diff --git a/drivers/bch/bchdev_driver.c b/drivers/bch/bchdev_driver.c index 0d4660264c8..5307565423f 100644 --- a/drivers/bch/bchdev_driver.c +++ b/drivers/bch/bchdev_driver.c @@ -39,6 +39,7 @@ #include #include +#include #include #include #include @@ -122,6 +123,11 @@ static int bch_open(FAR struct file *filep) FAR struct bchlib_s *bch; int ret = OK; + if (!nxsched_capable(PR_CAP_RAWIO)) + { + return -EPERM; + } + DEBUGASSERT(inode->i_private); bch = inode->i_private; diff --git a/fs/mount/fs_mount.c b/fs/mount/fs_mount.c index 75eeb3c6874..086b2745012 100644 --- a/fs/mount/fs_mount.c +++ b/fs/mount/fs_mount.c @@ -34,6 +34,7 @@ #include #include +#include #include "driver/driver.h" #include "inode/inode.h" @@ -304,6 +305,11 @@ int nx_mount(FAR const char *source, FAR const char *target, FAR void *fshandle = NULL; int ret; + if (!nxsched_capable(PR_CAP_RAWIO)) + { + return -EPERM; + } + /* Verify required pointer arguments */ DEBUGASSERT(target && filesystemtype); diff --git a/fs/mount/fs_umount2.c b/fs/mount/fs_umount2.c index 6ac21c7f405..bfa3b54ab00 100644 --- a/fs/mount/fs_umount2.c +++ b/fs/mount/fs_umount2.c @@ -32,6 +32,7 @@ #include #include +#include #include "inode/inode.h" #include "vfs/vfs.h" @@ -62,6 +63,11 @@ int nx_umount2(FAR const char *target, unsigned int flags) struct inode_search_s desc; int ret; + if (!nxsched_capable(PR_CAP_RAWIO)) + { + return -EPERM; + } + /* Verify required pointer arguments */ if (!target) diff --git a/fs/vfs/fs_open.c b/fs/vfs/fs_open.c index d4b13b8d4de..9cfae266f7d 100644 --- a/fs/vfs/fs_open.c +++ b/fs/vfs/fs_open.c @@ -148,6 +148,13 @@ static int file_vopen(FAR struct file *filep, FAR const char *path, } #endif + if ((INODE_IS_BLOCK(inode) || INODE_IS_MTD(inode)) && + !nxsched_capable(PR_CAP_RAWIO)) + { + ret = -EPERM; + goto errout_with_inode; + } + #if defined(CONFIG_BCH) && \ !defined(CONFIG_DISABLE_MOUNTPOINT) && \ !defined(CONFIG_DISABLE_PSEUDOFS_OPERATIONS)