1*ef23f679Sriastradh /* $NetBSD: t_memfd_create.c,v 1.3 2023/11/24 17:31:03 riastradh Exp $ */
2d3ba7ba3Schristos
3d3ba7ba3Schristos /*-
4d3ba7ba3Schristos * Copyright (c) 2023 The NetBSD Foundation, Inc.
5d3ba7ba3Schristos * All rights reserved.
6d3ba7ba3Schristos *
7d3ba7ba3Schristos * This code is derived from software contributed to The NetBSD Foundation
8d3ba7ba3Schristos * by Theodore Preduta.
9d3ba7ba3Schristos *
10d3ba7ba3Schristos * Redistribution and use in source and binary forms, with or without
11d3ba7ba3Schristos * modification, are permitted provided that the following conditions
12d3ba7ba3Schristos * are met:
13d3ba7ba3Schristos * 1. Redistributions of source code must retain the above copyright
14d3ba7ba3Schristos * notice, this list of conditions and the following disclaimer.
15d3ba7ba3Schristos * 2. Redistributions in binary form must reproduce the above copyright
16d3ba7ba3Schristos * notice, this list of conditions and the following disclaimer in the
17d3ba7ba3Schristos * documentation and/or other materials provided with the distribution.
18d3ba7ba3Schristos *
19d3ba7ba3Schristos * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
20d3ba7ba3Schristos * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
21d3ba7ba3Schristos * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
22d3ba7ba3Schristos * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
23d3ba7ba3Schristos * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
24d3ba7ba3Schristos * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25d3ba7ba3Schristos * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26d3ba7ba3Schristos * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
27d3ba7ba3Schristos * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28d3ba7ba3Schristos * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
29d3ba7ba3Schristos * POSSIBILITY OF SUCH DAMAGE.
30d3ba7ba3Schristos */
31d3ba7ba3Schristos #include <sys/cdefs.h>
32*ef23f679Sriastradh __RCSID("$NetBSD: t_memfd_create.c,v 1.3 2023/11/24 17:31:03 riastradh Exp $");
33d3ba7ba3Schristos
34d3ba7ba3Schristos #include <sys/param.h>
35d3ba7ba3Schristos #include <sys/types.h>
36d3ba7ba3Schristos #include <sys/mman.h>
37d3ba7ba3Schristos #include <sys/stat.h>
38d3ba7ba3Schristos #include <errno.h>
39d3ba7ba3Schristos #include <fcntl.h>
40d3ba7ba3Schristos
41d3ba7ba3Schristos #include <atf-c.h>
42d3ba7ba3Schristos
43d3ba7ba3Schristos #include "h_macros.h"
44d3ba7ba3Schristos
45d3ba7ba3Schristos char name_buf[NAME_MAX];
46d3ba7ba3Schristos char write_buf[8192];
47d3ba7ba3Schristos char read_buf[8192];
48d3ba7ba3Schristos
49d3ba7ba3Schristos ATF_TC(create_null_name);
ATF_TC_HEAD(create_null_name,tc)50d3ba7ba3Schristos ATF_TC_HEAD(create_null_name, tc)
51d3ba7ba3Schristos {
52d3ba7ba3Schristos
53d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
54d3ba7ba3Schristos "Checks memfd_create fails with EFAULT when invalid memory"
55d3ba7ba3Schristos " is provided");
56d3ba7ba3Schristos }
