* [PATCH v3 0/3] sysfs: Refine is_visible API
@ 2015-03-12 13:58 Vivien Didelot
2015-03-12 13:58 ` [PATCH v3 1/3] sysfs: Use only return value from is_visible for the file mode Vivien Didelot
` (2 more replies)
0 siblings, 3 replies; 5+ messages in thread
From: Vivien Didelot @ 2015-03-12 13:58 UTC (permalink / raw)
To: Greg Kroah-Hartman; +Cc: Vivien Didelot, linux-kernel, Guenter Roeck, kernel
Up to now, is_visible can only be used to either remove visibility
of a file entirely or to add permissions, but not to reduce permissions.
This makes it impossible, for example, to use DEVICE_ATTR_RW to define
file attributes and reduce permissions to read-only.
This behavior is undesirable and unnecessarily complicates code which
needs to reduce permissions; instead of just returning the desired
permissions, it has to ensure that the permissions in the attribute
variable declaration only reflect the minimal permissions ever needed.
Change semantics of is_visible to only use the permissions returned
from it instead of oring the returned value with the hard-coded
permissions.
The code now dumps a warning to the console if an is_visible function
returns unexpected permissions.
Also document struct attribute_group.
Tested with v3.19-rc5.
v2: This patchset, originally from Guenter, includes the fixup for the
patch 2/3 discussed in the thread https://lkml.org/lkml/2015/1/20/877,
that is limiting the scope of attributes to SYSFS_PREALLOC | 0664, since
we want to avoid executable and world-writable sysfs files as well.
Rebased onto v4.0-rc3.
v3: Add missing signed-off-by.
Guenter Roeck (2):
sysfs: Use only return value from is_visible for the file mode
sysfs: Document struct attribute_group
Vivien Didelot (1):
sysfs: Only accept read/write permissions for file attributes
fs/sysfs/group.c | 11 ++++++++---
include/linux/sysfs.h | 15 +++++++++++++++
2 files changed, 23 insertions(+), 3 deletions(-)
--
2.3.2
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v3 1/3] sysfs: Use only return value from is_visible for the file mode
2015-03-12 13:58 [PATCH v3 0/3] sysfs: Refine is_visible API Vivien Didelot
@ 2015-03-12 13:58 ` Vivien Didelot
2015-03-12 13:58 ` [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes Vivien Didelot
2015-03-12 13:58 ` [PATCH v3 3/3] sysfs: Document struct attribute_group Vivien Didelot
2 siblings, 0 replies; 5+ messages in thread
From: Vivien Didelot @ 2015-03-12 13:58 UTC (permalink / raw)
To: Greg Kroah-Hartman; +Cc: Guenter Roeck, linux-kernel, kernel, Vivien Didelot
From: Guenter Roeck <linux@roeck-us.net>
Up to now, is_visible can only be used to either remove visibility
of a file entirely or to add permissions, but not to reduce permissions.
This makes it impossible, for example, to use DEVICE_ATTR_RW to define
file attributes and reduce permissions to read-only.
This behavior is undesirable and unnecessarily complicates code which
needs to reduce permissions; instead of just returning the desired
permissions, it has to ensure that the permissions in the attribute
variable declaration only reflect the minimal permissions ever needed.
Change semantics of is_visible to only use the permissions returned
from it instead of oring the returned value with the hard-coded
permissions.
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Vivien Didelot <vivien.didelot@savoirfairelinux.com>
---
fs/sysfs/group.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/fs/sysfs/group.c b/fs/sysfs/group.c
index 2554d88..3fdccd9 100644
--- a/fs/sysfs/group.c
+++ b/fs/sysfs/group.c
@@ -41,7 +41,7 @@ static int create_files(struct kernfs_node *parent, struct kobject *kobj,
if (grp->attrs) {
for (i = 0, attr = grp->attrs; *attr && !error; i++, attr++) {
- umode_t mode = 0;
+ umode_t mode = (*attr)->mode;
/*
* In update mode, we're changing the permissions or
@@ -56,8 +56,7 @@ static int create_files(struct kernfs_node *parent, struct kobject *kobj,
continue;
}
error = sysfs_add_file_mode_ns(parent, *attr, false,
- (*attr)->mode | mode,
- NULL);
+ mode, NULL);
if (unlikely(error))
break;
}
--
2.3.2
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes
2015-03-12 13:58 [PATCH v3 0/3] sysfs: Refine is_visible API Vivien Didelot
2015-03-12 13:58 ` [PATCH v3 1/3] sysfs: Use only return value from is_visible for the file mode Vivien Didelot
@ 2015-03-12 13:58 ` Vivien Didelot
2015-03-12 16:37 ` Guenter Roeck
2015-03-12 13:58 ` [PATCH v3 3/3] sysfs: Document struct attribute_group Vivien Didelot
2 siblings, 1 reply; 5+ messages in thread
From: Vivien Didelot @ 2015-03-12 13:58 UTC (permalink / raw)
To: Greg Kroah-Hartman; +Cc: Vivien Didelot, linux-kernel, Guenter Roeck, kernel
For sysfs file attributes, only read and write permissions make sense.
Mask provided attribute permissions accordingly and send a warning
to the console if invalid permission bits are set.
This patch is originally from Guenter [1] and includes the fixup
explained in the thread, that is printing permissions in octal format
and limiting the scope of attributes to SYSFS_PREALLOC | 0664.
[1] https://lkml.org/lkml/2015/1/19/599
Cc: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Vivien Didelot <vivien.didelot@savoirfairelinux.com>
---
fs/sysfs/group.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/fs/sysfs/group.c b/fs/sysfs/group.c
index 3fdccd9..b400c04 100644
--- a/fs/sysfs/group.c
+++ b/fs/sysfs/group.c
@@ -55,6 +55,12 @@ static int create_files(struct kernfs_node *parent, struct kobject *kobj,
if (!mode)
continue;
}
+
+ WARN(mode & ~(SYSFS_PREALLOC | 0664),
+ "Attribute %s: Invalid permissions 0%o\n",
+ (*attr)->name, mode);
+
+ mode &= SYSFS_PREALLOC | 0664;
error = sysfs_add_file_mode_ns(parent, *attr, false,
mode, NULL);
if (unlikely(error))
--
2.3.2
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v3 3/3] sysfs: Document struct attribute_group
2015-03-12 13:58 [PATCH v3 0/3] sysfs: Refine is_visible API Vivien Didelot
2015-03-12 13:58 ` [PATCH v3 1/3] sysfs: Use only return value from is_visible for the file mode Vivien Didelot
2015-03-12 13:58 ` [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes Vivien Didelot
@ 2015-03-12 13:58 ` Vivien Didelot
2 siblings, 0 replies; 5+ messages in thread
From: Vivien Didelot @ 2015-03-12 13:58 UTC (permalink / raw)
To: Greg Kroah-Hartman; +Cc: Guenter Roeck, linux-kernel, kernel, Vivien Didelot
From: Guenter Roeck <linux@roeck-us.net>
Document variables defined in struct attribute_group to ensure
correct usage.
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Vivien Didelot <vivien.didelot@savoirfairelinux.com>
---
include/linux/sysfs.h | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/include/linux/sysfs.h b/include/linux/sysfs.h
index ddad161..99382c0 100644
--- a/include/linux/sysfs.h
+++ b/include/linux/sysfs.h
@@ -57,6 +57,21 @@ do { \
#define sysfs_attr_init(attr) do {} while (0)
#endif
+/**
+ * struct attribute_group - data structure used to declare an attribute group.
+ * @name: Optional: Attribute group name
+ * If specified, the attribute group will be created in
+ * a new subdirectory with this name.
+ * @is_visible: Optional: Function to return permissions associated with an
+ * attribute of the group. Will be called repeatedly for each
+ * attribute in the group. Only read/write permissions as well as
+ * SYSFS_PREALLOC are accepted. Must return 0 if an attribute is
+ * not visible. The returned value will replace static permissions
+ * defined in struct attribute or struct bin_attribute.
+ * @attrs: Pointer to NULL terminated list of attributes.
+ * @bin_attrs: Pointer to NULL terminated list of binary attributes.
+ * Either attrs or bin_attrs or both must be provided.
+ */
struct attribute_group {
const char *name;
umode_t (*is_visible)(struct kobject *,
--
2.3.2
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes
2015-03-12 13:58 ` [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes Vivien Didelot
@ 2015-03-12 16:37 ` Guenter Roeck
0 siblings, 0 replies; 5+ messages in thread
From: Guenter Roeck @ 2015-03-12 16:37 UTC (permalink / raw)
To: Vivien Didelot; +Cc: Greg Kroah-Hartman, linux-kernel, kernel
On Thu, Mar 12, 2015 at 09:58:27AM -0400, Vivien Didelot wrote:
> For sysfs file attributes, only read and write permissions make sense.
> Mask provided attribute permissions accordingly and send a warning
> to the console if invalid permission bits are set.
>
> This patch is originally from Guenter [1] and includes the fixup
> explained in the thread, that is printing permissions in octal format
> and limiting the scope of attributes to SYSFS_PREALLOC | 0664.
>
> [1] https://lkml.org/lkml/2015/1/19/599
>
> Cc: Guenter Roeck <linux@roeck-us.net>
> Signed-off-by: Vivien Didelot <vivien.didelot@savoirfairelinux.com>
Reviewed-by: Guenter Roeck <linux@roeck-us.net>
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2015-03-12 16:37 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2015-03-12 13:58 [PATCH v3 0/3] sysfs: Refine is_visible API Vivien Didelot
2015-03-12 13:58 ` [PATCH v3 1/3] sysfs: Use only return value from is_visible for the file mode Vivien Didelot
2015-03-12 13:58 ` [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes Vivien Didelot
2015-03-12 16:37 ` Guenter Roeck
2015-03-12 13:58 ` [PATCH v3 3/3] sysfs: Document struct attribute_group Vivien Didelot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®