mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v3 0/3] sysfs: Refine is_visible API
@ 2015-03-12 13:58 Vivien Didelot
  2015-03-12 13:58 ` [PATCH v3 1/3] sysfs: Use only return value from is_visible for the file mode Vivien Didelot
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Vivien Didelot @ 2015-03-12 13:58 UTC (permalink / raw)
  To: Greg Kroah-Hartman; +Cc: Vivien Didelot, linux-kernel, Guenter Roeck, kernel

Up to now, is_visible can only be used to either remove visibility
of a file entirely or to add permissions, but not to reduce permissions.
This makes it impossible, for example, to use DEVICE_ATTR_RW to define
file attributes and reduce permissions to read-only.

This behavior is undesirable and unnecessarily complicates code which
needs to reduce permissions; instead of just returning the desired
permissions, it has to ensure that the permissions in the attribute
variable declaration only reflect the minimal permissions ever needed.

Change semantics of is_visible to only use the permissions returned
from it instead of oring the returned value with the hard-coded
permissions.

The code now dumps a warning to the console if an is_visible function
returns unexpected permissions.

Also document struct attribute_group.

Tested with v3.19-rc5.

v2: This patchset, originally from Guenter, includes the fixup for the
patch 2/3 discussed in the thread https://lkml.org/lkml/2015/1/20/877,
that is limiting the scope of attributes to SYSFS_PREALLOC | 0664, since
we want to avoid executable and world-writable sysfs files as well.

Rebased onto v4.0-rc3.

v3: Add missing signed-off-by.

Guenter Roeck (2):
  sysfs: Use only return value from is_visible for the file mode
  sysfs: Document struct attribute_group

Vivien Didelot (1):
  sysfs: Only accept read/write permissions for file attributes

 fs/sysfs/group.c      | 11 ++++++++---
 include/linux/sysfs.h | 15 +++++++++++++++
 2 files changed, 23 insertions(+), 3 deletions(-)

-- 
2.3.2


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v3 1/3] sysfs: Use only return value from is_visible for the file mode
  2015-03-12 13:58 [PATCH v3 0/3] sysfs: Refine is_visible API Vivien Didelot
@ 2015-03-12 13:58 ` Vivien Didelot
  2015-03-12 13:58 ` [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes Vivien Didelot
  2015-03-12 13:58 ` [PATCH v3 3/3] sysfs: Document struct attribute_group Vivien Didelot
  2 siblings, 0 replies; 5+ messages in thread
From: Vivien Didelot @ 2015-03-12 13:58 UTC (permalink / raw)
  To: Greg Kroah-Hartman; +Cc: Guenter Roeck, linux-kernel, kernel, Vivien Didelot

From: Guenter Roeck <linux@roeck-us.net>

Up to now, is_visible can only be used to either remove visibility
of a file entirely or to add permissions, but not to reduce permissions.
This makes it impossible, for example, to use DEVICE_ATTR_RW to define
file attributes and reduce permissions to read-only.

This behavior is undesirable and unnecessarily complicates code which
needs to reduce permissions; instead of just returning the desired
permissions, it has to ensure that the permissions in the attribute
variable declaration only reflect the minimal permissions ever needed.

Change semantics of is_visible to only use the permissions returned
from it instead of oring the returned value with the hard-coded
permissions.

Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Vivien Didelot <vivien.didelot@savoirfairelinux.com>
---
 fs/sysfs/group.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/fs/sysfs/group.c b/fs/sysfs/group.c
index 2554d88..3fdccd9 100644
--- a/fs/sysfs/group.c
+++ b/fs/sysfs/group.c
@@ -41,7 +41,7 @@ static int create_files(struct kernfs_node *parent, struct kobject *kobj,
 
 	if (grp->attrs) {
 		for (i = 0, attr = grp->attrs; *attr && !error; i++, attr++) {
-			umode_t mode = 0;
+			umode_t mode = (*attr)->mode;
 
 			/*
 			 * In update mode, we're changing the permissions or
@@ -56,8 +56,7 @@ static int create_files(struct kernfs_node *parent, struct kobject *kobj,
 					continue;
 			}
 			error = sysfs_add_file_mode_ns(parent, *attr, false,
-						       (*attr)->mode | mode,
-						       NULL);
+						       mode, NULL);
 			if (unlikely(error))
 				break;
 		}
-- 
2.3.2


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes
  2015-03-12 13:58 [PATCH v3 0/3] sysfs: Refine is_visible API Vivien Didelot
  2015-03-12 13:58 ` [PATCH v3 1/3] sysfs: Use only return value from is_visible for the file mode Vivien Didelot
@ 2015-03-12 13:58 ` Vivien Didelot
  2015-03-12 16:37   ` Guenter Roeck
  2015-03-12 13:58 ` [PATCH v3 3/3] sysfs: Document struct attribute_group Vivien Didelot
  2 siblings, 1 reply; 5+ messages in thread
From: Vivien Didelot @ 2015-03-12 13:58 UTC (permalink / raw)
  To: Greg Kroah-Hartman; +Cc: Vivien Didelot, linux-kernel, Guenter Roeck, kernel

For sysfs file attributes, only read and write permissions make sense.
Mask provided attribute permissions accordingly and send a warning
to the console if invalid permission bits are set.

This patch is originally from Guenter [1] and includes the fixup
explained in the thread, that is printing permissions in octal format
and limiting the scope of attributes to SYSFS_PREALLOC | 0664.

[1] https://lkml.org/lkml/2015/1/19/599

Cc: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Vivien Didelot <vivien.didelot@savoirfairelinux.com>
---
 fs/sysfs/group.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/fs/sysfs/group.c b/fs/sysfs/group.c
index 3fdccd9..b400c04 100644
--- a/fs/sysfs/group.c
+++ b/fs/sysfs/group.c
@@ -55,6 +55,12 @@ static int create_files(struct kernfs_node *parent, struct kobject *kobj,
 				if (!mode)
 					continue;
 			}
+
+			WARN(mode & ~(SYSFS_PREALLOC | 0664),
+			     "Attribute %s: Invalid permissions 0%o\n",
+			     (*attr)->name, mode);
+
+			mode &= SYSFS_PREALLOC | 0664;
 			error = sysfs_add_file_mode_ns(parent, *attr, false,
 						       mode, NULL);
 			if (unlikely(error))
-- 
2.3.2


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v3 3/3] sysfs: Document struct attribute_group
  2015-03-12 13:58 [PATCH v3 0/3] sysfs: Refine is_visible API Vivien Didelot
  2015-03-12 13:58 ` [PATCH v3 1/3] sysfs: Use only return value from is_visible for the file mode Vivien Didelot
  2015-03-12 13:58 ` [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes Vivien Didelot
@ 2015-03-12 13:58 ` Vivien Didelot
  2 siblings, 0 replies; 5+ messages in thread
From: Vivien Didelot @ 2015-03-12 13:58 UTC (permalink / raw)
  To: Greg Kroah-Hartman; +Cc: Guenter Roeck, linux-kernel, kernel, Vivien Didelot

From: Guenter Roeck <linux@roeck-us.net>

Document variables defined in struct attribute_group to ensure
correct usage.

Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Vivien Didelot <vivien.didelot@savoirfairelinux.com>
---
 include/linux/sysfs.h | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/include/linux/sysfs.h b/include/linux/sysfs.h
index ddad161..99382c0 100644
--- a/include/linux/sysfs.h
+++ b/include/linux/sysfs.h
@@ -57,6 +57,21 @@ do {							\
 #define sysfs_attr_init(attr) do {} while (0)
 #endif
 
+/**
+ * struct attribute_group - data structure used to declare an attribute group.
+ * @name:	Optional: Attribute group name
+ *		If specified, the attribute group will be created in
+ *		a new subdirectory with this name.
+ * @is_visible:	Optional: Function to return permissions associated with an
+ *		attribute of the group. Will be called repeatedly for each
+ *		attribute in the group. Only read/write permissions as well as
+ *		SYSFS_PREALLOC are accepted. Must return 0 if an attribute is
+ *		not visible. The returned value will replace static permissions
+ *		defined in struct attribute or struct bin_attribute.
+ * @attrs:	Pointer to NULL terminated list of attributes.
+ * @bin_attrs:	Pointer to NULL terminated list of binary attributes.
+ *		Either attrs or bin_attrs or both must be provided.
+ */
 struct attribute_group {
 	const char		*name;
 	umode_t			(*is_visible)(struct kobject *,
-- 
2.3.2


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes
  2015-03-12 13:58 ` [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes Vivien Didelot
@ 2015-03-12 16:37   ` Guenter Roeck
  0 siblings, 0 replies; 5+ messages in thread
From: Guenter Roeck @ 2015-03-12 16:37 UTC (permalink / raw)
  To: Vivien Didelot; +Cc: Greg Kroah-Hartman, linux-kernel, kernel

On Thu, Mar 12, 2015 at 09:58:27AM -0400, Vivien Didelot wrote:
> For sysfs file attributes, only read and write permissions make sense.
> Mask provided attribute permissions accordingly and send a warning
> to the console if invalid permission bits are set.
> 
> This patch is originally from Guenter [1] and includes the fixup
> explained in the thread, that is printing permissions in octal format
> and limiting the scope of attributes to SYSFS_PREALLOC | 0664.
> 
> [1] https://lkml.org/lkml/2015/1/19/599
> 
> Cc: Guenter Roeck <linux@roeck-us.net>
> Signed-off-by: Vivien Didelot <vivien.didelot@savoirfairelinux.com>

Reviewed-by: Guenter Roeck <linux@roeck-us.net>

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2015-03-12 16:37 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2015-03-12 13:58 [PATCH v3 0/3] sysfs: Refine is_visible API Vivien Didelot
2015-03-12 13:58 ` [PATCH v3 1/3] sysfs: Use only return value from is_visible for the file mode Vivien Didelot
2015-03-12 13:58 ` [PATCH v3 2/3] sysfs: Only accept read/write permissions for file attributes Vivien Didelot
2015-03-12 16:37   ` Guenter Roeck
2015-03-12 13:58 ` [PATCH v3 3/3] sysfs: Document struct attribute_group Vivien Didelot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®