ATF_TC_BODY(create_null_name,tc)57d3ba7ba3Schristos ATF_TC_BODY(create_null_name, tc)
58d3ba7ba3Schristos {
59d3ba7ba3Schristos int fd;
60d3ba7ba3Schristos
61d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(fd = memfd_create(NULL, 0), -1,
62d3ba7ba3Schristos "Unexpected success");
63d3ba7ba3Schristos ATF_REQUIRE_ERRNO(EFAULT, true);
64d3ba7ba3Schristos }
65d3ba7ba3Schristos
66d3ba7ba3Schristos ATF_TC(create_long_name);
ATF_TC_HEAD(create_long_name,tc)67d3ba7ba3Schristos ATF_TC_HEAD(create_long_name, tc)
68d3ba7ba3Schristos {
69d3ba7ba3Schristos
70d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
71d3ba7ba3Schristos "Checks memfd_create fails for names longer than NAME_MAX-6");
72d3ba7ba3Schristos }
ATF_TC_BODY(create_long_name,tc)73d3ba7ba3Schristos ATF_TC_BODY(create_long_name, tc)
74d3ba7ba3Schristos {
75d3ba7ba3Schristos int fd;
76d3ba7ba3Schristos
77d3ba7ba3Schristos memset(name_buf, 'A', sizeof(name_buf));
78d3ba7ba3Schristos name_buf[NAME_MAX-6] = '\0';
79d3ba7ba3Schristos
80d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(fd = memfd_create(name_buf, 0), -1,
81d3ba7ba3Schristos "Unexpected success");
82d3ba7ba3Schristos ATF_REQUIRE_ERRNO(ENAMETOOLONG, true);
83d3ba7ba3Schristos
84d3ba7ba3Schristos name_buf[NAME_MAX-7] = '\0';
85d3ba7ba3Schristos
86d3ba7ba3Schristos RL(fd = memfd_create(name_buf, 0));
87d3ba7ba3Schristos }
88d3ba7ba3Schristos
89d3ba7ba3Schristos ATF_TC(read_write);
ATF_TC_HEAD(read_write,tc)90d3ba7ba3Schristos ATF_TC_HEAD(read_write, tc)
91d3ba7ba3Schristos {
92d3ba7ba3Schristos
93d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
94d3ba7ba3Schristos "Checks that data can be written to/read from a memfd");
95d3ba7ba3Schristos }
ATF_TC_BODY(read_write,tc)96d3ba7ba3Schristos ATF_TC_BODY(read_write, tc)
97d3ba7ba3Schristos {
98d3ba7ba3Schristos int fd;
99d3ba7ba3Schristos off_t offset;
100d3ba7ba3Schristos
101d3ba7ba3Schristos RL(fd = memfd_create("", 0));
102d3ba7ba3Schristos
103d3ba7ba3Schristos tests_makegarbage(write_buf, sizeof(write_buf));
104d3ba7ba3Schristos memset(read_buf, 0, sizeof(read_buf));
105d3ba7ba3Schristos
106d3ba7ba3Schristos RL(write(fd, write_buf, sizeof(write_buf)));
107d3ba7ba3Schristos offset = lseek(fd, 0, SEEK_CUR);
108d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(offset, sizeof(write_buf),
109123e0529Srin "File offset not set after write (%jd != %zu)", (intmax_t)offset,
110d3ba7ba3Schristos sizeof(write_buf));
111d3ba7ba3Schristos
112*ef23f679Sriastradh RL(lseek(fd, 0, SEEK_SET));
113d3ba7ba3Schristos
114d3ba7ba3Schristos RL(read(fd, read_buf, sizeof(read_buf)));
115d3ba7ba3Schristos offset = lseek(fd, 0, SEEK_CUR);
116d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(offset, sizeof(read_buf),
117123e0529Srin "File offset not set after read (%jd != %zu)", (intmax_t)offset,
118d3ba7ba3Schristos sizeof(read_buf));
119d3ba7ba3Schristos
120d3ba7ba3Schristos for (size_t i = 0; i < sizeof(read_buf); i++)
121d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(read_buf[i], write_buf[i],
