mirror of
https://github.com/apache/nuttx.git
synced 2026-10-06 13:55:15 +00:00
sched: add per-group filesystem jail root
Store the jail as an absolute path on the task group, copy it to children, and free it when the last member leaves. Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
This commit is contained in:
parent
1757b28b1f
commit
6c7f604f79
3 changed files with 90 additions and 1 deletions
|
|
@ -558,6 +558,12 @@ struct task_group_s
|
|||
|
||||
struct fdlist tg_fdlist; /* Maps file descriptor to file */
|
||||
|
||||
#ifdef CONFIG_FS_CHROOT
|
||||
/* chroot() jail **********************************************************/
|
||||
|
||||
FAR char *tg_root; /* Absolute jail path, NULL = no jail */
|
||||
#endif
|
||||
|
||||
/* Virtual memory mapping info ********************************************/
|
||||
|
||||
struct mm_map_s tg_mm_map; /* Task group virtual memory mappings */
|
||||
|
|
|
|||
|
|
@ -33,7 +33,6 @@
|
|||
|
||||
#include <nuttx/debug.h>
|
||||
#include <nuttx/irq.h>
|
||||
#include <nuttx/fs/fs.h>
|
||||
#include <nuttx/kmalloc.h>
|
||||
#include <nuttx/semaphore.h>
|
||||
#include <nuttx/sched.h>
|
||||
|
|
@ -42,6 +41,10 @@
|
|||
#include "group/group.h"
|
||||
#include "tls/tls.h"
|
||||
|
||||
#ifdef CONFIG_FS_CHROOT
|
||||
# include "../../fs/fs_heap.h"
|
||||
#endif
|
||||
|
||||
/****************************************************************************
|
||||
* Private Data
|
||||
****************************************************************************/
|
||||
|
|
@ -98,6 +101,57 @@ static inline void group_inherit_identity(FAR struct task_group_s *group)
|
|||
# define group_inherit_identity(group)
|
||||
#endif
|
||||
|
||||
#ifdef CONFIG_FS_CHROOT
|
||||
/****************************************************************************
|
||||
* Name: group_inherit_chroot
|
||||
*
|
||||
* Description:
|
||||
* Inherit the chroot jail from the parent task group. Kernel threads
|
||||
* share g_kthread_group and must not inherit a user jail.
|
||||
* CONFIG_FS_CHROOT is selected in fs/Kconfig.
|
||||
*
|
||||
* Input Parameters:
|
||||
* group - The new task group.
|
||||
* ttype - The type of the new thread (TCB_FLAG_TTYPE_* value).
|
||||
*
|
||||
* Returned Value:
|
||||
* Zero (OK) on success; a negated errno value on failure.
|
||||
*
|
||||
****************************************************************************/
|
||||
|
||||
static int group_inherit_chroot(FAR struct task_group_s *group,
|
||||
uint8_t ttype)
|
||||
{
|
||||
FAR struct tcb_s *rtcb;
|
||||
FAR struct task_group_s *rgroup;
|
||||
|
||||
if (ttype == TCB_FLAG_TTYPE_KERNEL)
|
||||
{
|
||||
return OK;
|
||||
}
|
||||
|
||||
rtcb = this_task();
|
||||
rgroup = rtcb->group;
|
||||
|
||||
DEBUGASSERT(group != NULL && rgroup != NULL);
|
||||
|
||||
if (rgroup->tg_root == NULL)
|
||||
{
|
||||
return OK;
|
||||
}
|
||||
|
||||
group->tg_root = fs_heap_strdup(rgroup->tg_root);
|
||||
if (group->tg_root == NULL)
|
||||
{
|
||||
return -ENOMEM;
|
||||
}
|
||||
|
||||
return OK;
|
||||
}
|
||||
#else
|
||||
# define group_inherit_chroot(group, ttype) (0)
|
||||
#endif
|
||||
|
||||
/****************************************************************************
|
||||
* Public Functions
|
||||
****************************************************************************/
|
||||
|
|
@ -190,6 +244,12 @@ int group_allocate(FAR struct tcb_s *tcb, uint8_t ttype)
|
|||
|
||||
group_inherit_identity(group);
|
||||
|
||||
ret = group_inherit_chroot(group, ttype);
|
||||
if (ret < 0)
|
||||
{
|
||||
goto errout_with_group;
|
||||
}
|
||||
|
||||
/* Initialize file descriptors for the TCB */
|
||||
|
||||
fdlist_init(&group->tg_fdlist);
|
||||
|
|
@ -219,6 +279,14 @@ int group_allocate(FAR struct tcb_s *tcb, uint8_t ttype)
|
|||
return OK;
|
||||
|
||||
errout_with_group:
|
||||
#ifdef CONFIG_FS_CHROOT
|
||||
if (group->tg_root != NULL)
|
||||
{
|
||||
fs_heap_free(group->tg_root);
|
||||
group->tg_root = NULL;
|
||||
}
|
||||
#endif
|
||||
|
||||
kmm_free(group);
|
||||
return ret;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -33,6 +33,7 @@
|
|||
#include <nuttx/debug.h>
|
||||
#include <nuttx/irq.h>
|
||||
#include <nuttx/fs/fs.h>
|
||||
#include <nuttx/kmalloc.h>
|
||||
#include <nuttx/net/net.h>
|
||||
#include <nuttx/sched.h>
|
||||
#include <nuttx/spinlock.h>
|
||||
|
|
@ -48,6 +49,10 @@
|
|||
#include "group/group.h"
|
||||
#include "tls/tls.h"
|
||||
|
||||
#ifdef CONFIG_FS_CHROOT
|
||||
# include "../../fs/fs_heap.h"
|
||||
#endif
|
||||
|
||||
/****************************************************************************
|
||||
* Private Functions
|
||||
****************************************************************************/
|
||||
|
|
@ -104,6 +109,16 @@ static inline void group_release(FAR struct task_group_s *group)
|
|||
|
||||
fdlist_free(&group->tg_fdlist);
|
||||
|
||||
#ifdef CONFIG_FS_CHROOT
|
||||
/* Drop the chroot jail path */
|
||||
|
||||
if (group->tg_root != NULL)
|
||||
{
|
||||
fs_heap_free(group->tg_root);
|
||||
group->tg_root = NULL;
|
||||
}
|
||||
#endif
|
||||
|
||||
/* Release all shared environment variables */
|
||||
|
||||
env_release(group);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue