nuttx/drivers/spi/spi_driver.c
Catalin Visinescu 081e4c478a drivers/: Multiple Drivers Are Registered With World Writable - Part 2
Permissions (Part 2)

Description:

In kernel builds, any unprivileged process running on the NuttX
device can open /dev/efuse and attempt to read/write fuse content.
Reading the fuses may provide valuable information to an attacker
controlling the user process. The write operation, in extreme cases
where the fuse blocks are not locked, may brick the device.

DISCLAIMER: I tried to be strict with the settings, better to relax them
later if it's needed.

This is part of https://github.com/apache/nuttx/issues/19410

See https://github.com/apache/nuttx/issues/19410

Compiles ok.

Signed-off-by: Catalin Visinescu <catalin_visinescu@yahoo.com>
2026-07-15 15:27:28 +08:00

398 lines
11 KiB
C

/****************************************************************************
* drivers/spi/spi_driver.c
*
* SPDX-License-Identifier: Apache-2.0
*
* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed with
* this work for additional information regarding copyright ownership. The
* ASF licenses this file to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance with the
* License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
* WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
* License for the specific language governing permissions and limitations
* under the License.
*
****************************************************************************/
/****************************************************************************
* Included Files
****************************************************************************/
#include <nuttx/config.h>
#include <sys/types.h>
#include <stdbool.h>
#include <stdio.h>
#include <string.h>
#include <assert.h>
#include <errno.h>
#include <nuttx/debug.h>
#include <nuttx/kmalloc.h>
#include <nuttx/fs/fs.h>
#include <nuttx/mutex.h>
#include <nuttx/spi/spi_transfer.h>
/****************************************************************************
* Pre-processor Definitions
****************************************************************************/
/* Device naming ************************************************************/
#define DEVNAME_FMT "/dev/spi%d"
#define DEVNAME_FMTLEN (8 + 3 + 1)
/****************************************************************************
* Private Types
****************************************************************************/
/* Driver state structure */
struct spi_driver_s
{
FAR struct spi_dev_s *spi; /* Contained SPI lower half driver */
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
mutex_t lock; /* Mutual exclusion */
int16_t crefs; /* Number of open references */
bool unlinked; /* True, driver has been unlinked */
#endif
};
/****************************************************************************
* Private Function Prototypes
****************************************************************************/
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
static int spidrvr_open(FAR struct file *filep);
static int spidrvr_close(FAR struct file *filep);
#endif
static ssize_t spidrvr_read(FAR struct file *filep, FAR char *buffer,
size_t buflen);
static ssize_t spidrvr_write(FAR struct file *filep, FAR const char *buffer,
size_t buflen);
static int spidrvr_ioctl(FAR struct file *filep, int cmd,
unsigned long arg);
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
static int spidrvr_unlink(FAR struct inode *inode);
#endif
/****************************************************************************
* Private Data
****************************************************************************/
static const struct file_operations g_spidrvr_fops =
{
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
spidrvr_open, /* open */
spidrvr_close, /* close */
#else
NULL, /* open */
NULL, /* close */
#endif
spidrvr_read, /* read */
spidrvr_write, /* write */
NULL, /* seek */
spidrvr_ioctl, /* ioctl */
NULL, /* mmap */
NULL, /* truncate */
NULL, /* poll */
NULL, /* readv */
NULL /* writev */
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
, spidrvr_unlink /* unlink */
#endif
};
/****************************************************************************
* Private Functions
****************************************************************************/
/****************************************************************************
* Name: spidrvr_open
****************************************************************************/
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
static int spidrvr_open(FAR struct file *filep)
{
FAR struct spi_driver_s *priv;
int ret;
/* Sanity check */
DEBUGASSERT(filep->f_inode->i_private != NULL);
/* Get our private data structure */
priv = filep->f_inode->i_private;
/* Get exclusive access to the SPI driver state structure */
ret = nxmutex_lock(&priv->lock);
if (ret < 0)
{
return ret;
}
/* Increment the count of open references on the driver */
priv->crefs++;
DEBUGASSERT(priv->crefs > 0);
nxmutex_unlock(&priv->lock);
return OK;
}
#endif
/****************************************************************************
* Name: spidrvr_close
****************************************************************************/
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
static int spidrvr_close(FAR struct file *filep)
{
FAR struct spi_driver_s *priv;
int ret;
/* Sanity check */
DEBUGASSERT(filep->f_inode->i_private != NULL);
/* Get our private data structure */
priv = filep->f_inode->i_private;
/* Get exclusive access to the SPI driver state structure */
ret = nxmutex_lock(&priv->lock);
if (ret < 0)
{
return ret;
}
/* Decrement the count of open references on the driver */
DEBUGASSERT(priv->crefs > 0);
priv->crefs--;
/* If the count has decremented to zero and the driver has been unlinked,
* then commit Hara-Kiri now.
*/
if (priv->crefs <= 0 && priv->unlinked)
{
nxmutex_destroy(&priv->lock);
kmm_free(priv);
filep->f_inode->i_private = NULL;
return OK;
}
nxmutex_unlock(&priv->lock);
return OK;
}
#endif
/****************************************************************************
* Name: spidrvr_read
****************************************************************************/
static ssize_t spidrvr_read(FAR struct file *filep, FAR char *buffer,
size_t len)
{
return 0; /* Return EOF */
}
/****************************************************************************
* Name: spidrvr_write
****************************************************************************/
static ssize_t spidrvr_write(FAR struct file *filep, FAR const char *buffer,
size_t len)
{
return len; /* Say that everything was written */
}
/****************************************************************************
* Name: spidrvr_ioctl
****************************************************************************/
static int spidrvr_ioctl(FAR struct file *filep, int cmd, unsigned long arg)
{
FAR struct spi_driver_s *priv;
FAR struct spi_sequence_s *seq;
int ret;
/* Sanity check */
DEBUGASSERT(filep->f_inode->i_private != NULL);
spiinfo("cmd=%d arg=%lu\n", cmd, arg);
/* Get our private data structure */
priv = filep->f_inode->i_private;
/* Get exclusive access to the SPI driver state structure */
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
ret = nxmutex_lock(&priv->lock);
if (ret < 0)
{
return ret;
}
#endif
/* Process the IOCTL command */
switch (cmd)
{
/* Command: SPIIOC_TRANSFER
* Description: Perform a sequence of SPI transfers
* Argument: A reference to an instance of struct spi_sequence_s.
* Dependencies: CONFIG_SPI_DRIVER
*/
case SPIIOC_TRANSFER:
{
/* Get the reference to the spi_transfer_s structure */
seq = (FAR struct spi_sequence_s *)((uintptr_t)arg);
DEBUGASSERT(seq != NULL);
/* Perform the transfer */
ret = spi_transfer(priv->spi, seq);
}
break;
default:
ret = -ENOTTY;
break;
}
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
nxmutex_unlock(&priv->lock);
#endif
return ret;
}
/****************************************************************************
* Name: spidrvr_unlink
****************************************************************************/
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
static int spidrvr_unlink(FAR struct inode *inode)
{
FAR struct spi_driver_s *priv;
int ret;
/* Get our private data structure */
DEBUGASSERT(inode->i_private != NULL);
priv = inode->i_private;
/* Get exclusive access to the SPI driver state structure */
ret = nxmutex_lock(&priv->lock);
if (ret < 0)
{
return ret;
}
/* Are there open references to the driver data structure? */
if (priv->crefs <= 0)
{
nxmutex_destroy(&priv->lock);
kmm_free(priv);
inode->i_private = NULL;
return OK;
}
/* No... just mark the driver as unlinked and free the resources when the
* last client closes their reference to the driver.
*/
priv->unlinked = true;
nxmutex_unlock(&priv->lock);
return ret;
}
#endif
/****************************************************************************
* Public Functions
****************************************************************************/
/****************************************************************************
* Name: spi_register
*
* Description:
* Create and register the SPI character driver.
*
* The SPI character driver is a simple character driver that supports SPI
* transfers. The intent of this driver is to support SPI testing. It is
* not suitable for use in any real driver application.
*
* Input Parameters:
* spi - An instance of the lower half SPI driver
* bus - The SPI bus number. This will be used as the SPI device minor
* number. The SPI character device will be registered as /dev/spiN
* where N is the minor number
*
* Returned Value:
* OK if the driver was successfully registered; A negated errno value is
* returned on any failure.
*
****************************************************************************/
int spi_register(FAR struct spi_dev_s *spi, int bus)
{
FAR struct spi_driver_s *priv;
char devname[DEVNAME_FMTLEN];
int ret;
/* Sanity check */
DEBUGASSERT(spi != NULL && (unsigned)bus < 1000);
/* Allocate a SPI character device structure */
priv = kmm_zalloc(sizeof(struct spi_driver_s));
if (priv)
{
/* Initialize the SPI character device structure */
priv->spi = spi;
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
nxmutex_init(&priv->lock);
#endif
/* Create the character device name */
snprintf(devname, sizeof(devname), DEVNAME_FMT, bus);
ret = register_driver(devname, &g_spidrvr_fops, 0600, priv);
if (ret < 0)
{
/* Free the device structure if we failed to create the character
* device.
*/
#ifndef CONFIG_DISABLE_PSEUDOFS_OPERATIONS
nxmutex_destroy(&priv->lock);
#endif
kmm_free(priv);
return ret;
}
/* Return the result of the registration */
return ret;
}
return -ENOMEM;
}