[roll] Roll fuchsia [sestarnix] Implement fast-path for file_permission()

During file_open() the SID of the FsNode and the sequence-number
of the currently loaded policy are cached, and the caller's access
to the FsNode (re-)validated. While this actually duplicates the
access validation performed earlier in the open() process, made
via FsNode::check_access(), the duplicate call will be mitigated by
the AVC.

During file_permission() it is then possible to skip the FsNode
access checks if the current task and FsNode labels, and policy
sequence number match, because by definition that combination is
already known to be permitted.

Original-Original-Bug: 522200811
Original-Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1638274
SLSA-Policy-Verified: SLSA Policy Verification Service <devtools-gerritcodereview-exitgate@google.com>
Original-Original-Revision: 95e712a615cdd0451fa69191e6d9ba19a46f5b0d
GitOrigin-RevId: dd250d8442c7312c9535e127fa6562b3ab4d0c9b
Change-Id: I4c8065772d9f7da0367f91dee75fbd17078ba18a
Reviewed-on: https://fuchsia-review.googlesource.com/c/integration/+/1681335
Cr-Commit-Position: refs/heads/main@{#195767}
1 file changed
tree: 317a4f7216908e31f4e87d123f97b90a7adf2904
  1. ctf/
  2. git-hooks/
  3. infra/
  4. third_party/
  5. cobalt
  6. flower
  7. jiri.lock
  8. MILESTONE
  9. minimal
  10. prebuilts
  11. README.md
  12. stem
  13. test_durations
README.md

Integration

This repository contains Fuchsia's Global Integration manifest files.

Making changes

All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.

Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.

Obtaining the source

First install Jiri.

Next run:

$ jiri init
$ jiri import minimal https://fuchsia.googlesource.com/integration
$ jiri update

Third party

Third party projects should have their own subdirectory in ./third_party.