122d3ba7ba3Schristos "Data read does not match data written");
123d3ba7ba3Schristos }
124d3ba7ba3Schristos
125d3ba7ba3Schristos ATF_TC(truncate);
ATF_TC_HEAD(truncate,tc)126d3ba7ba3Schristos ATF_TC_HEAD(truncate, tc)
127d3ba7ba3Schristos {
128d3ba7ba3Schristos
129d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
130d3ba7ba3Schristos "Checks that truncation does result in data removal");
131d3ba7ba3Schristos }
ATF_TC_BODY(truncate,tc)132d3ba7ba3Schristos ATF_TC_BODY(truncate, tc)
133d3ba7ba3Schristos {
134d3ba7ba3Schristos int fd;
135d3ba7ba3Schristos struct stat st;
136d3ba7ba3Schristos
137d3ba7ba3Schristos RL(fd = memfd_create("", 0));
138d3ba7ba3Schristos
139d3ba7ba3Schristos tests_makegarbage(write_buf, sizeof(write_buf));
140d3ba7ba3Schristos tests_makegarbage(read_buf, sizeof(read_buf));
141d3ba7ba3Schristos
142d3ba7ba3Schristos RL(write(fd, write_buf, sizeof(write_buf)));
143d3ba7ba3Schristos
144d3ba7ba3Schristos RL(fstat(fd, &st));
145d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(st.st_size, sizeof(write_buf),
146123e0529Srin "Write did not grow size to %zu (is %jd)", sizeof(write_buf),
147123e0529Srin (intmax_t)st.st_size);
148d3ba7ba3Schristos
149d3ba7ba3Schristos RL(ftruncate(fd, sizeof(write_buf)/2));
150d3ba7ba3Schristos RL(fstat(fd, &st));
151d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(st.st_size, sizeof(write_buf)/2,
152123e0529Srin "Truncate did not shrink size to %zu (is %jd)",
153123e0529Srin sizeof(write_buf)/2, (intmax_t)st.st_size);
154d3ba7ba3Schristos
155d3ba7ba3Schristos RL(ftruncate(fd, sizeof(read_buf)));
156d3ba7ba3Schristos RL(fstat(fd, &st));
157d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(st.st_size, sizeof(read_buf),
158123e0529Srin "Truncate did not grow size to %zu (is %jd)", sizeof(read_buf),
159123e0529Srin (intmax_t)st.st_size);
160d3ba7ba3Schristos
161*ef23f679Sriastradh RL(lseek(fd, 0, SEEK_SET));
162d3ba7ba3Schristos RL(read(fd, read_buf, sizeof(read_buf)));
163d3ba7ba3Schristos
164d3ba7ba3Schristos for (size_t i = 0; i < sizeof(read_buf)/2; i++)
165d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(read_buf[i], write_buf[i],
166d3ba7ba3Schristos "Data read does not match data written");
167d3ba7ba3Schristos for (size_t i = sizeof(read_buf)/2; i < sizeof(read_buf); i++)
168d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(read_buf[i], 0,
169d3ba7ba3Schristos "Data read on growed region is not zeroed");
170d3ba7ba3Schristos }
171d3ba7ba3Schristos
172d3ba7ba3Schristos ATF_TC(mmap);
ATF_TC_HEAD(mmap,tc)173d3ba7ba3Schristos ATF_TC_HEAD(mmap, tc)
174d3ba7ba3Schristos {
175d3ba7ba3Schristos
176d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr", "Check that mmap succeeds");
177d3ba7ba3Schristos }
ATF_TC_BODY(mmap,tc)178d3ba7ba3Schristos ATF_TC_BODY(mmap, tc)
179d3ba7ba3Schristos {
180d3ba7ba3Schristos int fd;
181d3ba7ba3Schristos void *addr;
182d3ba7ba3Schristos
183d3ba7ba3Schristos RL(fd = memfd_create("", 0));
184d3ba7ba3Schristos RL(ftruncate(fd, sizeof(read_buf)));
185d3ba7ba3Schristos
