com, Jerry.Gilliam@sun.com,
        Sherry.Moore@sun.com, Shidokht.Yadegari@sun.com
Message-id: <200911162326.nAGNQJ8I012667@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 3232

Gerry,

> 	Please also refer to inline comments below.
> 	Thanks!
> 	--Gerry
> 
> Gary Winiger <mailto:gww@eng.sun.com> wrote:
> > Mike,
> > 
> >> I'm working with Intel to answer your questions.  Essentially we
> >> want to provide the least amount of access possible for this daemon
> >> to do its job.
> > 
> > 	IIRC, my initial question had 3 parts:  How does the project meet
> > 	the SMF requirement for authorizations to manage?  What is the
> > 	Method Context used to start the service? The service is to be
> We haven't defined any method_environment, method_profile, 
> method_credential or method_context properties in the manifest file.
> So it should use the default configuration, is that OK?

	Not really.  The point is to meet the principle of least privilege.
	That is done with a method_context in the start method.  The
	default method_context is euid=ruid=egid=rgid = 0, privs = all.
	Why is this required for this service?  What above noaccess,
	privs = none is actually required?

> > 	enabled only on the xxx platform - how is this done?
> The service will be enabled on all x86 platforms. We provide an x86
> specific package named SUNWacpihpd, which includes the service 
> manifest file for acpihpd. When installing the package, the acpihpd 
> service should be installed and enabled. So seems we don't need to
> touch the platform profile file, is that true?

	I personally don't know about how the platform profiles are
	intended to be used.  Contact the smf team about that.  The
	SMF usage policy
http://hub.opensolaris.org/bin/view/Community+Group+arc/SMF%2Dpolicy
	states:
    "Services must be delivered (by manifest or programatically) disabled by
     default to align with Sun's security goals. Projects impacted by
     Appendix C, must consult with the ARC to determine if this aspect of the
     policy is applicable."
	
	So, it seems that the project team should address why and how
	the service is enabled.
	
> > 	I'd like to clarify the first part about authorizations.  When
> > 	we talked I may not have been complete.
> > 	If there are no properties that configure the service as in
> > 	a property group of type application, there is no need for
> > 	value authorizations to manage them.
> Currently acpihpd service doesn't define any properties of category
> "application", so seems we don't need to define the "modify_authorization",
> "value_authorization" and "read_authorization" security properties.
> Is that true?

	"application" type property groups are not the only types that
	have configurable properties.  The question is about any/all
	configurable properties.  Property group types are arbitrary.

> > 	If the service is never intended to be enabled/disabled by
> > 	the administrator (but always enabled/started automatically
> > 	at boot time and never disabled), there is no need for
> > 	action/value authorizations to manage the service.
> The service should always be enabled and not intended to be managed
> by administrators.

	So there are no circumstances that the service should be disabled?

	Then I think the open questions are:
		1) what is the least user/group ids and privileges?
		2) how is the service enabled?
		3) is there any configuration?

Gary..

From casper@holland.sun.com Tue Nov 17 01:04:01 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAH940Cq019919
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Nov 2009 01:04:01 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id nAH93xFl023746
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Tue, 17 Nov 2009 09:04:00 GMT
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KT80061XX6NTJ00@brm-avmta-1.central.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Tue, 17 Nov 2009 02:03:59 -0700 (MST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KT800A4RX6LISB0@brm-avmta-1.central.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Tue,
 17 Nov 2009 02:03:58 -0700 (MST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id nAH93o35023432; Tue, 17 Nov 2009 09:03:50 +0000 (GMT)
Date: Tue, 17 Nov 2009 10:03:50 +0100
From: Casper.Dik@sun.com
Subject: Re: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
In-reply-to: <200911162326.nAGNQJ8I012667@marduk.eng.sun.com>
Sender: casper@holland.sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: Michael.Corcoran@sun.com, jiang.liu@intel.com, PSARC-ext@sun.com,
        geetanjali.krishna@intel.com, Jerry.Gilliam@sun.com,
        Sherry.Moore@sun.com, Shidokht.Yadegari@sun.com
Message-id: <200911170903.nAH93o35023432@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200911162326.nAGNQJ8I012667@marduk.eng.sun.com>
Status: RO
Content-Length: 471



>	Not really.  The point is to meet the principle of least privilege.
>	That is done with a method_context in the start method.  The
>	default method_context is euid=ruid=egid=rgid = 0, privs = all.
>	Why is this required for this service?  What above noaccess,
>	privs = none is actually required?

