fs: raw storage needs PR_CAP_RAWIO

Opening a block or MTD node, mount() and umount2() need it, and so does
a BCH character node, which checks in its own open(): a node made by
bchdev_register() is a character driver, so the inode type cannot tell
it apart. The checks sit in file_vopen(), nx_mount() and nx_umount2(),
which every path reaches; kernel threads hold every capability.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
This commit is contained in:
Royyan Zahir 2026-10-02 06:56:44 +04:00 • committed by Alan C. Assis
parent 90ab43a7f5
commit e55c073799
4 changed files with 25 additions and 0 deletions

View file

@ -39,6 +39,7 @@
#include <assert.h>
#include <nuttx/debug.h>
#include <nuttx/sched.h>
#include <nuttx/fs/fs.h>
#include <nuttx/fs/ioctl.h>
#include <nuttx/drivers/drivers.h>
@ -122,6 +123,11 @@ static int bch_open(FAR struct file *filep)
FAR struct bchlib_s *bch;
int ret = OK;
if (!nxsched_capable(PR_CAP_RAWIO))
{
return -EPERM;
}
DEBUGASSERT(inode->i_private);
bch = inode->i_private;

View file

@ -34,6 +34,7 @@
#include <nuttx/debug.h>
#include <nuttx/fs/fs.h>
#include <nuttx/sched.h>
#include "driver/driver.h"
#include "inode/inode.h"
@ -304,6 +305,11 @@ int nx_mount(FAR const char *source, FAR const char *target,
FAR void *fshandle = NULL;
int ret;
if (!nxsched_capable(PR_CAP_RAWIO))
{
return -EPERM;
}
/* Verify required pointer arguments */
DEBUGASSERT(target && filesystemtype);

View file

@ -32,6 +32,7 @@
#include <assert.h>
#include <nuttx/fs/fs.h>
#include <nuttx/sched.h>
#include "inode/inode.h"
#include "vfs/vfs.h"
@ -62,6 +63,11 @@ int nx_umount2(FAR const char *target, unsigned int flags)
struct inode_search_s desc;
int ret;
if (!nxsched_capable(PR_CAP_RAWIO))
{
return -EPERM;
}
/* Verify required pointer arguments */
if (!target)

View file

@ -148,6 +148,13 @@ static int file_vopen(FAR struct file *filep, FAR const char *path,
}
#endif
if ((INODE_IS_BLOCK(inode) || INODE_IS_MTD(inode)) &&
!nxsched_capable(PR_CAP_RAWIO))
{
ret = -EPERM;
goto errout_with_inode;
}
#if defined(CONFIG_BCH) && \
!defined(CONFIG_DISABLE_MOUNTPOINT) && \
!defined(CONFIG_DISABLE_PSEUDOFS_OPERATIONS)