[Devel] [PATCH vz10 7/7] fs/proc, ve: add per-VE ve.proc_permissions
Vladimir Riabchun
vladimir.riabchun at virtuozzo.com
Mon Jul 6 19:05:04 MSK 2026
On 6/28/26 11:26, Mirian Shilakadze wrote:
> Add a per-VE allowlist of /proc paths exposed through the cgroup file
> ve.proc_permissions, the procfs counterpart of ve.sysfs_permissions.
> Each proc_dir_entry gains a kmapset map keyed by VE (proc_perms_key on
> ...
> +static int proc_perms_show(struct seq_file *m, void *v)
> +{
> + struct ve_struct *ve = css_to_ve(seq_css(m));
> + struct proc_dir_entry *de = v;
> + struct kmapset_map *map;
> + char *buf;
> + size_t size, len, off;
> + int mask;
> +
> + map = rcu_dereference_protected(de->ve_perms_map,
> + lockdep_is_held(&proc_perms_mutex));
> + if (ve_is_super(ve))
> + mask = map->default_value;
> + else
> + mask = kmapset_get_value(map, &ve->proc_perms_key);
> +
> + size = seq_get_buf(m, &buf);
> + if (size) {
> + off = size;
> + do {
> + len = strlen(de->name);
> + if (len >= off) {
> + seq_commit(m, -1);
> + return 0;
> + }
> + if (S_ISDIR(de->mode))
> + buf[--off] = '/';
> + off -= len;
> + memcpy(buf + off, de->name, len);
> + de = de->parent;
> + } while (de && de != &proc_root);
This loop seems a little bit sad. Take a look at sysctl_print_dir,
I think the recursive approach here will be perfect - seq_write will
do all size checks instead of us and the recursion depth shouldn't be big.
This will simplify the code greatly.
> + memmove(buf, buf + off, size - off);
> + seq_commit(m, size - off);
> + }
> +
> + ve_perms_emit(m, mask);
> + return 0;
> +}
> ...
--
Best regards, Riabchun Vladimir
Linux Kernel Developer, Virtuozzo
More information about the Devel
mailing list