Please use "priv=basic" if you want to define a "a standard account";
priv=none may not be enough not or in the future.

I agree with the general sentiment :-)

Casper


From jiang.liu@intel.com Thu Nov 26 04:34:07 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAQCY7gL005006
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 26 Nov 2009 04:34:07 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nAQCY6rR013997;
	Thu, 26 Nov 2009 04:34:06 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KTP00B01UWUO400@brm-avmta-1.central.sun.com>; Thu,
 26 Nov 2009 05:34:06 -0700 (MST)
Received: from cltea-mail-1.sun.com ([192.18.128.18])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KTP00FN4UWTXX70@brm-avmta-1.central.sun.com>; Thu,
 26 Nov 2009 05:34:06 -0700 (MST)
Received: from mga09.intel.com (mga09.intel.com [134.134.136.24])
	by cltea-mail-1.sun.com (8.13.6/8.12.8) with ESMTP id nAQCXOql013400
	(version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=FAIL); Thu,
 26 Nov 2009 12:33:25 +0000 (GMT)
Received: from orsmga002.jf.intel.com ([10.7.209.21]) by orsmga102.jf.intel.com
 with ESMTP; Thu, 26 Nov 2009 04:33:48 -0800
Received: from pgsmsx603.gar.corp.intel.com ([10.221.43.87])
 by orsmga002.jf.intel.com with ESMTP; Thu, 26 Nov 2009 04:51:01 -0800
Received: from pdsmsx601.ccr.corp.intel.com (172.16.12.94)
 by pgsmsx603.gar.corp.intel.com (10.221.43.87) with Microsoft SMTP Server
 (TLS) id 8.1.358.0; Thu, 26 Nov 2009 20:34:01 +0800
Received: from pdsmsx501.ccr.corp.intel.com ([172.16.12.89])
 by pdsmsx601.ccr.corp.intel.com ([172.16.12.94]) with mapi; Thu,
 26 Nov 2009 20:34:00 +0800
Date: Thu, 26 Nov 2009 20:30:59 +0800
From: "Liu, Jiang" <jiang.liu@intel.com>
Subject: RE: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
In-reply-to: <200911162326.nAGNQJ8I012667@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>,
        "Michael.Corcoran@sun.com" <Michael.Corcoran@sun.com>
Cc: "PSARC-ext@sun.com" <PSARC-ext@sun.com>,
        "Krishna, Geetanjali" <geetanjali.krishna@intel.com>,
        "Jerry.Gilliam@sun.com" <Jerry.Gilliam@sun.com>,
        "Sherry.Moore@sun.com" <Sherry.Moore@sun.com>,
        "Shidokht.Yadegari@sun.com" <Shidokht.Yadegari@sun.com>
Message-id: 
 <E2263E4A5B2284449EEBD0AAB751098418E5742D8C@PDSMSX501.ccr.corp.intel.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-language: en-US
Content-transfer-encoding: 7BIT
Accept-Language: en-US
Thread-topic: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
Thread-index: AcpnFENCEnZGzbqZSUymjm8IGAjQ1QHMVruA
acceptlanguage: en-US
X-PMX-Version: 5.4.1.325704
X-ExtLoop1: 1
X-IronPort-AV: E=Sophos;i="4.47,293,1257148800";   d="scan'208";a="470775023"
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
References: <200911162326.nAGNQJ8I012667@marduk.eng.sun.com>
Status: RO
Content-Length: 4728

Hi Gary,
	Sorry for late reply, it took us sometime to figure out the
preferred way for acpihpd service.

