royzah opened a new pull request, #20417: URL: https://github.com/apache/nuttx/pull/20417
Depends on #20412; its commits are included until it merges. ## Why In a kernel build every process could open raw storage, spawn programs, mount file systems and reset the board. Isolation keeps a process out of kernel memory, but not away from those. ## How | Commit | Does | | --- | --- | | nxstyle | `nx_start.c` passes the check; whitespace only | | `sched` | a task group holds `PR_CAP_RAWIO`, `PR_CAP_SPAWN`, `PR_CAP_ADMIN`; inherited from its creator; `prctl(PR_CAPS_DROP)` only removes, `PR_CAPS_GET` reads | | `fs` | opening a block, MTD or BCH node needs `RAWIO`; kernel services keep `file_open()` | | `syscall` | `posix_spawn` and `execve` need `SPAWN`, `mount` and `umount2` need `RAWIO`, a board reset or power-off needs `ADMIN` | The kernel and `init` start with all three, so nothing changes until a process drops them. Flat and protected builds are unchanged. ## Tested | Where | Result | | --- | --- | | `qemu-armv8a:knsh` | `ostest` passes; `hello` | | `rv-virt:knsh64` | `hello`; `ostest` log identical to master's | | i.MX93, PX4 kernel build | a process that dropped all three: raw open, spawn, launch and mount refused, `PR_CAPS_GET` reads 0; each flight module runs with only what it declares | `tools/checkpatch.sh` clean. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
