From e55c073799774000a286c0aa1e796644f4012eb6 Mon Sep 17 00:00:00 2001 From: Royyan Zahir Date: Fri, 2 Oct 2026 06:56:44 +0400 Subject: [PATCH] fs: raw storage needs PR_CAP_RAWIO Opening a block or MTD node, mount() and umount2() need it, and so does a BCH character node, which checks in its own open(): a node made by bchdev_register() is a character driver, so the inode type cannot tell it apart. The checks sit in file_vopen(), nx_mount() and nx_umount2(), which every path reaches; kernel threads hold every capability. Signed-off-by: Royyan Zahir --- drivers/bch/bchdev_driver.c | 6 ++++++ fs/mount/fs_mount.c | 6 ++++++ fs/mount/fs_umount2.c | 6 ++++++ fs/vfs/fs_open.c | 7 +++++++ 4 files changed, 25 insertions(+) diff --git a/drivers/bch/bchdev_driver.c b/drivers/bch/bchdev_driver.c index 0d4660264c8..5307565423f 100644 --- a/drivers/bch/bchdev_driver.c +++ b/drivers/bch/bchdev_driver.c @@ -39,6 +39,7 @@ #include #include +#include #include #include #include @@ -122,6 +123,11 @@ static int bch_open(FAR struct file *filep) FAR struct bchlib_s *bch; int ret = OK; + if (!nxsched_capable(PR_CAP_RAWIO)) + { + return -EPERM; + } + DEBUGASSERT(inode->i_private); bch = inode->i_private; diff --git a/fs/mount/fs_mount.c b/fs/mount/fs_mount.c index 75eeb3c6874..086b2745012 100644 --- a/fs/mount/fs_mount.c +++ b/fs/mount/fs_mount.c @@ -34,6 +34,7 @@ #include #include +#include #include "driver/driver.h" #include "inode/inode.h" @@ -304,6 +305,11 @@ int nx_mount(FAR const char *source, FAR const char *target, FAR void *fshandle = NULL; int ret; + if (!nxsched_capable(PR_CAP_RAWIO)) + { + return -EPERM; + } + /* Verify required pointer arguments */ DEBUGASSERT(target && filesystemtype); diff --git a/fs/mount/fs_umount2.c b/fs/mount/fs_umount2.c index 6ac21c7f405..bfa3b54ab00 100644 --- a/fs/mount/fs_umount2.c +++ b/fs/mount/fs_umount2.c @@ -32,6 +32,7 @@ #include #include +#include #include "inode/inode.h" #include "vfs/vfs.h" @@ -62,6 +63,11 @@ int nx_umount2(FAR const char *target, unsigned int flags) struct inode_search_s desc; int ret; + if (!nxsched_capable(PR_CAP_RAWIO)) + { + return -EPERM; + } + /* Verify required pointer arguments */ if (!target) diff --git a/fs/vfs/fs_open.c b/fs/vfs/fs_open.c index d4b13b8d4de..9cfae266f7d 100644 --- a/fs/vfs/fs_open.c +++ b/fs/vfs/fs_open.c @@ -148,6 +148,13 @@ static int file_vopen(FAR struct file *filep, FAR const char *path, } #endif + if ((INODE_IS_BLOCK(inode) || INODE_IS_MTD(inode)) && + !nxsched_capable(PR_CAP_RAWIO)) + { + ret = -EPERM; + goto errout_with_inode; + } + #if defined(CONFIG_BCH) && \ !defined(CONFIG_DISABLE_MOUNTPOINT) && \ !defined(CONFIG_DISABLE_PSEUDOFS_OPERATIONS)