Home | History | Annotate | Line # | Download | only in vfs
t_unpriv.c revision 1.9
      1  1.9  njoly /*	$NetBSD: t_unpriv.c,v 1.9 2012/04/04 18:53:34 njoly Exp $	*/
      2  1.1  njoly 
      3  1.1  njoly /*-
      4  1.1  njoly  * Copyright (c) 2011 The NetBSD Foundation, Inc.
      5  1.1  njoly  * All rights reserved.
      6  1.1  njoly  *
      7  1.1  njoly  * Redistribution and use in source and binary forms, with or without
      8  1.1  njoly  * modification, are permitted provided that the following conditions
      9  1.1  njoly  * are met:
     10  1.1  njoly  * 1. Redistributions of source code must retain the above copyright
     11  1.1  njoly  *    notice, this list of conditions and the following disclaimer.
     12  1.1  njoly  * 2. Redistributions in binary form must reproduce the above copyright
     13  1.1  njoly  *    notice, this list of conditions and the following disclaimer in the
     14  1.1  njoly  *    documentation and/or other materials provided with the distribution.
     15  1.1  njoly  *
     16  1.1  njoly  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     17  1.1  njoly  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     18  1.1  njoly  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     19  1.1  njoly  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     20  1.1  njoly  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     21  1.1  njoly  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     22  1.1  njoly  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     23  1.1  njoly  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     24  1.1  njoly  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     25  1.1  njoly  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     26  1.1  njoly  * POSSIBILITY OF SUCH DAMAGE.
     27  1.1  njoly  */
     28  1.1  njoly 
     29  1.9  njoly #include <sys/stat.h>
     30  1.6  njoly #include <sys/time.h>
     31  1.6  njoly 
     32  1.1  njoly #include <atf-c.h>
     33  1.5  njoly #include <libgen.h>
     34  1.1  njoly #include <unistd.h>
     35  1.1  njoly 
     36  1.1  njoly #include <rump/rump_syscalls.h>
     37  1.1  njoly #include <rump/rump.h>
     38  1.1  njoly 
     39  1.1  njoly #include "../common/h_fsmacros.h"
     40  1.1  njoly #include "../../h_macros.h"
     41  1.1  njoly 
     42  1.2  njoly #define USES_OWNER							 \
     43  1.4  njoly 	if (FSTYPE_MSDOS(tc))						 \
     44  1.1  njoly 	    atf_tc_skip("owner not supported by file system")
     45  1.1  njoly 
     46  1.1  njoly static void
     47  1.1  njoly owner(const atf_tc_t *tc, const char *mp)
     48  1.1  njoly {
     49  1.1  njoly 
     50  1.2  njoly 	USES_OWNER;
     51  1.1  njoly 
     52  1.1  njoly 	FSTEST_ENTER();
     53  1.1  njoly 
     54  1.1  njoly 	rump_pub_lwproc_rfork(RUMP_RFCFDG);
     55  1.1  njoly 	if (rump_sys_setuid(1) == -1)
     56  1.1  njoly 		atf_tc_fail_errno("setuid");
     57  1.1  njoly         if (rump_sys_chown(".", 1, -1) != -1 || errno != EPERM)
     58  1.1  njoly 		atf_tc_fail_errno("chown");
     59  1.1  njoly         if (rump_sys_chmod(".", 0000) != -1 || errno != EPERM)
     60  1.1  njoly                 atf_tc_fail_errno("chmod");
     61  1.1  njoly 	rump_pub_lwproc_releaselwp();
     62  1.1  njoly 
     63  1.1  njoly 	if (rump_sys_chown(".", 1, -1) == -1)
     64  1.1  njoly 		atf_tc_fail_errno("chown");
     65  1.1  njoly 
