Write permissions on the /dev/dma_heap/* device files are not required
to issue ioctls and allocate dmabufs. Applications should be opening
these file as O_RDONLY. The BPF dmabuf_iter selftest already does
this. [1]

Users are pointing to these selftests as examples of how use dmabuf,
and encountering permission errors on systems where write permissions
are not available on /dev/dma_heap/*. Apply the principle of least
privilege to selftests which open dmabuf heaps by removing the write
access mode and using O_RDONLY for the open() instead.

The same is true for the vgem test using /dev/dri/card.

[1] 
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/tools/testing/selftests/bpf/prog_tests/dmabuf_iter.c?h=v7.1#n49

Signed-off-by: T.J. Mercier <[email protected]>
---
 tools/testing/selftests/dmabuf-heaps/dmabuf-heap.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/tools/testing/selftests/dmabuf-heaps/dmabuf-heap.c 
b/tools/testing/selftests/dmabuf-heaps/dmabuf-heap.c
index fc9694fc4e89..45b420e37c97 100644
--- a/tools/testing/selftests/dmabuf-heaps/dmabuf-heap.c
+++ b/tools/testing/selftests/dmabuf-heaps/dmabuf-heap.c
@@ -48,7 +48,7 @@ static int open_vgem(void)
 
                snprintf(name, 80, "%s%u", drmstr, i);
 
-               fd = open(name, O_RDWR);
+               fd = open(name, O_RDONLY);
                if (fd < 0)
                        continue;
 
@@ -96,7 +96,7 @@ static int dmabuf_heap_open(char *name)
        if (ret < 0)
                ksft_exit_fail_msg("snprintf failed! %d\n", ret);
 
-       fd = open(buf, O_RDWR);
+       fd = open(buf, O_RDONLY);
        if (fd < 0)
                ksft_exit_fail_msg("open %s failed: %s\n", buf, 
strerror(errno));
 

base-commit: 9a11db68872055e6ead919bad04d6330851c522d
-- 
2.55.0.679.g6767b8d81c-goog


Reply via email to