> 	Then I think the open questions are:
> 		1) what is the least user/group ids and privileges?
Acpihpd needs to call sysevent library, and libsysevent rejects
requests if the caller isn't root. So acpihpd must be run as root.
We are trying to use following method context for acpihpd.
		<method_context>
			<method_credential
				user='root'
				group='daemon'
				privileges='basic,!proc_info,sys_config,sys_mount,sys_devices' />
		</method_context> 

> 		2) how is the service enabled?
We will try to add a profile file for x86 platforms and enable 
acpihpd in platform_x86.xml. And acpihpd will be set to disable
in acpihpd.xml by default.

> 		3) is there any configuration?
Currently there's no configuration for acpihpd, so no special authorization
needed for accessing service properties.

For safety, we will add following authorization control for acpihpd.
	<property_group name='general' type='framework'>
                <propval name='action_authorization' type='astring'
                        value='solaris.smf.manage.acpihpd' />
                <propval name='value_authorization' type='astring'
                        value='solaris.smf.manage.acpihpd' />
	</property_group>

Thanks!

Gary Winiger <mailto:gww@eng.sun.com> wrote:
> Gerry,
> 
>> 	Please also refer to inline comments below.
>> 	Thanks!
>> 	--Gerry
>> 
>> Gary Winiger <mailto:gww@eng.sun.com> wrote:
>>> Mike,
>>> 
>>>> I'm working with Intel to answer your questions.  Essentially we
>>>> want to provide the least amount of access possible for this daemon
>>>> to do its job.
>>> 
>>> 	IIRC, my initial question had 3 parts:  How does the project meet
>>> 	the SMF requirement for authorizations to manage?  What is the
>>> 	Method Context used to start the service? The service is to be
>> We haven't defined any method_environment, method_profile,
>> method_credential or method_context properties in the manifest file.
>> So it should use the default configuration, is that OK?
> 
> 	Not really.  The point is to meet the principle of least privilege.
> 	That is done with a method_context in the start method.  The
> 	default method_context is euid=ruid=egid=rgid = 0, privs = all.
> 	Why is this required for this service?  What above noaccess,
> 	privs = none is actually required?
> 
>>> 	enabled only on the xxx platform - how is this done?
>> The service will be enabled on all x86 platforms. We provide an x86
>> specific package named SUNWacpihpd, which includes the service
>> manifest file for acpihpd. When installing the package, the acpihpd
>> service should be installed and enabled. So seems we don't need to
>> touch the platform profile file, is that true?
> 
> 	I personally don't know about how the platform profiles are
> 	intended to be used.  Contact the smf team about that.  The
> 	SMF usage policy
> http://hub.opensolaris.org/bin/view/Community+Group+arc/SMF%2Dpolicy
> 	states:
>     "Services must be delivered (by manifest or programatically)
>      disabled by default to align with Sun's security goals. Projects
>      impacted by Appendix C, must consult with the ARC to determine
>      if this aspect of the policy is applicable."
> 
> 	So, it seems that the project team should address why and how
> 	the service is enabled.
> 
>>> 	I'd like to clarify the first part about authorizations.  When
>>> 	we talked I may not have been complete.
>>> 	If there are no properties that configure the service as in
>>> 	a property group of type application, there is no need for
>>> 	value authorizations to manage them.
>> Currently acpihpd service doesn't define any properties of category
>> "application", so seems we don't need to define the
>> "modify_authorization", "value_authorization" and
>> "read_authorization" security properties. 
>> Is that true?
> 
> 	"application" type property groups are not the only types that
> 	have configurable properties.  The question is about any/all
> 	configurable properties.  Property group types are arbitrary.
> 
>>> 	If the service is never intended to be enabled/disabled by
>>> 	the administrator (but always enabled/started automatically
>>> 	at boot time and never disabled), there is no need for
>>> 	action/value authorizations to manage the service.
>> The service should always be enabled and not intended to be managed
>> by administrators.
> 
> 	So there are no circumstances that the service should be disabled?
> 
> 	Then I think the open questions are:
> 		1) what is the least user/group ids and privileges?
> 		2) how is the service enabled?
> 		3) is there any configuration?
> 
> Gary..

