mirror of
https://github.com/apache/nuttx.git
synced 2026-10-10 07:40:27 +00:00
Documentation: describe process capabilities
What each capability guards, the prctl() interface, inheritance through the task group, and where the checks sit. Signed-off-by: Royyan Zahir <royzah@gmail.com>
This commit is contained in:
parent
36cb05ca2f
commit
4c76b78e93
2 changed files with 28 additions and 0 deletions
27
Documentation/os/scheduling/capabilities.rst
Normal file
27
Documentation/os/scheduling/capabilities.rst
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
.. _capabilities:
|
||||
|
||||
====================
|
||||
Process capabilities
|
||||
====================
|
||||
|
||||
A process holds three capabilities. Without one, the calls it guards fail
|
||||
with ``EPERM``. Every build, the kernel and init start with all three.
|
||||
``CONFIG_SCHED_CAPABILITIES``, off with ``DEFAULT_SMALL``, builds the checks.
|
||||
|
||||
================= ==================================================
|
||||
``PR_CAP_RAWIO`` ``open()`` of block, MTD and BCH nodes,
|
||||
``mount()``, ``umount2()``
|
||||
``PR_CAP_SPAWN`` ``posix_spawn()``, ``task_spawn()``,
|
||||
``task_create()``, ``exec()``, ``execve()``
|
||||
``PR_CAP_ADMIN`` ``boardctl()`` reset and poweroff
|
||||
================= ==================================================
|
||||
|
||||
.. code-block:: c
|
||||
|
||||
prctl(PR_CAPS_DROP, PR_CAP_RAWIO | PR_CAP_SPAWN);
|
||||
int caps = prctl(PR_CAPS_GET);
|
||||
|
||||
A drop is permanent. The set lives in the task group and a new group copies
|
||||
its creator's. The checks sit in the internal functions, so kernel code
|
||||
running for a process is held to that process's set. Kernel threads hold
|
||||
all three.
|
||||
|
|
@ -237,3 +237,4 @@ In this section
|
|||
wqueue.rst
|
||||
tls.rst
|
||||
user_identity.rst
|
||||
capabilities.rst
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue