mirror of
https://github.com/apache/nuttx.git
synced 2026-10-10 07:40:27 +00:00
sched: process capabilities
A task group holds PR_CAP_RAWIO, PR_CAP_SPAWN and PR_CAP_ADMIN, inherits them from its creator and can only drop them. Every build: the kernel and init start with all three, so nothing changes until a task drops one. CONFIG_SCHED_CAPABILITIES, off with DEFAULT_SMALL, lets a board short of flash leave the checks out. Signed-off-by: Royyan Zahir <royzah@gmail.com>
This commit is contained in:
parent
fdf5ea919e
commit
e70cd6bf45
6 changed files with 41 additions and 6 deletions
|
|
@ -33,6 +33,7 @@
|
|||
#include <stdbool.h>
|
||||
#include <stdint.h>
|
||||
#include <sched.h>
|
||||
#include <sys/prctl.h>
|
||||
#include <signal.h>
|
||||
#include <pthread.h>
|
||||
#include <time.h>
|
||||
|
|
@ -456,6 +457,7 @@ struct task_group_s
|
|||
pid_t tg_pid; /* The ID of the task within the group */
|
||||
pid_t tg_ppid; /* This is the ID of the parent thread */
|
||||
uint8_t tg_flags; /* See GROUP_FLAG_* definitions */
|
||||
uint8_t tg_caps; /* See PR_CAP_* definitions */
|
||||
|
||||
/* User identity (POSIX real, effective, and saved-set IDs) ***************/
|
||||
|
||||
|
|
@ -924,6 +926,12 @@ static inline_function bool nxsched_has_gid(FAR struct tcb_s *tcb,
|
|||
|
||||
FAR struct tcb_s *nxsched_self(void);
|
||||
|
||||
#ifdef CONFIG_SCHED_CAPABILITIES
|
||||
# define nxsched_capable(c) ((nxsched_self()->group->tg_caps & (c)) == (c))
|
||||
#else
|
||||
# define nxsched_capable(c) true
|
||||
#endif
|
||||
|
||||
/****************************************************************************
|
||||
* Name: nxsched_foreach
|
||||
*
|
||||
|
|
|
|||
|
|
@ -78,6 +78,13 @@
|
|||
|
||||
#define PR_SET_DUMPABLE 5
|
||||
#define PR_GET_DUMPABLE 6
|
||||
#define PR_CAPS_DROP 7
|
||||
#define PR_CAPS_GET 8
|
||||
|
||||
#define PR_CAP_RAWIO (1 << 0)
|
||||
#define PR_CAP_SPAWN (1 << 1)
|
||||
#define PR_CAP_ADMIN (1 << 2)
|
||||
#define PR_CAP_ALL (PR_CAP_RAWIO | PR_CAP_SPAWN | PR_CAP_ADMIN)
|
||||
|
||||
/****************************************************************************
|
||||
* Public Type Definitions
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue