xiaoxiang781216 commented on code in PR #20425:
URL: https://github.com/apache/nuttx/pull/20425#discussion_r4157567948
##########
sched/task/task_prctl.c:
##########
@@ -187,6 +187,15 @@ int prctl(int option, ...)
goto errout;
#endif
+ case PR_CAPS_DROP:
+ this_task()->group->tg_caps &= ~va_arg(ap, int);
+ va_end(ap);
+ return OK;
Review Comment:
change to break and remove line 192
##########
sched/task/task_prctl.c:
##########
Review Comment:
remove line 205-209 and 212
##########
drivers/bch/bchdev_register.c:
##########
@@ -69,7 +69,7 @@ int bchdev_register(FAR const char *blkdev, FAR const char
*chardev,
/* Then setup the character device */
- ret = register_driver(chardev, &g_bch_fops, 0600, handle);
+ ret = register_rawdriver(chardev, &g_bch_fops, 0600, handle);
Review Comment:
why not block all Block, MTD and BCH without FSNODEFLAG_RAWIO
##########
fs/mount/fs_umount2.c:
##########
@@ -239,6 +240,12 @@ int umount2(FAR const char *target, unsigned int flags)
{
int ret;
+ if (!nxsched_capable(PR_CAP_RAWIO))
Review Comment:
move into nx_umount2 too
##########
binfmt/binfmt_exec.c:
##########
@@ -270,6 +271,12 @@ int exec(FAR const char *filename, FAR char * const *argv,
{
int ret;
+ if (!nxsched_capable(PR_CAP_SPAWN))
Review Comment:
why not move into exec_internal
##########
sched/task/task_spawn.c:
##########
@@ -339,6 +339,11 @@ int task_spawn(FAR const char *name, main_t entry,
pid_t pid = INVALID_PROCESS_ID;
int ret;
+ if (!nxsched_capable(PR_CAP_SPAWN))
Review Comment:
move into the function which real launch the program and remove the repeat
check in the wrapper function
##########
fs/vfs/fs_open.c:
##########
@@ -72,7 +72,8 @@
****************************************************************************/
static int file_vopen(FAR struct file *filep, FAR const char *path,
- int oflags, mode_t umask, va_list ap)
+ int oflags, mode_t umask, bool fdopen,
Review Comment:
why need pass fdopen? file_open can only be called inside kernel space, and
all kernel thread should get all CAP by default.
##########
sched/task/task_create.c:
##########
@@ -208,6 +208,12 @@ int task_create_with_stack(FAR const char *name, int
priority,
{
int ret;
+ if (!nxsched_capable(PR_CAP_SPAWN))
Review Comment:
move into nxtask_create, please move all check into the deepest function, to
avoid the check get escaped.
##########
fs/mount/fs_mount.c:
##########
@@ -592,6 +593,12 @@ int mount(FAR const char *source, FAR const char *target,
{
int ret;
+ if (!nxsched_capable(PR_CAP_RAWIO))
Review Comment:
move into nx_mount
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]