186d3ba7ba3Schristos addr = mmap(NULL, sizeof(read_buf), PROT_READ|PROT_WRITE, MAP_SHARED,
187d3ba7ba3Schristos fd, 0);
188d3ba7ba3Schristos ATF_REQUIRE_MSG(addr != MAP_FAILED, "Mmap failed unexpectedly (%s)",
189d3ba7ba3Schristos strerror(errno));
190d3ba7ba3Schristos }
191d3ba7ba3Schristos
192d3ba7ba3Schristos ATF_TC(create_no_sealing);
ATF_TC_HEAD(create_no_sealing,tc)193d3ba7ba3Schristos ATF_TC_HEAD(create_no_sealing, tc)
194d3ba7ba3Schristos {
195d3ba7ba3Schristos
196d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
197d3ba7ba3Schristos "Checks that seals cannot be added if MFD_ALLOW_SEALING is"
198d3ba7ba3Schristos " not specified to memfd_create");
199d3ba7ba3Schristos }
ATF_TC_BODY(create_no_sealing,tc)200d3ba7ba3Schristos ATF_TC_BODY(create_no_sealing, tc)
201d3ba7ba3Schristos {
202d3ba7ba3Schristos int fd;
203d3ba7ba3Schristos
204d3ba7ba3Schristos RL(fd = memfd_create("", 0));
205d3ba7ba3Schristos
206d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(fcntl(fd, F_ADD_SEALS, F_SEAL_WRITE), -1,
207d3ba7ba3Schristos "fcntl succeeded unexpectedly");
208d3ba7ba3Schristos ATF_REQUIRE_ERRNO(EPERM, true);
209d3ba7ba3Schristos }
210d3ba7ba3Schristos
211d3ba7ba3Schristos ATF_TC(seal_seal);
ATF_TC_HEAD(seal_seal,tc)212d3ba7ba3Schristos ATF_TC_HEAD(seal_seal, tc)
213d3ba7ba3Schristos {
214d3ba7ba3Schristos
215d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
216d3ba7ba3Schristos "Checks adding F_SEAL_SEAL prevents adding other seals");
217d3ba7ba3Schristos }
ATF_TC_BODY(seal_seal,tc)218d3ba7ba3Schristos ATF_TC_BODY(seal_seal, tc)
219d3ba7ba3Schristos {
220d3ba7ba3Schristos int fd;
221d3ba7ba3Schristos
222d3ba7ba3Schristos RL(fd = memfd_create("", MFD_ALLOW_SEALING));
223d3ba7ba3Schristos RL(fcntl(fd, F_ADD_SEALS, F_SEAL_SEAL));
224d3ba7ba3Schristos
225d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(fcntl(fd, F_ADD_SEALS, F_SEAL_WRITE), -1,
226d3ba7ba3Schristos "fcntl succeeded unexpectedly");
227d3ba7ba3Schristos ATF_REQUIRE_ERRNO(EPERM, true);
228d3ba7ba3Schristos }
229d3ba7ba3Schristos
230d3ba7ba3Schristos /*
231d3ba7ba3Schristos * Tests that the seals provided in except to not also prevent some
232d3ba7ba3Schristos * other operation.
233d3ba7ba3Schristos *
234d3ba7ba3Schristos * Note: fd must have a positive size.
235d3ba7ba3Schristos */
236d3ba7ba3Schristos static void
test_all_seals_except(int fd,int except)237d3ba7ba3Schristos test_all_seals_except(int fd, int except)
238d3ba7ba3Schristos {
239d3ba7ba3Schristos int rv;
240d3ba7ba3Schristos struct stat st;
241d3ba7ba3Schristos void *addr;
242d3ba7ba3Schristos
243d3ba7ba3Schristos RL(fstat(fd, &st));
244d3ba7ba3Schristos ATF_REQUIRE(st.st_size > 0);
245d3ba7ba3Schristos
246d3ba7ba3Schristos if (except & ~F_SEAL_SEAL) {
247d3ba7ba3Schristos rv = fcntl(fd, F_ADD_SEALS, F_SEAL_SEAL);
248d3ba7ba3Schristos if (rv == -1) {
249d3ba7ba3Schristos ATF_REQUIRE_MSG(errno != EPERM,
250d3ba7ba3Schristos "Seal %x prevented F_ADD_SEALS", except);
251d3ba7ba3Schristos ATF_REQUIRE_MSG(errno == EPERM,
