fs/inode: Add shared permission helpers and pseudoFS open checks
MemBrowse Memory Report / changes-filter (push) Has been cancelled
MemBrowse Memory Report / load-targets (push) Has been cancelled
MemBrowse Memory Report / identical (push) Has been cancelled
MemBrowse Memory Report / analyze (push) Has been cancelled

Add fs_checkmode() and fs_checkopenperm() for reuse across filesystems.
Enforce pseudoFS mode bits in inode_checkperm() and allow world-readable
open of passwd/group entries so getpwnam() works after seteuid().

Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
This commit is contained in:
Abhishek Mishra
2026-06-20 11:49:09 +08:00
committed by Xiang Xiao
parent 92d83aaf5e
commit 111f3fff4f
6 changed files with 121 additions and 108 deletions
+92 -85
View File
File diff suppressed because it is too large Load Diff
+24 -18
View File
@@ -422,6 +422,24 @@ void inode_release(FAR struct inode *inode);
* Name: inode_checkperm
*
* Description:
* Check 'inode' for 'amode' access on pseudo-filesystem inodes.
* NULL 'inode' (root) and mountpoints are exempt.
*
* Input Parameters:
* inode - Inode to check, or NULL for a root-level path
* amode - Access mode bitmask (R_OK / W_OK / X_OK)
*
* Returned Value:
* Zero (OK) on success, or -EACCES if permission is denied.
*
****************************************************************************/
int inode_checkperm(FAR struct inode *inode, int amode);
/****************************************************************************
* Name: inode_checkopenperm
*
* Description:
* Validate open access to 'inode' for 'oflags'. Checks driver operation
* support, then pseudo-filesystem mode bits when enabled. Mountpoints
* are exempt from mode checks.
@@ -435,25 +453,13 @@ void inode_release(FAR struct inode *inode);
*
****************************************************************************/
int inode_checkperm(FAR struct inode *inode, int oflags);
int inode_checkopenperm(FAR struct inode *inode, int oflags);
/****************************************************************************
* Name: inode_checkdirperm
*
* Description:
* Check parent directory 'dir' for 'amode' access on pseudo-filesystem
* inodes. NULL 'dir' (root) and mountpoints are exempt.
*
* Input Parameters:
* dir - Parent directory inode, or NULL for a root-level path
* amode - Access mode bitmask (R_OK / W_OK / X_OK)
*
* Returned Value:
* Zero (OK) on success, or -EACCES if permission is denied.
*
****************************************************************************/
int inode_checkdirperm(FAR struct inode *dir, int amode);
#ifdef CONFIG_FS_PERMISSION
int fs_checkmode(uid_t owner, gid_t group, mode_t mode, int amode);
int fs_open_amode(int oflags);
int fs_checkopenperm(uid_t owner, gid_t group, mode_t mode, int oflags);
#endif
/****************************************************************************
* Name: foreach_inode
+1 -1
View File
@@ -142,7 +142,7 @@ int mkdir(const char *pathname, mode_t mode)
* both W_OK and X_OK to create a directory entry.
*/
ret = inode_checkdirperm(desc.parent, W_OK | X_OK);
ret = inode_checkperm(desc.parent, W_OK | X_OK);
if (ret < 0)
{
errcode = -ret;
+1 -1
View File
@@ -172,7 +172,7 @@ static int file_vopen(FAR struct file *filep, FAR const char *path,
/* Validate operation support and pseudo-filesystem permissions */
ret = inode_checkperm(inode, oflags);
ret = inode_checkopenperm(inode, oflags);
if (ret < 0)
{
goto errout_with_inode;
+2 -2
View File
@@ -86,7 +86,7 @@ static int pseudorename(FAR const char *oldpath, FAR struct inode *oldinode,
/* Verify source parent write permission. */
ret = inode_checkdirperm(oldparent, W_OK);
ret = inode_checkperm(oldparent, W_OK);
if (ret < 0)
{
goto errout;
@@ -177,7 +177,7 @@ static int pseudorename(FAR const char *oldpath, FAR struct inode *oldinode,
inode_find(&pardesc); /* pardesc.parent valid even if node not found */
parnode = pardesc.node;
ret = inode_checkdirperm(pardesc.parent, W_OK);
ret = inode_checkperm(pardesc.parent, W_OK);
/* inode_find() holds a reference on parnode; RELEASE_SEARCH() only
* frees pardesc.buffer.
+1 -1
View File
@@ -123,7 +123,7 @@ int nx_unlink(FAR const char *pathname)
/* Verify parent-directory write permission before unlink. */
ret = inode_checkdirperm(desc.parent, W_OK);
ret = inode_checkperm(desc.parent, W_OK);
if (ret < 0)
{
goto errout_with_inode;