Liu Jiang (Gerry)
OpenSolaris, OTC, SSG, Intel

From jerry.gilliam@sun.com Wed Dec  2 15:03:31 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nB2N3VOq003021
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 2 Dec 2009 15:03:31 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nB2N3Ut1004453;
	Wed, 2 Dec 2009 15:03:30 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KU100601S1UZN00@brm-avmta-1.central.sun.com>; Wed,
 02 Dec 2009 16:03:30 -0700 (MST)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KU100EQ5S1R7C90@brm-avmta-1.central.sun.com>; Wed,
 02 Dec 2009 16:03:28 -0700 (MST)
Received: from [129.146.226.92] (tethys.SFBay.Sun.COM [129.146.226.92])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id nB2N3Rk6648700; Wed, 02 Dec 2009 15:03:27 -0800 (PST)
Date: Wed, 02 Dec 2009 14:55:43 -0800
From: Jerry Gilliam <jerry.gilliam@sun.com>
Subject: Re: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
In-reply-to: <4AD3B465.9090701@sun.com>
To: PSARC-ext@sun.com, Michael Corcoran <Michael.Corcoran@sun.com>,
        Geetanjali Krishna <geetanjali.krishna@intel.com>
Cc: Jiang Liu <jiang.liu@intel.com>, sherry.moore@sun.com,
        Shidokht Yadegari <Shidokht.Yadegari@sun.com>
Message-id: <4B16F06F.7080708@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4AD3B465.9090701@sun.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20091013)
Status: RO
Content-Length: 4563


An updated spec for this case, included below, is now ready for
review as a fast-track.  The spec includes marks where changed.
I've reset the timer for a week, to 12/09/2009.

-------------------

Introduction
===========
	Future Intel high-end server platforms support IOH/CPU/memory
hot plug. To enable ACPI based IOH/CPU/memory hot plug, an ACPI hot plug
daemon (acpihpd) is needed to handle events generated by the ACPI subsystem
and maintain state changes.

Release Binding
===============
minor

Dependency
===========
	The acpihpd daemon has dependency on syseventd daemon to relay hot
plug events. It also has dependency on cfgadm framework and sbd plugin to
handle hot plug events. Acpihpd receives hot plug events from syseventd
and invokes cfgadm library to handle these events.

Technical Detail
================
	The acpihpd daemon registers for DR request events and handles them
when they arrive.
	The acpihpd daemon would subscribe to EC_DR/ESC_DR_REQ sysevents
(defined in PSARC/2000/189). When IOH/CPU/memory hot plug events arrive,
the acpihpd parses the DR request and calls into the cfgadm library to
add/remove devices from the system. DR requests are handled by cfgadm
framework.
	The events that the acpihpd is interested in are published by ACPI
virtual nexus driver (acpinex). ACPI BIOS generates ACPI system notifications
when user initiates a device insertion/removal. These notifications will be
forwarded to acpinex driver by the acpica driver. When acpinex driver gets
notifications, it translates the device into Attachment Point and generates
EC_DR/ESC_DR_REQ events.
	When EC_DR/ESC_DR_REQ events are relayed to acpihpd daemon, it invokes
cfgadm library to handle the events. It also takes the responsibility to
udpate other components as part of the DR operation, for example, notify power
management by executing pmconfig command.
	The acpihpd is started and stopped using the standard Solaris service
management facility. The acpihpd is an smf service, and will only be enabled on
the platforms which supports IOH/CPU/memory hot plug via an i86pc specific	|
profile.  Unfortunately, the service has to run as root as it relies on the	|
sysevent library which will reject any request from a non-root user.  The	|
privileges will be restricted to 'basic,!proc_info,sys_config,sys_mount,	|
sys_devices'.									|

Interface table and Stability
=============================

	Interface			Classification     Comments
----------------------------------------------------------------------------
/usr/platform/i86pc/lib/acpihpd		Project Private    ACPI HP daemon
/usr/platform/i86pc/lib/amd64/acpihpd	Project Private    ACPI HP daemon
/lib/svc/method/acpihp			Project Private    acpihp service
/var/svc/manifest/platform/i86pc/	Project Private    acpihp manifest
	acpihpd.xml



System Administration Commands                            acpihpd(1M)

NAME
       acpihpd - ACPI hot plug daemon

SYNOPSIS
       /usr/platform/i86pc/lib/acpihpd

DESCRIPTION
       The ACPI hot plug daemon is a daemon process that runs on x86 platforms.
       The daemon is started by the service management facility. It communicates
       with the syseventd and cfgadm sub-systems to handle ACPI events from
       hotpluggable devices.

       The service FMRI for acpihpd is:

       svc:/platform/i86pc/acpihpd:default

OPTIONS
       The acpihpd does not support any options.

ERRORS
       acpihpd uses syslog(3C) to report status and error messages.
       All of the messages are logged with the LOG_DAEMON facility.

       Error messages are logged with the  LOG_ERR  and  LOG_NOTICE
       priorities, and informational messages are logged with the
       LOG_DEBUG priority.   The   default    entries    in    the
       /etc/syslog.conf  file  log all of the DCS error messages to
       the /var/adm/messages log.

ATTRIBUTES

       See attributes(5) for descriptions of the  following  attri-
       butes:
       ____________________________________________________________
      |       ATTRIBUTE TYPE        |       ATTRIBUTE VALUE       |
      |_____________________________|_____________________________|
      | Availability                | SUNWacpihpd                 |
      |_____________________________|_____________________________|

SEE ALSO

       svcs(1), inetadm(1M), svcadm(1M), syslog(3C), syslog.conf(4),
       attributes(5)

NOTES

       The acpihpd service is managed by the service management  facil-
       ity, smf(5), under the service identifier:

       svc:/platform/i86pc/acpihpd:default					|


From glenn.skinner@covad.net Wed Dec  2 16:04:40 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nB304eBe004560
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 2 Dec 2009 16:04:40 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nB304b9d001336;
	Wed, 2 Dec 2009 17:04:38 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KU10040BUVQNO00@nwk-avmta-2.sfbay.sun.com>; Wed,
 02 Dec 2009 16:04:38 -0800 (PST)
Received: from sca-ea-mail-3.sun.com ([192.18.43.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KU100GCRUVPW3D0@nwk-avmta-2.sfbay.sun.com>; Wed,
 02 Dec 2009 16:04:37 -0800 (PST)
Received: from relay42i.sun.com ([192.5.209.72])
	by sca-ea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nB304b4G002388;
 Thu, 03 Dec 2009 00:04:37 +0000 (GMT)
Received: from mms48es.mms.us.syntegra.com ([160.41.221.230] [160.41.221.230])
 by relay42i.sun.com with ESMTP id BT-MMP-1853964; Thu,
 03 Dec 2009 00:04:37 +0000 (Z)
Received: from relay44i.sun.com (relay44i.sun.com [192.5.209.118])
 by mms48es.mms.us.syntegra.com with ESMTP id BT-MMP-10800299; Thu,
 03 Dec 2009 00:04:36 +0000 (Z)
Received: from mail155c8.megamailservers.com
 ([209.235.129.65] [209.235.129.65]) by relay4i.sun.com with ESMTP id
 BT-MMP-4638061; Thu, 03 Dec 2009 00:04:35 +0000 (Z)
Received: from [192.168.1.106]
 (h-64-105-36-23.snvacaid.static.covad.net [64.105.36.23])
	by mail155c8.megamailservers.com (8.13.6/8.13.1) with ESMTP id nB3042Zo030432;
 Wed, 02 Dec 2009 19:04:33 -0500
Date: Wed, 02 Dec 2009 16:04:01 -0800
From: Glenn Skinner <glenn.skinner@covad.net>
Subject: Re: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
In-reply-to: <4B16F06F.7080708@sun.com>
To: Jerry Gilliam <jerry.gilliam@sun.com>
Cc: PSARC-ext@sun.com, Michael Corcoran <Michael.Corcoran@sun.com>,
        Geetanjali Krishna <geetanjali.krishna@intel.com>,
        Shidokht Yadegari <Shidokht.Yadegari@sun.com>, sherry.moore@sun.com
Message-id: <EDACD162-2AD8-4652-9E99-EEFD0F7EE6D5@covad.net>
MIME-version: 1.0
X-Mailer: Apple Mail (2.936)
Content-type: text/plain; charset=US-ASCII; format=flowed; delsp=yes
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-POP-User: dbclispr.covad.net
X-Antispam: No, score=-0.7/5.0, scanned in 0.611sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <4AD3B465.9090701@sun.com> <4B16F06F.7080708@sun.com>
Status: RO
Content-Length: 1308


On Dec 2, 2009, at 2:55 PM, Jerry Gilliam wrote:

>
> An updated spec for this case, included below, is now ready for
> review as a fast-track.  The spec includes marks where changed.
> I've reset the timer for a week, to 12/09/2009.

