.. | .. |
---|
1 | 1 | /* SPDX-License-Identifier: GPL-2.0 */ |
---|
2 | 2 | #include <linux/fs.h> |
---|
3 | | -#include <linux/bpf-cgroup.h> |
---|
4 | 3 | |
---|
5 | 4 | #define DEVCG_ACC_MKNOD 1 |
---|
6 | 5 | #define DEVCG_ACC_READ 2 |
---|
.. | .. |
---|
11 | 10 | #define DEVCG_DEV_CHAR 2 |
---|
12 | 11 | #define DEVCG_DEV_ALL 4 /* this represents all devices */ |
---|
13 | 12 | |
---|
14 | | -#ifdef CONFIG_CGROUP_DEVICE |
---|
15 | | -extern int __devcgroup_check_permission(short type, u32 major, u32 minor, |
---|
16 | | - short access); |
---|
17 | | -#else |
---|
18 | | -static inline int __devcgroup_check_permission(short type, u32 major, u32 minor, |
---|
19 | | - short access) |
---|
20 | | -{ return 0; } |
---|
21 | | -#endif |
---|
22 | 13 | |
---|
23 | 14 | #if defined(CONFIG_CGROUP_DEVICE) || defined(CONFIG_CGROUP_BPF) |
---|
24 | | -static inline int devcgroup_check_permission(short type, u32 major, u32 minor, |
---|
25 | | - short access) |
---|
26 | | -{ |
---|
27 | | - int rc = BPF_CGROUP_RUN_PROG_DEVICE_CGROUP(type, major, minor, access); |
---|
28 | | - |
---|
29 | | - if (rc) |
---|
30 | | - return -EPERM; |
---|
31 | | - |
---|
32 | | - return __devcgroup_check_permission(type, major, minor, access); |
---|
33 | | -} |
---|
34 | | - |
---|
| 15 | +int devcgroup_check_permission(short type, u32 major, u32 minor, |
---|
| 16 | + short access); |
---|
35 | 17 | static inline int devcgroup_inode_permission(struct inode *inode, int mask) |
---|
36 | 18 | { |
---|
37 | 19 | short type, access = 0; |
---|
.. | .. |
---|
62 | 44 | if (!S_ISBLK(mode) && !S_ISCHR(mode)) |
---|
63 | 45 | return 0; |
---|
64 | 46 | |
---|
| 47 | + if (S_ISCHR(mode) && dev == WHITEOUT_DEV) |
---|
| 48 | + return 0; |
---|
| 49 | + |
---|
65 | 50 | if (S_ISBLK(mode)) |
---|
66 | 51 | type = DEVCG_DEV_BLOCK; |
---|
67 | 52 | else |
---|
.. | .. |
---|
72 | 57 | } |
---|
73 | 58 | |
---|
74 | 59 | #else |
---|
| 60 | +static inline int devcgroup_check_permission(short type, u32 major, u32 minor, |
---|
| 61 | + short access) |
---|
| 62 | +{ return 0; } |
---|
75 | 63 | static inline int devcgroup_inode_permission(struct inode *inode, int mask) |
---|
76 | 64 | { return 0; } |
---|
77 | 65 | static inline int devcgroup_inode_mknod(int mode, dev_t dev) |
---|