252d3ba7ba3Schristos "F_ADD_SEALS failed unexpectedly (%s)",
253d3ba7ba3Schristos strerror(errno));
254d3ba7ba3Schristos }
255d3ba7ba3Schristos }
256d3ba7ba3Schristos
257d3ba7ba3Schristos if (except & ~(F_SEAL_WRITE|F_SEAL_FUTURE_WRITE)) {
258*ef23f679Sriastradh RL(lseek(fd, 0, SEEK_SET));
259d3ba7ba3Schristos rv = write(fd, write_buf, sizeof(write_buf));
260d3ba7ba3Schristos if (rv == -1) {
261d3ba7ba3Schristos ATF_REQUIRE_MSG(errno != EPERM,
262d3ba7ba3Schristos "Seal %x prevented write", except);
263d3ba7ba3Schristos ATF_REQUIRE_MSG(errno == EPERM,
264d3ba7ba3Schristos "Write failed unexpectedly (%s)",
265d3ba7ba3Schristos strerror(errno));
266d3ba7ba3Schristos }
267d3ba7ba3Schristos
268d3ba7ba3Schristos addr = mmap(NULL, st.st_size, PROT_READ|PROT_WRITE,
269d3ba7ba3Schristos MAP_SHARED, fd, 0);
270d3ba7ba3Schristos ATF_REQUIRE_MSG(addr != MAP_FAILED,
271d3ba7ba3Schristos "Mmap failed unexpectedly (%s)", strerror(errno));
272d3ba7ba3Schristos }
273d3ba7ba3Schristos
274d3ba7ba3Schristos if (except & ~F_SEAL_SHRINK) {
275d3ba7ba3Schristos rv = ftruncate(fd, st.st_size - 1);
276d3ba7ba3Schristos if (rv == -1) {
277d3ba7ba3Schristos ATF_REQUIRE_MSG(errno != EPERM,
278d3ba7ba3Schristos "Seal %x prevented truncate to shrink", except);
279d3ba7ba3Schristos ATF_REQUIRE_MSG(errno == EPERM,
280d3ba7ba3Schristos "Truncate failed unexpectedly (%s)",
281d3ba7ba3Schristos strerror(errno));
282d3ba7ba3Schristos }
283d3ba7ba3Schristos }
284d3ba7ba3Schristos
285d3ba7ba3Schristos if (except & ~F_SEAL_GROW) {
286d3ba7ba3Schristos rv = ftruncate(fd, st.st_size + 1);
287d3ba7ba3Schristos if (rv == -1) {
288d3ba7ba3Schristos ATF_REQUIRE_MSG(errno != EPERM,
289d3ba7ba3Schristos "Seal %x prevented truncate to shrink", except);
290d3ba7ba3Schristos ATF_REQUIRE_MSG(errno == EPERM,
291d3ba7ba3Schristos "Truncate failed unexpectedly (%s)",
292d3ba7ba3Schristos strerror(errno));
293d3ba7ba3Schristos }
294d3ba7ba3Schristos }
295d3ba7ba3Schristos }
296d3ba7ba3Schristos
297d3ba7ba3Schristos ATF_TC(seal_shrink);
ATF_TC_HEAD(seal_shrink,tc)298d3ba7ba3Schristos ATF_TC_HEAD(seal_shrink, tc)
299d3ba7ba3Schristos {
300d3ba7ba3Schristos
301d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
302d3ba7ba3Schristos "Checks F_SEAL_SHRINK prevents shrinking the file");
303d3ba7ba3Schristos }
ATF_TC_BODY(seal_shrink,tc)304d3ba7ba3Schristos ATF_TC_BODY(seal_shrink, tc)
305d3ba7ba3Schristos {
306d3ba7ba3Schristos int fd;
307d3ba7ba3Schristos
308d3ba7ba3Schristos RL(fd = memfd_create("", MFD_ALLOW_SEALING));
309d3ba7ba3Schristos RL(ftruncate(fd, sizeof(write_buf)));
310d3ba7ba3Schristos RL(fcntl(fd, F_ADD_SEALS, F_SEAL_SHRINK));
311d3ba7ba3Schristos
312d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(ftruncate(fd, sizeof(write_buf)/2), -1,
313d3ba7ba3Schristos "Truncate succeeded unexpectedly");
314d3ba7ba3Schristos ATF_REQUIRE_ERRNO(EPERM, true);
315d3ba7ba3Schristos
316d3ba7ba3Schristos test_all_seals_except(fd, F_SEAL_SHRINK);
317d3ba7ba3Schristos }
318d3ba7ba3Schristos