     66  1.1  njoly 	rump_pub_lwproc_rfork(RUMP_RFCFDG);
     67  1.1  njoly 	if (rump_sys_setuid(1) == -1)
     68  1.1  njoly 		atf_tc_fail_errno("setuid");
     69  1.1  njoly         if (rump_sys_chown(".", 1, -1) == -1)
     70  1.1  njoly 		atf_tc_fail_errno("chown");
     71  1.1  njoly         if (rump_sys_chmod(".", 0000) == -1)
     72  1.1  njoly                 atf_tc_fail_errno("chmod");
     73  1.1  njoly 	rump_pub_lwproc_releaselwp();
     74  1.1  njoly 
     75  1.1  njoly 	FSTEST_EXIT();
     76  1.1  njoly }
     77  1.1  njoly 
     78  1.5  njoly static void
     79  1.5  njoly dirperms(const atf_tc_t *tc, const char *mp)
     80  1.5  njoly {
     81  1.5  njoly 	char name[] = "dir.test/file.test";
     82  1.5  njoly 	char *dir = dirname(name);
     83  1.5  njoly 	int fd;
     84  1.5  njoly 
     85  1.5  njoly 	if (FSTYPE_SYSVBFS(tc))
     86  1.5  njoly 		atf_tc_skip("directories not supported by file system");
     87  1.5  njoly 
     88  1.5  njoly 	FSTEST_ENTER();
     89  1.5  njoly 
     90  1.5  njoly 	if (rump_sys_mkdir(dir, 0777) == -1)
     91  1.5  njoly 		atf_tc_fail_errno("mkdir");
     92  1.5  njoly 
     93  1.5  njoly 	rump_pub_lwproc_rfork(RUMP_RFCFDG);
     94  1.5  njoly 	if (rump_sys_setuid(1) == -1)
     95  1.5  njoly 		atf_tc_fail_errno("setuid");
     96  1.5  njoly         if (rump_sys_open(name, O_RDWR|O_CREAT, 0666) != -1 || errno != EACCES)
     97  1.5  njoly 		atf_tc_fail_errno("open");
     98  1.5  njoly 	rump_pub_lwproc_releaselwp();
     99  1.5  njoly 
    100  1.5  njoly 	if ((fd = rump_sys_open(name, O_RDWR|O_CREAT, 0666)) == -1)
    101  1.5  njoly 		atf_tc_fail_errno("open");
    102  1.5  njoly 	if (rump_sys_close(fd) == -1)
    103  1.5  njoly 		atf_tc_fail_errno("close");
    104  1.5  njoly 
    105  1.5  njoly 	rump_pub_lwproc_rfork(RUMP_RFCFDG);
    106  1.5  njoly 	if (rump_sys_setuid(1) == -1)
    107  1.5  njoly 		atf_tc_fail_errno("setuid");
    108  1.5  njoly         if (rump_sys_unlink(name) != -1 || errno != EACCES)
    109  1.5  njoly 		atf_tc_fail_errno("unlink");
    110  1.5  njoly 	rump_pub_lwproc_releaselwp();
    111  1.5  njoly 
    112  1.5  njoly         if (rump_sys_unlink(name) == -1)
    113  1.5  njoly 		atf_tc_fail_errno("unlink");
    114  1.5  njoly 
    115  1.5  njoly 	if (rump_sys_rmdir(dir) == -1)
    116  1.5  njoly 		atf_tc_fail_errno("rmdir");
    117  1.5  njoly 
    118  1.5  njoly 	FSTEST_EXIT();
    119  1.5  njoly }
    120  1.1  njoly 
    121  1.6  njoly static void
    122  1.6  njoly times(const atf_tc_t *tc, const char *mp)
    123  1.6  njoly {
    124  1.6  njoly 	const char *name = "file.test";
    125  1.8  njoly 	int fd;
    126  1.7  njoly 	struct timeval tmv[2];
    127  1.6  njoly 
    128  1.6  njoly 	FSTEST_ENTER();
    129  1.6  njoly 
    130  1.6  njoly 	if ((fd = rump_sys_open(name, O_RDWR|O_CREAT, 0666)) == -1)
    131  1.6  njoly 		atf_tc_fail_errno("open");
    132  1.6  njoly 	if (rump_sys_close(fd) == -1)
    133  1.6  njoly 		atf_tc_fail_errno("close");
    134  1.6  njoly 
    135  1.6  njoly 	rump_pub_lwproc_rfork(RUMP_RFCFDG);
    136  1.6  njoly 	if (rump_sys_setuid(1) == -1)
    137  1.6  njoly 		atf_tc_fail_errno("setuid");
    138  1.6  njoly 	if (rump_sys_utimes(name, NULL) != -1 || errno != EACCES)
    139  1.6  njoly 		atf_tc_fail_errno("utimes");
    140  1.6  njoly 	rump_pub_lwproc_releaselwp();
    141  1.6  njoly 
