{"id":27360,"url":"https://patchwork.libcamera.org/api/patches/27360/?format=json","web_url":"https://patchwork.libcamera.org/patch/27360/","project":{"id":1,"url":"https://patchwork.libcamera.org/api/projects/1/?format=json","name":"libcamera","link_name":"libcamera","list_id":"libcamera_core","list_email":"libcamera-devel@lists.libcamera.org","web_url":"","scm_url":"","webscm_url":""},"msgid":"<20260709183049.2282221-1-tjmercier@google.com>","date":"2026-07-09T18:30:45","name":"DmaBufAllocator: Open heap device files O_RDONLY","commit_ref":null,"pull_url":null,"state":"new","archived":false,"hash":"496d459c032d41c2f4e05c91e5cd346dd78868f3","submitter":{"id":385,"url":"https://patchwork.libcamera.org/api/people/385/?format=json","name":"T.J. Mercier","email":"tjmercier@google.com"},"delegate":null,"mbox":"https://patchwork.libcamera.org/patch/27360/mbox/","series":[{"id":6056,"url":"https://patchwork.libcamera.org/api/series/6056/?format=json","web_url":"https://patchwork.libcamera.org/project/libcamera/list/?series=6056","date":"2026-07-09T18:30:45","name":"DmaBufAllocator: Open heap device files O_RDONLY","version":1,"mbox":"https://patchwork.libcamera.org/series/6056/mbox/"}],"comments":"https://patchwork.libcamera.org/api/patches/27360/comments/","check":"pending","checks":"https://patchwork.libcamera.org/api/patches/27360/checks/","tags":{},"headers":{"Return-Path":"<libcamera-devel-bounces@lists.libcamera.org>","X-Original-To":"parsemail@patchwork.libcamera.org","Delivered-To":"parsemail@patchwork.libcamera.org","Received":["from lancelot.ideasonboard.com (lancelot.ideasonboard.com\n\t[92.243.16.209])\n\tby patchwork.libcamera.org (Postfix) with ESMTPS id DF5C9C3318\n\tfor <parsemail@patchwork.libcamera.org>;\n\tThu,  9 Jul 2026 18:30:56 +0000 (UTC)","from lancelot.ideasonboard.com (localhost [IPv6:::1])\n\tby lancelot.ideasonboard.com (Postfix) with ESMTP id CBF44660F7;\n\tThu,  9 Jul 2026 20:30:55 +0200 (CEST)","from mail-pg1-x54a.google.com (mail-pg1-x54a.google.com\n\t[IPv6:2607:f8b0:4864:20::54a])\n\tby lancelot.ideasonboard.com (Postfix) with ESMTPS id DF15E660E3\n\tfor <libcamera-devel@lists.libcamera.org>;\n\tThu,  9 Jul 2026 20:30:53 +0200 (CEST)","by mail-pg1-x54a.google.com with SMTP id\n\t41be03b00d2f7-c894c1c4aa9so177847a12.0\n\tfor <libcamera-devel@lists.libcamera.org>;\n\tThu, 09 Jul 2026 11:30:53 -0700 (PDT)"],"Authentication-Results":"lancelot.ideasonboard.com; dkim=pass (2048-bit key;\n\tunprotected) header.d=google.com header.i=@google.com\n\theader.b=\"PqEOZC9n\"; dkim-atps=neutral","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=google.com; s=20251104; t=1783621852; x=1784226652;\n\tdarn=lists.libcamera.org; \n\th=content-type:cc:to:from:subject:message-id:mime-version:date:from\n\t:to:cc:subject:date:message-id:reply-to:content-type;\n\tbh=vSGK9CeAbi4IqaeyB3S8skUc+lL+s/l/Ze39ZEYbDI0=;\n\tb=PqEOZC9nHBPaDY236cvAz/6UnCiqBn1BHHevTOCsNiyLM05PKkPwlCtAjHLUPSF9N2\n\tnJSXQJ+yr9KU+Zbdn++/yp88BV/47d4+NZmLyKzjBU4wGUuJTlxIoVmwo5U6zklN5gZy\n\tjY2451KQ1YmiAQg6ZbdM919c/Z5R815VYoamPaghoYeyNXRaAPG2jYGDYerY239gQ1p9\n\t7p8RrIve/UT2puQgrwbUqsTbxCmnjAqxZDOZQGB56WeD3NRJ1O6C6s8rx84Op6dDZ+Lw\n\t9EHPN8eFDyV39EflyYOvrB4NxuzWOsAc2SL4BsD3q7UK4mMZgBd4xZjn54y7zf3VMZIu\n\tI/4A==","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20251104; t=1783621852; x=1784226652;\n\th=content-type:cc:to:from:subject:message-id:mime-version:date\n\t:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