sched: process capabilities

A task group holds PR_CAP_RAWIO, PR_CAP_SPAWN and PR_CAP_ADMIN, inherits
them from its creator and can only drop them. Every build: the kernel and
init start with all three, so nothing changes until a task drops one.
CONFIG_SCHED_CAPABILITIES, off with DEFAULT_SMALL, lets a board short of
flash leave the checks out.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
This commit is contained in:
Royyan Zahir 2026-10-02 06:56:34 +04:00 • committed by Alan C. Assis
parent fdf5ea919e
commit e70cd6bf45
6 changed files with 41 additions and 6 deletions

View file

@ -33,6 +33,7 @@
#include <stdbool.h>
#include <stdint.h>
#include <sched.h>
#include <sys/prctl.h>
#include <signal.h>
#include <pthread.h>
#include <time.h>
@ -456,6 +457,7 @@ struct task_group_s
pid_t tg_pid; /* The ID of the task within the group */
pid_t tg_ppid; /* This is the ID of the parent thread */
uint8_t tg_flags; /* See GROUP_FLAG_* definitions */
uint8_t tg_caps; /* See PR_CAP_* definitions */
/* User identity (POSIX real, effective, and saved-set IDs) ***************/
@ -924,6 +926,12 @@ static inline_function bool nxsched_has_gid(FAR struct tcb_s *tcb,
FAR struct tcb_s *nxsched_self(void);
#ifdef CONFIG_SCHED_CAPABILITIES
# define nxsched_capable(c) ((nxsched_self()->group->tg_caps & (c)) == (c))
#else
# define nxsched_capable(c) true
#endif
/****************************************************************************
* Name: nxsched_foreach
*

View file

@ -78,6 +78,13 @@
#define PR_SET_DUMPABLE 5
#define PR_GET_DUMPABLE 6
#define PR_CAPS_DROP 7
#define PR_CAPS_GET 8
#define PR_CAP_RAWIO (1 << 0)
#define PR_CAP_SPAWN (1 << 1)
#define PR_CAP_ADMIN (1 << 2)
#define PR_CAP_ALL (PR_CAP_RAWIO | PR_CAP_SPAWN | PR_CAP_ADMIN)
/****************************************************************************
* Public Type Definitions