Home | History | Annotate | Line # | Download | only in sys
      1 /* $NetBSD: t_setuid.c,v 1.1 2011/07/07 06:57:54 jruoho Exp $ */
      2 
      3 /*-
      4  * Copyright (c) 2011 The NetBSD Foundation, Inc.
      5  * All rights reserved.
      6  *
      7  * This code is derived from software contributed to The NetBSD Foundation
      8  * by Jukka Ruohonen.
      9  *
     10  * Redistribution and use in source and binary forms, with or without
     11  * modification, are permitted provided that the following conditions
     12  * are met:
     13  * 1. Redistributions of source code must retain the above copyright
     14  *    notice, this list of conditions and the following disclaimer.
     15  * 2. Redistributions in binary form must reproduce the above copyright
     16  *    notice, this list of conditions and the following disclaimer in the
     17  *    documentation and/or other materials provided with the distribution.
     18  *
     19  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     20  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     21  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     22  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     23  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     24  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     25  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     26  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     27  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     28  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     29  * POSSIBILITY OF SUCH DAMAGE.
     30  */
     31 #include <sys/cdefs.h>
     32 __RCSID("$NetBSD: t_setuid.c,v 1.1 2011/07/07 06:57:54 jruoho Exp $");
     33 
     34 #include <sys/wait.h>
     35 
     36 #include <atf-c.h>
     37 #include <errno.h>
     38 #include <pwd.h>
     39 #include <stdlib.h>
     40 #include <unistd.h>
     41 
     42 ATF_TC(setuid_perm);
     43 ATF_TC_HEAD(setuid_perm, tc)
     44 {
     45 	atf_tc_set_md_var(tc, "descr", "Test setuid(0) as normal user");
     46 	atf_tc_set_md_var(tc, "require.user", "unprivileged");
     47 }
     48 
     49 ATF_TC_BODY(setuid_perm, tc)
     50 {
     51 	errno = 0;
     52 
     53 	ATF_REQUIRE(setuid(0) == -1);
     54 	ATF_REQUIRE(errno == EPERM);
     55 }
     56 
     57 ATF_TC(setuid_real);
     58 ATF_TC_HEAD(setuid_real, tc)
     59 {
     60 	atf_tc_set_md_var(tc, "descr", "Test setuid(2) with real UID");
     61 }
     62 
     63 ATF_TC_BODY(setuid_real, tc)
     64 {
     65 	uid_t uid = getuid();
     66 
     67 	ATF_REQUIRE(setuid(uid) == 0);
     68 
     69 	ATF_REQUIRE(getuid() == uid);
     70 	ATF_REQUIRE(geteuid() == uid);
     71 }
     72 
     73 ATF_TC(setuid_root);
     74 ATF_TC_HEAD(setuid_root, tc)
     75 {
     76 	atf_tc_set_md_var(tc, "descr", "A basic test of setuid(2)");
     77 	atf_tc_set_md_var(tc, "require.user", "root");
     78 }
     79 
     80 ATF_TC_BODY(setuid_root, tc)
     81 {
     82 	struct passwd *pw;
     83 	int rv, sta;
     84 	pid_t pid;
     85 	uid_t uid;
     86 
     87 	while ((pw = getpwent()) != NULL) {
     88 
     89 		pid = fork();
     90 		ATF_REQUIRE(pid >= 0);
     91 
     92 		if (pid == 0) {
     93 
     94 			rv = setuid(pw->pw_uid);
     95 
     96 			if (rv != 0)
     97 				_exit(EXIT_FAILURE);
     98 
     99 			uid = getuid();
    100 
    101 			if (uid != pw->pw_uid)
    102 				_exit(EXIT_FAILURE);
    103 
    104 			_exit(EXIT_SUCCESS);
    105 		}
    106 
    107 		(void)wait(&sta);
    108 
    109 		if (WIFEXITED(sta) == 0 || WEXITSTATUS(sta) != EXIT_SUCCESS)
    110 			atf_tc_fail("failed to change UID to %u", pw->pw_uid);
    111 	}
    112 }
    113 
    114 ATF_TP_ADD_TCS(tp)
    115 {
    116 
    117 	ATF_TP_ADD_TC(tp, setuid_perm);
    118 	ATF_TP_ADD_TC(tp, setuid_real);
    119 	ATF_TP_ADD_TC(tp, setuid_root);
    120 
    121 	return atf_no_error();
    122 }
    123