| .. | .. |
|---|
| 1 | 1 | /* SPDX-License-Identifier: GPL-2.0 */ |
|---|
| 2 | 2 | #include <linux/fs.h> |
|---|
| 3 | | -#include <linux/bpf-cgroup.h> |
|---|
| 4 | 3 | |
|---|
| 5 | 4 | #define DEVCG_ACC_MKNOD 1 |
|---|
| 6 | 5 | #define DEVCG_ACC_READ 2 |
|---|
| .. | .. |
|---|
| 11 | 10 | #define DEVCG_DEV_CHAR 2 |
|---|
| 12 | 11 | #define DEVCG_DEV_ALL 4 /* this represents all devices */ |
|---|
| 13 | 12 | |
|---|
| 14 | | -#ifdef CONFIG_CGROUP_DEVICE |
|---|
| 15 | | -extern int __devcgroup_check_permission(short type, u32 major, u32 minor, |
|---|
| 16 | | - short access); |
|---|
| 17 | | -#else |
|---|
| 18 | | -static inline int __devcgroup_check_permission(short type, u32 major, u32 minor, |
|---|
| 19 | | - short access) |
|---|
| 20 | | -{ return 0; } |
|---|
| 21 | | -#endif |
|---|
| 22 | 13 | |
|---|
| 23 | 14 | #if defined(CONFIG_CGROUP_DEVICE) || defined(CONFIG_CGROUP_BPF) |
|---|
| 24 | | -static inline int devcgroup_check_permission(short type, u32 major, u32 minor, |
|---|
| 25 | | - short access) |
|---|
| 26 | | -{ |
|---|
| 27 | | - int rc = BPF_CGROUP_RUN_PROG_DEVICE_CGROUP(type, major, minor, access); |
|---|
| 28 | | - |
|---|
| 29 | | - if (rc) |
|---|
| 30 | | - return -EPERM; |
|---|
| 31 | | - |
|---|
| 32 | | - return __devcgroup_check_permission(type, major, minor, access); |
|---|
| 33 | | -} |
|---|
| 34 | | - |
|---|
| 15 | +int devcgroup_check_permission(short type, u32 major, u32 minor, |
|---|
| 16 | + short access); |
|---|
| 35 | 17 | static inline int devcgroup_inode_permission(struct inode *inode, int mask) |
|---|
| 36 | 18 | { |
|---|
| 37 | 19 | short type, access = 0; |
|---|
| .. | .. |
|---|
| 62 | 44 | if (!S_ISBLK(mode) && !S_ISCHR(mode)) |
|---|
| 63 | 45 | return 0; |
|---|
| 64 | 46 | |
|---|
| 47 | + if (S_ISCHR(mode) && dev == WHITEOUT_DEV) |
|---|
| 48 | + return 0; |
|---|
| 49 | + |
|---|
| 65 | 50 | if (S_ISBLK(mode)) |
|---|
| 66 | 51 | type = DEVCG_DEV_BLOCK; |
|---|
| 67 | 52 | else |
|---|
| .. | .. |
|---|
| 72 | 57 | } |
|---|
| 73 | 58 | |
|---|
| 74 | 59 | #else |
|---|
| 60 | +static inline int devcgroup_check_permission(short type, u32 major, u32 minor, |
|---|
| 61 | + short access) |
|---|
| 62 | +{ return 0; } |
|---|
| 75 | 63 | static inline int devcgroup_inode_permission(struct inode *inode, int mask) |
|---|
| 76 | 64 | { return 0; } |
|---|
| 77 | 65 | static inline int devcgroup_inode_mknod(int mode, dev_t dev) |
|---|