Hello T J,

On Wed, 12 Aug 2026 at 02:11, T.J. Mercier <[email protected]> wrote:
>
> Write permissions on the /dev/dma_heap/* device files are not required
> to issue ioctls and allocate dmabufs. Applications should be opening
> these file as O_RDONLY. The BPF dmabuf_iter selftest already does
> this. [1]
>
> Users are pointing to these selftests as examples of how use dmabuf,
> and encountering permission errors on systems where write permissions
> are not available on /dev/dma_heap/*. Apply the principle of least
> privilege to selftests which open dmabuf heaps by removing the write
> access mode and using O_RDONLY for the open() instead.

Thanks for the patch.
>
> The same is true for the vgem test using /dev/dri/card.
>
> [1] 
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/tools/testing/selftests/bpf/prog_tests/dmabuf_iter.c?h=v7.1#n49
>
> Signed-off-by: T.J. Mercier <[email protected]>
Acked-by: Sumit Semwal <[email protected]>
> ---
>  tools/testing/selftests/dmabuf-heaps/dmabuf-heap.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/tools/testing/selftests/dmabuf-heaps/dmabuf-heap.c 
> b/tools/testing/selftests/dmabuf-heaps/dmabuf-heap.c
> index fc9694fc4e89..45b420e37c97 100644
> --- a/tools/testing/selftests/dmabuf-heaps/dmabuf-heap.c
> +++ b/tools/testing/selftests/dmabuf-heaps/dmabuf-heap.c
> @@ -48,7 +48,7 @@ static int open_vgem(void)
>
>                 snprintf(name, 80, "%s%u", drmstr, i);
>
> -               fd = open(name, O_RDWR);
> +               fd = open(name, O_RDONLY);
>                 if (fd < 0)
>                         continue;
>
> @@ -96,7 +96,7 @@ static int dmabuf_heap_open(char *name)
>         if (ret < 0)
>                 ksft_exit_fail_msg("snprintf failed! %d\n", ret);
>
> -       fd = open(buf, O_RDWR);
> +       fd = open(buf, O_RDONLY);
>         if (fd < 0)
>                 ksft_exit_fail_msg("open %s failed: %s\n", buf, 
> strerror(errno));
>
>
> base-commit: 9a11db68872055e6ead919bad04d6330851c522d
> --
> 2.55.0.679.g6767b8d81c-goog
>

Reply via email to