...
> 	The acpihpd is started and stopped using the standard Solaris service
> management facility. The acpihpd is an smf service, and will only be  
> enabled on
> the platforms which supports IOH/CPU/memory hot plug via an i86pc  
> specific	|
> profile.  Unfortunately, the service has to run as root as it relies  
> on the	|
> sysevent library which will reject any request from a non-root  
> user.  The	|
> privileges will be restricted to 'basic,! 
> proc_info,sys_config,sys_mount,	|
> sys_devices'.									|

I realize that this case is just working with what it's given and that  
that's why running as root is required, but why does the sysevent  
library make explicit checks for root in the first place?  Is there  
something that prevents it from expecting its clients to have suitable  
privileges and simply passing failures due to insufficient privilege  
back to its clients?

Stated a bit differently, I'm wondering whether a bug should be filed  
against the sysevent library for non-conformance to the Solaris  
privilege architecture.

		-- Glenn


From Michael.Corcoran@sun.com Wed Dec  2 16:31:31 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nB30VUWZ005100
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 2 Dec 2009 16:31:31 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nB30VUkX017907
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 2 Dec 2009 17:31:30 -0700 (MST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KU100G07W4I8Q00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 02 Dec 2009 17:31:30 -0700 (MST)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KU100ES2W4H79D0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 02 Dec 2009 17:31:29 -0700 (MST)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nB30VTFh013660	for
 <PSARC-ext@sun.com>; Thu, 03 Dec 2009 00:31:29 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KU100D00W227E00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 02 Dec 2009 17:31:29 -0700 (MST)
Received: from [192.168.0.101]
 (cpe-24-25-218-236.san.res.rr.com [24.25.218.236])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KU100J9PW4F7M70@mail-amer.sun.com>; Wed,
 02 Dec 2009 17:31:28 -0700 (MST)
Date: Wed, 02 Dec 2009 16:31:27 -0800
From: Michael Corcoran <Michael.Corcoran@sun.com>
Subject: Re: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
In-reply-to: <EDACD162-2AD8-4652-9E99-EEFD0F7EE6D5@covad.net>
Sender: Michael.Corcoran@sun.com
To: Glenn Skinner <glenn.skinner@covad.net>
Cc: Michael Corcoran <Michael.Corcoran@sun.com>,
        Jerry Gilliam <Jerry.Gilliam@sun.com>, PSARC-ext@sun.com,
        Geetanjali Krishna <geetanjali.krishna@intel.com>,
        Shidokht Yadegari <Shidokht.Yadegari@sun.com>, Sherry.Moore@sun.com
Message-id: <706F4C9B-497A-4A3A-9D0D-49EAEB9ED123@Sun.COM>
MIME-version: 1.0
X-Mailer: Apple Mail (2.936)
Content-type: text/plain; CHARSET=US-ASCII; delsp=yes; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4AD3B465.9090701@sun.com> <4B16F06F.7080708@sun.com>
 <EDACD162-2AD8-4652-9E99-EEFD0F7EE6D5@covad.net>
Status: RO
Content-Length: 1509


On Dec 2, 2009, at 4:04 PM, Glenn Skinner wrote:

