io_uring: refactor io_uring_allowed()

Have io_uring_allowed() return an error code directly instead of
true/false. This is needed for follow-up work to guard io_uring_setup()
with LSM.

Cc: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Hamza Mahfooz <hamzamahfooz@linux.microsoft.com>
Acked-by: Jens Axboe <axboe@kernel.dk>
[PM: goto-to-return conversion as discussed on-list]
Signed-off-by: Paul Moore <paul@paul-moore.com>
This commit is contained in:
Hamza Mahfooz 2025-01-27 10:57:17 -05:00 committed by Paul Moore
parent 2014c95afe
commit b8a468e0b0

View File

@ -3791,29 +3791,35 @@ static long io_uring_setup(u32 entries, struct io_uring_params __user *params)
return io_uring_create(entries, &p, params);
}
static inline bool io_uring_allowed(void)
static inline int io_uring_allowed(void)
{
int disabled = READ_ONCE(sysctl_io_uring_disabled);
kgid_t io_uring_group;
if (disabled == 2)
return false;
return -EPERM;
if (disabled == 0 || capable(CAP_SYS_ADMIN))
return true;
return 0;
io_uring_group = make_kgid(&init_user_ns, sysctl_io_uring_group);
if (!gid_valid(io_uring_group))
return false;
return -EPERM;
return in_group_p(io_uring_group);
if (!in_group_p(io_uring_group))
return -EPERM;
return 0;
}
SYSCALL_DEFINE2(io_uring_setup, u32, entries,
struct io_uring_params __user *, params)
{
if (!io_uring_allowed())
return -EPERM;
int ret;
ret = io_uring_allowed();
if (ret)
return ret;
return io_uring_setup(entries, params);
}