royzah opened a new pull request, #20417:
URL: https://github.com/apache/nuttx/pull/20417

   Depends on #20412; its commits are included until it merges.
   
   ## Why
   
   In a kernel build every process could open raw storage, spawn programs, 
mount file systems and reset the board. Isolation keeps a process out of kernel 
memory, but not away from those.
   
   ## How
   
   | Commit | Does |
   | --- | --- |
   | nxstyle | `nx_start.c` passes the check; whitespace only |
   | `sched` | a task group holds `PR_CAP_RAWIO`, `PR_CAP_SPAWN`, 
`PR_CAP_ADMIN`; inherited from its creator; `prctl(PR_CAPS_DROP)` only removes, 
`PR_CAPS_GET` reads |
   | `fs` | opening a block, MTD or BCH node needs `RAWIO`; kernel services 
keep `file_open()` |
   | `syscall` | `posix_spawn` and `execve` need `SPAWN`, `mount` and `umount2` 
need `RAWIO`, a board reset or power-off needs `ADMIN` |
   
   The kernel and `init` start with all three, so nothing changes until a 
process drops them. Flat and protected builds are unchanged.
   
   ## Tested
   
   | Where | Result |
   | --- | --- |
   | `qemu-armv8a:knsh` | `ostest` passes; `hello` |
   | `rv-virt:knsh64` | `hello`; `ostest` log identical to master's |
   | i.MX93, PX4 kernel build | a process that dropped all three: raw open, 
spawn, launch and mount refused, `PR_CAPS_GET` reads 0; each flight module runs 
with only what it declares |
   
   `tools/checkpatch.sh` clean.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to