319d3ba7ba3Schristos ATF_TC(seal_grow);
ATF_TC_HEAD(seal_grow,tc)320d3ba7ba3Schristos ATF_TC_HEAD(seal_grow, tc)
321d3ba7ba3Schristos {
322d3ba7ba3Schristos
323d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
324d3ba7ba3Schristos "Checks F_SEAL_SHRINK prevents growing the file");
325d3ba7ba3Schristos }
ATF_TC_BODY(seal_grow,tc)326d3ba7ba3Schristos ATF_TC_BODY(seal_grow, tc)
327d3ba7ba3Schristos {
328d3ba7ba3Schristos int fd;
329d3ba7ba3Schristos
330d3ba7ba3Schristos RL(fd = memfd_create("", MFD_ALLOW_SEALING));
331d3ba7ba3Schristos RL(ftruncate(fd, sizeof(write_buf)/2));
332d3ba7ba3Schristos RL(fcntl(fd, F_ADD_SEALS, F_SEAL_GROW));
333d3ba7ba3Schristos
334d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(ftruncate(fd, sizeof(write_buf)), -1,
335d3ba7ba3Schristos "Truncate succeeded unexpectedly");
336d3ba7ba3Schristos ATF_REQUIRE_ERRNO(EPERM, true);
337d3ba7ba3Schristos
338d3ba7ba3Schristos test_all_seals_except(fd, F_SEAL_GROW);
339d3ba7ba3Schristos }
340d3ba7ba3Schristos
341d3ba7ba3Schristos ATF_TC(seal_write);
ATF_TC_HEAD(seal_write,tc)342d3ba7ba3Schristos ATF_TC_HEAD(seal_write, tc)
343d3ba7ba3Schristos {
344d3ba7ba3Schristos
345d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
346d3ba7ba3Schristos "Checks F_SEAL_WRITE prevents writing");
347d3ba7ba3Schristos }
ATF_TC_BODY(seal_write,tc)348d3ba7ba3Schristos ATF_TC_BODY(seal_write, tc)
349d3ba7ba3Schristos {
350d3ba7ba3Schristos int fd;
351d3ba7ba3Schristos
352d3ba7ba3Schristos RL(fd = memfd_create("", MFD_ALLOW_SEALING));
353d3ba7ba3Schristos RL(ftruncate(fd, sizeof(write_buf)/2));
354d3ba7ba3Schristos RL(fcntl(fd, F_ADD_SEALS, F_SEAL_WRITE));
355d3ba7ba3Schristos
356d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(write(fd, write_buf, sizeof(write_buf)), -1,
357d3ba7ba3Schristos "Write succeeded unexpectedly");
358d3ba7ba3Schristos ATF_REQUIRE_ERRNO(EPERM, true);
359d3ba7ba3Schristos
360d3ba7ba3Schristos test_all_seals_except(fd, F_SEAL_WRITE);
361d3ba7ba3Schristos }
362d3ba7ba3Schristos
363d3ba7ba3Schristos ATF_TC(seal_write_mmap);
ATF_TC_HEAD(seal_write_mmap,tc)364d3ba7ba3Schristos ATF_TC_HEAD(seal_write_mmap, tc)
365d3ba7ba3Schristos {
366d3ba7ba3Schristos
367d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
368d3ba7ba3Schristos "Checks that F_SEAL_WRITE cannot be added with open mmaps");
369d3ba7ba3Schristos }
ATF_TC_BODY(seal_write_mmap,tc)370d3ba7ba3Schristos ATF_TC_BODY(seal_write_mmap, tc)
371d3ba7ba3Schristos {
372d3ba7ba3Schristos int fd;
373d3ba7ba3Schristos void *addr;
374d3ba7ba3Schristos
375d3ba7ba3Schristos RL(fd = memfd_create("", MFD_ALLOW_SEALING));
376d3ba7ba3Schristos RL(ftruncate(fd, sizeof(read_buf)));
377d3ba7ba3Schristos
378d3ba7ba3Schristos addr = mmap(NULL, sizeof(read_buf), PROT_READ|PROT_WRITE, MAP_SHARED,
379d3ba7ba3Schristos fd, 0);
380d3ba7ba3Schristos ATF_REQUIRE_MSG(addr != MAP_FAILED, "Mmap failed unexpectedly (%s)",
381d3ba7ba3Schristos strerror(errno));
382d3ba7ba3Schristos
383d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(fcntl(fd, F_ADD_SEALS, F_SEAL_WRITE), -1,