>
> On Dec 2, 2009, at 2:55 PM, Jerry Gilliam wrote:
>
>>
>> An updated spec for this case, included below, is now ready for
>> review as a fast-track.  The spec includes marks where changed.
>> I've reset the timer for a week, to 12/09/2009.
>
> ...
>> 	The acpihpd is started and stopped using the standard Solaris  
>> service
>> management facility. The acpihpd is an smf service, and will only  
>> be enabled on
>> the platforms which supports IOH/CPU/memory hot plug via an i86pc  
>> specific	|
>> profile.  Unfortunately, the service has to run as root as it  
>> relies on the	|
>> sysevent library which will reject any request from a non-root  
>> user.  The	|
>> privileges will be restricted to 'basic,! 
>> proc_info,sys_config,sys_mount,	|
>> sys_devices'.									|
>
> I realize that this case is just working with what it's given and  
> that that's why running as root is required, but why does the  
> sysevent library make explicit checks for root in the first place?   
> Is there something that prevents it from expecting its clients to  
> have suitable privileges and simply passing failures due to  
> insufficient privilege back to its clients?
>
> Stated a bit differently, I'm wondering whether a bug should be  
> filed against the sysevent library for non-conformance to the  
> Solaris privilege architecture.

Glenn,

It's already been filed:

6816881 sysevent_bind_handle() includes uid==0 check

--Mike

>
> 		-- Glenn
>


From Michael.Corcoran@sun.com Wed Dec  2 22:36:57 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nB36av0n012097
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 2 Dec 2009 22:36:57 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nB36RXrc005740
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 2 Dec 2009 22:36:53 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KU200803D19KB00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 02 Dec 2009 22:36:45 -0800 (PST)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KU2006EID19U110@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 02 Dec 2009 22:36:45 -0800 (PST)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nB36ajGs000555	for
 <PSARC-ext@sun.com>; Thu, 03 Dec 2009 06:36:45 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KU200J00D0CQI00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 02 Dec 2009 23:36:45 -0700 (MST)
Received: from [192.168.0.101]
 (cpe-24-25-218-236.san.res.rr.com [24.25.218.236])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KU2004YOD17QE90@mail-amer.sun.com>; Wed,
 02 Dec 2009 23:36:44 -0700 (MST)
Date: Wed, 02 Dec 2009 22:36:43 -0800
From: Michael Corcoran <Michael.Corcoran@sun.com>
Subject: Re: acpihpd ACPI Hotplug Daemon [PSARC/2009/551 fast-track timeout
 10/19/2009]
In-reply-to: <4B16F06F.7080708@sun.com>
Sender: Michael.Corcoran@sun.com
To: Jerry Gilliam <Jerry.Gilliam@sun.com>
Cc: Michael Corcoran <Michael.Corcoran@sun.com>, PSARC-ext@sun.com,
        Geetanjali Krishna <geetanjali.krishna@intel.com>,
        Jiang Liu <jiang.liu@intel.com>, Sherry.Moore@sun.com,
        Shidokht Yadegari <Shidokht.Yadegari@sun.com>
Message-id: <8621AC8B-81FF-4196-8950-0321915A4CCA@Sun.COM>
MIME-version: 1.0
X-Mailer: Apple Mail (2.936)
Content-type: text/plain; CHARSET=US-ASCII; delsp=yes; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4AD3B465.9090701@sun.com> <4B16F06F.7080708@sun.com>
Status: RO
Content-Length: 5311

Talking with Gerry on IRC, he pointed out that there will no longer be  
a 64bit version of acpihpd since the 32bit version can run on both  
32bit and 64bit os'es and there is no benefit in having a 64bit  
version of the program.

Thus
> /usr/platform/i86pc/lib/amd64/acpihpd	Project Private    ACPI HP  
> daemon
should be removed from the Interface table and stability section.

I apologize for the oversight here while updating the spec.

Thanks,

Mike


On Dec 2, 2009, at 2:55 PM, Jerry Gilliam wrote:

>
> An updated spec for this case, included below, is now ready for
> review as a fast-track.  The spec includes marks where changed.
> I've reset the timer for a week, to 12/09/2009.
>
> -------------------
>
> Introduction
> ===========
> 	Future Intel high-end server platforms support IOH/CPU/memory
> hot plug. To enable ACPI based IOH/CPU/memory hot plug, an ACPI hot  
> plug
> daemon (acpihpd) is needed to handle events generated by the ACPI  
> subsystem
> and maintain state changes.
>
> Release Binding
> ===============
> minor
>
> Dependency
> ===========
> 	The acpihpd daemon has dependency on syseventd daemon to relay hot
> plug events. It also has dependency on cfgadm framework and sbd  
> plugin to
> handle hot plug events. Acpihpd receives hot plug events from  
> syseventd
> and invokes cfgadm library to handle these events.
>
> Technical Detail
> ================
> 	The acpihpd daemon registers for DR request events and handles them
> when they arrive.
> 	The acpihpd daemon would subscribe to EC_DR/ESC_DR_REQ sysevents
> (defined in PSARC/2000/189). When IOH/CPU/memory hot plug events  
> arrive,
> the acpihpd parses the DR request and calls into the cfgadm library to
> add/remove devices from the system. DR requests are handled by cfgadm
> framework.
> 	The events that the acpihpd is interested in are published by ACPI
> virtual nexus driver (acpinex). ACPI BIOS generates ACPI system  
> notifications
> when user initiates a device insertion/removal. These notifications  
> will be
> forwarded to acpinex driver by the acpica driver. When acpinex  
> driver gets
> notifications, it translates the device into Attachment Point and  
> generates
> EC_DR/ESC_DR_REQ events.
> 	When EC_DR/ESC_DR_REQ events are relayed to acpihpd daemon, it  
> invokes
> cfgadm library to handle the events. It also takes the  
> responsibility to
> udpate other components as part of the DR operation, for example,  
> notify power
> management by executing pmconfig command.
> 	The acpihpd is started and stopped using the standard Solaris service
> management facility. The acpihpd is an smf service, and will only be  
> enabled on
> the platforms which supports IOH/CPU/memory hot plug via an i86pc  
> specific	|
> profile.  Unfortunately, the service has to run as root as it relies  
> on the	|
> sysevent library which will reject any request from a non-root  
> user.  The	|
> privileges will be restricted to 'basic,! 
> proc_info,sys_config,sys_mount,	|
> sys_devices'.									|
>
> Interface table and Stability
> =============================
>
> 	Interface			Classification     Comments
> ----------------------------------------------------------------------------
> /usr/platform/i86pc/lib/acpihpd		Project Private    ACPI HP daemon
> /usr/platform/i86pc/lib/amd64/acpihpd	Project Private    ACPI HP  
> daemon
> /lib/svc/method/acpihp			Project Private    acpihp service
> /var/svc/manifest/platform/i86pc/	Project Private    acpihp manifest
> 	acpihpd.xml
>
>
>
> System Administration Commands                            acpihpd(1M)
>
> NAME
>      acpihpd - ACPI hot plug daemon
>
> SYNOPSIS
>      /usr/platform/i86pc/lib/acpihpd
>
> DESCRIPTION
>      The ACPI hot plug daemon is a daemon process that runs on x86  
> platforms.
>      The daemon is started by the service management facility. It  
> communicates
>      with the syseventd and cfgadm sub-systems to handle ACPI events  
> from
>      hotpluggable devices.
>
>      The service FMRI for acpihpd is:
>
>      svc:/platform/i86pc/acpihpd:default
>
> OPTIONS
>      The acpihpd does not support any options.
>
> ERRORS
>      acpihpd uses syslog(3C) to report status and error messages.
>      All of the messages are logged with the LOG_DAEMON facility.
>
>      Error messages are logged with the  LOG_ERR  and  LOG_NOTICE
>      priorities, and informational messages are logged with the
>      LOG_DEBUG priority.   The   default    entries    in    the
>      /etc/syslog.conf  file  log all of the DCS error messages to
>      the /var/adm/messages log.
>
> ATTRIBUTES
>
>      See attributes(5) for descriptions of the  following  attri-
>      butes:
>      ____________________________________________________________
>     |       ATTRIBUTE TYPE        |       ATTRIBUTE VALUE       |
>     |_____________________________|_____________________________|
>     | Availability                | SUNWacpihpd                 |
>     |_____________________________|_____________________________|
>
> SEE ALSO
>
>      svcs(1), inetadm(1M), svcadm(1M), syslog(3C), syslog.conf(4),
>      attributes(5)
>
> NOTES
>
>      The acpihpd service is managed by the service management  facil-
>      ity, smf(5), under the service identifier:
>
>      svc:/platform/i86pc/acpihpd:default					|
>


