From 48c313e33cbbbcc42bd80cab0f59df7ae963aaf9 Mon Sep 17 00:00:00 2001 From: suri-codes Date: Mon, 11 May 2026 21:18:16 -0700 Subject: [PATCH] fix: coloring for sec and ctx figures --- poster/colors.typ | 1 - poster/figures/fig_cap.typ | 7 ++- poster/figures/fig_sec_ctx.typ | 19 ++++--- poster/figures/fig_twiz.typ | 58 +++++++++++++++++++++ poster/figures/fig_unix.typ | 75 +++++++++++++++++++++++++++ poster/sections/4_execution.typ | 90 +++------------------------------ 6 files changed, 155 insertions(+), 95 deletions(-) create mode 100644 poster/figures/fig_twiz.typ create mode 100644 poster/figures/fig_unix.typ diff --git a/poster/colors.typ b/poster/colors.typ index 56276ca..2d0621e 100644 --- a/poster/colors.typ +++ b/poster/colors.typ @@ -1,4 +1,3 @@ -//TODO: need to make these baskin colors #let base_colors = ( bgcolor1: rgb("#003c6c"), bgcolor2: rgb("#dde3f0"), diff --git a/poster/figures/fig_cap.typ b/poster/figures/fig_cap.typ index b0b762b..134c77c 100644 --- a/poster/figures/fig_cap.typ +++ b/poster/figures/fig_cap.typ @@ -2,19 +2,22 @@ #let cap-fill = rgb("#e8f0fe") #let cap-stroke = rgb("#3c5a99") + #let obj-fill = rgb("#e6f4ea") #let obj-stroke = rgb("#2d6a4f") + #let sec-fill = rgb("#fef3e2") #let sec-stroke = rgb("#b45309") + #let sig-fill = rgb("#f3e8ff") #let sig-stroke = rgb("#6b21a8") #align(center)[ - #set text(size: 18pt) #figure(caption: "Structure of a Capability")[ + #set text(size: 18pt) #diagram( node-inset: 18pt, node-corner-radius: 4pt, @@ -67,7 +70,7 @@ name: , align(center)[ #text(weight: "bold")[Security Context] \ - #text[identifies the accessor] + #text[parent context] ], fill: sec-fill, stroke: sec-stroke + 1pt, diff --git a/poster/figures/fig_sec_ctx.typ b/poster/figures/fig_sec_ctx.typ index 37a27c6..071686d 100644 --- a/poster/figures/fig_sec_ctx.typ +++ b/poster/figures/fig_sec_ctx.typ @@ -2,24 +2,27 @@ #let sec-fill = rgb("#fef3e2") #let sec-stroke = rgb("#b45309") + #let cap-fill = rgb("#e8f0fe") #let cap-stroke = rgb("#3c5a99") -#let mask-fill = rgb("#e6f4ea") -#let mask-stroke = rgb("#2d6a4f") -#let obj-fill = rgb("#f3e8ff") -#let obj-stroke = rgb("#6b21a8") -#set text(size: 18pt) +#let mask-fill = rgb("#f3e8ff") +#let mask-stroke = rgb("#6041ff") + +#let obj-fill = rgb("#e6f4ea") +#let obj-stroke = rgb("#2d6a4f") + #align(center)[ #figure(caption: "Structure of a Security Context")[ + #set text(size: 18pt) #diagram( node-inset: 18pt, node-corner-radius: 4pt, edge-stroke: 1.2pt, spacing: (4cm, 2cm), - // ── Central SecCtx record ────────────────────────────── + // ── Central SecCtx ── node( (0, 0), name: , @@ -31,10 +34,10 @@ column-gutter: 12pt, row-gutter: 7pt, text(fill: sec-stroke)[map], - text(font: "DejaVu Sans Mono")[Map〈ObjID, Vec〈Cap〉〉], + text(font: "DejaVu Sans Mono")[Map {ObjID $->$ [Cap]}], text(fill: sec-stroke)[masks], - text(font: "DejaVu Sans Mono")[Map〈ObjID, Mask〉], + text(font: "DejaVu Sans Mono")[Map {ObjID $->$ Mask}], text(fill: sec-stroke)[global_mask], text(font: "DejaVu Sans Mono")[Protections], diff --git a/poster/figures/fig_twiz.typ b/poster/figures/fig_twiz.typ new file mode 100644 index 0000000..4f911ab --- /dev/null +++ b/poster/figures/fig_twiz.typ @@ -0,0 +1,58 @@ +#import "@preview/chronos:0.3.0" +#import "../colors.typ": base_colors, bold_color + + +#align(center)[ + #figure(caption: "Twizzler Read/Write Execution")[ + #chronos.diagram( + // width: 27cm, + { + import chronos: * + + _par("A", display-name: "Process") + _par("B", display-name: "Twizzler") + _par("C", display-name: "Object") + + _grp("One-time fault handling", { + _seq( + "A", + "C", + comment: "read / write", + enable-dst: true, + lifeline-style: (fill: base_colors.bgcolor1), + ) + _seq( + "C", + "B", + comment: "Page Fault", + lifeline-style: (fill: bold_color), + enable-dst: true, + ) + _seq("B", "B", comment: "Inspect User SecCtx") + _seq("B", "B", comment: "Verify Capability") + _seq( + "B", + "C", + comment: "program MMU", + dashed: true, + disable-src: true, + disable-dst: true, + ) + }) + + _gap() + + _grp("Direct access (no kernel involvement)", { + _seq("A", "C", comment: "read", enable-dst: true, lifeline-style: ( + fill: base_colors.bgcolor1, + )) + _seq("C", "A", comment: "Ok", dashed: true, disable-src: true) + _seq("A", "C", comment: "write", enable-dst: true, lifeline-style: ( + fill: base_colors.bgcolor1, + )) + _seq("C", "A", comment: "Ok", dashed: true, disable-src: true) + }) + }, + ) + ] +] diff --git a/poster/figures/fig_unix.typ b/poster/figures/fig_unix.typ new file mode 100644 index 0000000..fdde3c4 --- /dev/null +++ b/poster/figures/fig_unix.typ @@ -0,0 +1,75 @@ +#import "@preview/chronos:0.3.0" +#import "../colors.typ": base_colors, bold_color + + + +#align(center)[ + #figure(caption: "Unix File Read/Write Execution")[ + #chronos.diagram({ + import chronos: * + _par("U", display-name: "Process") + _par("K", display-name: "Kernel") + _par("F", display-name: "File") + + _grp("Open", { + _seq( + "U", + "K", + comment: "open(path, flags)", + enable-dst: true, + lifeline-style: (fill: bold_color), + ) + _seq("K", "K", comment: "check permissions") + _seq("K", "U", comment: "fd", dashed: true, disable-src: true) + }) + + _gap() + + _grp("Read / Write", { + _seq( + "U", + "K", + comment: "read(fd, buf, n)", + enable-dst: true, + lifeline-style: (fill: bold_color), + ) + + _seq( + "K", + "F", + comment: " read page", + lifeline-style: (fill: base_colors.bgcolor1), + enable-dst: true, + disable-dst: true, + ) + + _seq("F", "K", comment: "4096 bytes", dashed: true, disable-src: true) + + _seq("K", "U", comment: "n bytes", dashed: true, disable-src: true) + + _gap() + + _seq( + "U", + "K", + comment: "write(fd, buf, n)", + enable-dst: true, + + lifeline-style: (fill: bold_color), + ) + _seq( + "K", + "F", + comment: "flush", + lifeline-style: (fill: base_colors.bgcolor1), + enable-dst: true, + disable-dst: true, + ) + + _seq("F", "K", comment: "done", dashed: true, disable-src: true) + + _seq("K", "U", comment: "Ok", dashed: true, disable-src: true) + }) + }) + ] +] diff --git a/poster/sections/4_execution.typ b/poster/sections/4_execution.typ index 3e82032..46d412c 100644 --- a/poster/sections/4_execution.typ +++ b/poster/sections/4_execution.typ @@ -2,6 +2,12 @@ #import "../colors.typ": bold_color #let title = "System At Work" + +Let's first recap how a traditional OS handles the data path. +#include "../figures/fig_unix.typ" + +#include "../figures/fig_twiz.typ" + // ok show an example of the system at work, what exactly is done // to map it in, and then run... @@ -22,88 +28,4 @@ granted by the capability with no involvement from the kernel. // but we still uphold security!! -#import "@preview/chronos:0.3.0" - -#let kern_color = rgb("#8b0000") - -#align(center)[ - #figure(caption: "Unix File Read/Write Execution")[ - #chronos.diagram(width: 27cm, { - import chronos: * - - _par("U", display-name: "Process") - _par("K", display-name: "Kernel") - _par("F", display-name: "File") - - _seq("U", "K", comment: "read(fd, buf, n)", enable-dst: true) - _seq( - "K", - "F", - comment: "copy to user", - lifeline-style: (fill: kern_color), - enable-dst: true, - disable-dst: true, - ) - _seq("K", "U", comment: "n bytes", dashed: true, disable-src: true) - - _seq("U", "K", comment: "write(fd, buf, n)", enable-dst: true) - _seq( - "K", - "F", - comment: "copy from user", - lifeline-style: (fill: kern_color), - enable-dst: true, - disable-dst: true, - ) - _seq("K", "U", comment: "Ok", dashed: true, disable-src: true) - }) - ] -] - -#import "@preview/chronos:0.3.0" - -#let bold_color = rgb("#003f8a") - -#align(center)[ - #figure(caption: "Twizzler Open Read Write Execution")[ - #chronos.diagram(width: 27cm, { - import chronos: * - - _par("A", display-name: "Process") - - _par("B", display-name: "Twizzler") - - _par("C", display-name: "Object") - - _grp("One-time fault handling", { - _seq("A", "C", comment: "read / write", enable-dst: true) - _seq( - "C", - "B", - comment: "Page Fault", - lifeline-style: (fill: bold_color), - enable-dst: true, - ) - _seq("B", "B", comment: "Inspect User SecCtx") - _seq("B", "B", comment: "Verify Capability") - _seq( - "B", - "C", - comment: "program MMU", - dashed: true, - disable-src: true, - disable-dst: true, - ) - }) - - _gap() - _grp("Direct access (no kernel involvement)", { - _seq("A", "C", comment: "read", enable-dst: true) - _seq("C", "A", comment: "Ok", dashed: true, disable-src: true) - _seq("A", "C", comment: "write", enable-dst: true) - _seq("C", "A", comment: "Ok", dashed: true, disable-src: true) - }) - }) - ] -] -- 2.51.2