    142  1.6  njoly 	if (rump_sys_utimes(name, NULL) == -1)
    143  1.6  njoly 		atf_tc_fail_errno("utimes");
    144  1.6  njoly 
    145  1.7  njoly 	rump_pub_lwproc_rfork(RUMP_RFCFDG);
    146  1.7  njoly 	if (rump_sys_setuid(1) == -1)
    147  1.7  njoly 		atf_tc_fail_errno("setuid");
    148  1.8  njoly 	if (rump_sys_utimes(name, tmv) != -1 || errno != EPERM)
    149  1.7  njoly 		atf_tc_fail_errno("utimes");
    150  1.7  njoly 	rump_pub_lwproc_releaselwp();
    151  1.7  njoly 
    152  1.7  njoly 	if (rump_sys_utimes(name, tmv) == -1)
    153  1.7  njoly 		atf_tc_fail_errno("utimes");
    154  1.7  njoly 
    155  1.6  njoly 	if (rump_sys_unlink(name) == -1)
    156  1.6  njoly 		atf_tc_fail_errno("unlink");
    157  1.6  njoly 
    158  1.6  njoly 	FSTEST_EXIT();
    159  1.6  njoly }
    160  1.6  njoly 
    161  1.9  njoly static void
    162  1.9  njoly flags(const atf_tc_t *tc, const char *mp)
    163  1.9  njoly {
    164  1.9  njoly 	const char *name = "file.test";
    165  1.9  njoly 	int fd, fflags;
    166  1.9  njoly 	struct stat st;
    167  1.9  njoly 
    168  1.9  njoly 	FSTEST_ENTER();
    169  1.9  njoly 
    170  1.9  njoly 	if ((fd = rump_sys_open(name, O_RDWR|O_CREAT, 0666)) == -1)
    171  1.9  njoly 		atf_tc_fail_errno("open");
    172  1.9  njoly 	if (rump_sys_close(fd) == -1)
    173  1.9  njoly 		atf_tc_fail_errno("close");
    174  1.9  njoly 
    175  1.9  njoly 	if (rump_sys_stat(name, &st) == -1)
    176  1.9  njoly 		atf_tc_fail_errno("stat");
    177  1.9  njoly 	if (rump_sys_chflags(name, st.st_flags) == -1) {
    178  1.9  njoly 		if (errno == EOPNOTSUPP)
    179  1.9  njoly 			atf_tc_skip("file flags not supported by file system");
    180  1.9  njoly 		atf_tc_fail_errno("chflags");
    181  1.9  njoly 	}
    182  1.9  njoly 
    183  1.9  njoly 	fflags = st.st_flags | UF_IMMUTABLE;
    184  1.9  njoly 
    185  1.9  njoly 	rump_pub_lwproc_rfork(RUMP_RFCFDG);
    186  1.9  njoly 	if (rump_sys_setuid(1) == -1)
    187  1.9  njoly 		atf_tc_fail_errno("setuid");
    188  1.9  njoly 	fflags |= UF_IMMUTABLE;
    189  1.9  njoly 	if (rump_sys_chflags(name, fflags) != -1 || errno != EPERM)
    190  1.9  njoly 		atf_tc_fail_errno("chflags");
    191  1.9  njoly 	rump_pub_lwproc_releaselwp();
    192  1.9  njoly 
    193  1.9  njoly 	if (rump_sys_chflags(name, fflags) == -1)
    194  1.9  njoly 		atf_tc_fail_errno("chflags");
    195  1.9  njoly 
    196  1.9  njoly 	fflags &= ~UF_IMMUTABLE;
    197  1.9  njoly 	if (rump_sys_chflags(name, fflags) == -1)
    198  1.9  njoly 		atf_tc_fail_errno("chflags");
    199  1.9  njoly 
    200  1.9  njoly 	if (rump_sys_unlink(name) == -1)
    201  1.9  njoly 		atf_tc_fail_errno("unlink");
    202  1.9  njoly 
    203  1.9  njoly 	FSTEST_EXIT();
    204  1.9  njoly }
    205  1.9  njoly 
    206  1.1  njoly ATF_TC_FSAPPLY(owner, "owner unprivileged checks");
    207  1.5  njoly ATF_TC_FSAPPLY(dirperms, "directory permission checks");
    208  1.6  njoly ATF_TC_FSAPPLY(times, "time set checks");
    209  1.9  njoly ATF_TC_FSAPPLY(flags, "file flags checks");
    210  1.1  njoly 
    211  1.1  njoly ATF_TP_ADD_TCS(tp)
    212  1.1  njoly {
    213  1.1  njoly 
    214  1.1  njoly 	ATF_TP_FSAPPLY(owner);
    215  1.5  njoly 	ATF_TP_FSAPPLY(dirperms);
    216  1.6  njoly 	ATF_TP_FSAPPLY(times);
    217  1.9  njoly 	ATF_TP_FSAPPLY(flags);
    218  1.1  njoly 
    219  1.1  njoly 	return atf_no_error();
    220  1.1  njoly }
    221