to\n\t:content-type;\n\tbh=vSGK9CeAbi4IqaeyB3S8skUc+lL+s/l/Ze39ZEYbDI0=;\n\tb=nBuc/AU41CZ8iWoH9q2kCiuTmNiKXV+g7gSowYg2Z8cUY0vQrsB729RQmufCBZU73z\n\th0lUElNixhsXqXOwQEJirkVqa1j+ZKEXgcyMswauHUVyfbSN4jQHMFeBiw1J3cuMfJS/\n\tvAELuhMGqPowAwD2G7Bbd6ZuPDxwlG2N6XR97ADfjh66RY17UWgWbufbXfmZHUeQlbOl\n\tKpZpGKjOzQFdgk0tnslzD7tpjhaPwIu/cIen/VB9zri3sb90yk8G+f/PjIJT1lZkDDbQ\n\t9kQ3idR38x4vhSc6Xy2CRMa0t6EkfrIra+G0XnudFOjocKXM4nVFcde3Bcsj/E6RjjEr\n\tD45Q==","X-Gm-Message-State":"AOJu0YwZ1sDvxc1Xygys+WWEPu9F6gyEI2TvmCBKWmevneXPLFRuKJCB\n\tKnxC+iD+MlbCIKmTzGZTJ3DPwahLDUq+gRuqIqmirihUkW3yH3nR79/Mq7G/GA+ORSlzr1PEhsp\n\ts6gWas3FlRQ04r3mz/M+7ecGOBa/TqOzwHt/bkKcUqIODOPSjjoZ0f6ATnr4a3XWfMYB0Y9LJWx\n\tJXIOPIxkFIAiiCJH95URt4K/nrhB79Ksvi0/S6FET6Q29CEwLNQtNikDaR8sc0vIfZQMYXpA==","X-Received":"from pgac17.prod.google.com\n\t([2002:a05:6a02:2951:b0:c76:6c2f:89d4])\n\t(user=tjmercier job=prod-delivery.src-stubby-dispatcher) by\n\t2002:a05:6a21:10d:b0:3bc:5284:4859 with SMTP id\n\tadf61e73a8af0-3c0bce12ef1mr10648748637.13.1783621851351; \n\tThu, 09 Jul 2026 11:30:51 -0700 (PDT)","Date":"Thu,  9 Jul 2026 11:30:45 -0700","Mime-Version":"1.0","X-Mailer":"git-send-email 2.55.0.795.g602f6c329a-goog","Message-ID":"<20260709183049.2282221-1-tjmercier@google.com>","Subject":"[PATCH] DmaBufAllocator: Open heap device files O_RDONLY","From":"\"T.J. Mercier\" <tjmercier@google.com>","To":"libcamera-devel@lists.libcamera.org","Cc":"\"T.J. Mercier\" <tjmercier@google.com>","Content-Type":"text/plain; charset=\"UTF-8\"","X-BeenThere":"libcamera-devel@lists.libcamera.org","X-Mailman-Version":"2.1.29","Precedence":"list","List-Id":"<libcamera-devel.lists.libcamera.org>","List-Unsubscribe":"<https://lists.libcamera.org/options/libcamera-devel>,\n\t<mailto:libcamera-devel-request@lists.libcamera.org?subject=unsubscribe>","List-Archive":"<https://lists.libcamera.org/pipermail/libcamera-devel/>","List-Post":"<mailto:libcamera-devel@lists.libcamera.org>","List-Help":"<mailto:libcamera-devel-request@lists.libcamera.org?subject=help>","List-Subscribe":"<https://lists.libcamera.org/listinfo/libcamera-devel>,\n\t<mailto:libcamera-devel-request@lists.libcamera.org?subject=subscribe>","Errors-To":"libcamera-devel-bounces@lists.libcamera.org","Sender":"\"libcamera-devel\" <libcamera-devel-bounces@lists.libcamera.org>"},"content":"The write access mode is not required to issue ioctls and allocate\ndma-bufs from heaps. Applications should be opening them as O_RDONLY.\n\nPermission errors can be encountered while attempting to open() files in\n/dev/dma_heap/* on systems where write permissions are not available. So\napply the principle of least privilege and remove the write access mode.\n\nSigned-off-by: T.J. Mercier <tjmercier@google.com>\n---\n src/libcamera/dma_buf_allocator.cpp | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)","diff":"diff --git a/src/libcamera/dma_buf_allocator.cpp b/src/libcamera/dma_buf_allocator.cpp\nindex d8c62dd67..c673d23ec 100644\n--- a/src/libcamera/dma_buf_allocator.cpp\n+++ b/src/libcamera/dma_buf_allocator.cpp\n@@ -100,7 +100,7 @@ DmaBufAllocator::DmaBufAllocator(DmaBufAllocatorFlags type)\n \t\tif (!(type & info.type))\n \t\t\tcontinue;\n \n-\t\tint ret = ::open(info.deviceNodeName, O_RDWR | O_CLOEXEC, 0);\n+\t\tint ret = ::open(info.deviceNodeName, O_RDONLY | O_CLOEXEC, 0);\n \t\tif (ret < 0) {\n \t\t\tret = errno;\n \t\t\tLOG(DmaBufAllocator, Debug)\n","prefixes":[]}