384d3ba7ba3Schristos "fcntl succeeded unexpectedly");
385d3ba7ba3Schristos ATF_REQUIRE_ERRNO(EBUSY, true);
386d3ba7ba3Schristos }
387d3ba7ba3Schristos
388d3ba7ba3Schristos ATF_TC(seal_future_write);
ATF_TC_HEAD(seal_future_write,tc)389d3ba7ba3Schristos ATF_TC_HEAD(seal_future_write, tc)
390d3ba7ba3Schristos {
391d3ba7ba3Schristos
392d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
393d3ba7ba3Schristos "Checks F_SEAL_FUTURE_WRITE prevents writing");
394d3ba7ba3Schristos }
ATF_TC_BODY(seal_future_write,tc)395d3ba7ba3Schristos ATF_TC_BODY(seal_future_write, tc)
396d3ba7ba3Schristos {
397d3ba7ba3Schristos int fd;
398d3ba7ba3Schristos
399d3ba7ba3Schristos RL(fd = memfd_create("", MFD_ALLOW_SEALING));
400d3ba7ba3Schristos RL(ftruncate(fd, sizeof(write_buf)/2));
401d3ba7ba3Schristos RL(fcntl(fd, F_ADD_SEALS, F_SEAL_FUTURE_WRITE));
402d3ba7ba3Schristos
403d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(write(fd, write_buf, sizeof(write_buf)), -1,
404d3ba7ba3Schristos "Write succeeded unexpectedly");
405d3ba7ba3Schristos ATF_REQUIRE_ERRNO(EPERM, true);
406d3ba7ba3Schristos
407d3ba7ba3Schristos test_all_seals_except(fd, F_SEAL_FUTURE_WRITE);
408d3ba7ba3Schristos }
409d3ba7ba3Schristos
410d3ba7ba3Schristos ATF_TC(seal_future_write_mmap);
ATF_TC_HEAD(seal_future_write_mmap,tc)411d3ba7ba3Schristos ATF_TC_HEAD(seal_future_write_mmap, tc)
412d3ba7ba3Schristos {
413d3ba7ba3Schristos
414d3ba7ba3Schristos atf_tc_set_md_var(tc, "descr",
415d3ba7ba3Schristos "Checks that F_SEAL_WRITE can be added with open mmaps but"
416d3ba7ba3Schristos " prevents creating new ones");
417d3ba7ba3Schristos }
ATF_TC_BODY(seal_future_write_mmap,tc)418d3ba7ba3Schristos ATF_TC_BODY(seal_future_write_mmap, tc)
419d3ba7ba3Schristos {
420d3ba7ba3Schristos int fd;
421d3ba7ba3Schristos void *addr;
422d3ba7ba3Schristos
423d3ba7ba3Schristos RL(fd = memfd_create("", MFD_ALLOW_SEALING));
424d3ba7ba3Schristos RL(ftruncate(fd, sizeof(read_buf)));
425d3ba7ba3Schristos addr = mmap(NULL, sizeof(read_buf), PROT_READ|PROT_WRITE, MAP_SHARED,
426d3ba7ba3Schristos fd, 0);
427d3ba7ba3Schristos ATF_REQUIRE_MSG(addr != MAP_FAILED, "Mmap failed unexpectedly (%s)",
428d3ba7ba3Schristos strerror(errno));
429d3ba7ba3Schristos
430d3ba7ba3Schristos RL(fcntl(fd, F_ADD_SEALS, F_SEAL_FUTURE_WRITE));
431d3ba7ba3Schristos
432d3ba7ba3Schristos ATF_REQUIRE_EQ_MSG(mmap(NULL, sizeof(read_buf), PROT_READ|PROT_WRITE,
433d3ba7ba3Schristos MAP_SHARED, fd, 0), MAP_FAILED, "Mmap succeeded unexpectedly");
434d3ba7ba3Schristos ATF_REQUIRE_ERRNO(EPERM, true);
435d3ba7ba3Schristos }
436d3ba7ba3Schristos
437d3ba7ba3Schristos
ATF_TP_ADD_TCS(tp)438d3ba7ba3Schristos ATF_TP_ADD_TCS(tp)
439d3ba7ba3Schristos {
440d3ba7ba3Schristos ATF_TP_ADD_TC(tp, create_null_name);
441d3ba7ba3Schristos ATF_TP_ADD_TC(tp, create_long_name);
442d3ba7ba3Schristos ATF_TP_ADD_TC(tp, read_write);
443d3ba7ba3Schristos ATF_TP_ADD_TC(tp, truncate);
444d3ba7ba3Schristos ATF_TP_ADD_TC(tp, mmap);
445d3ba7ba3Schristos ATF_TP_ADD_TC(tp, create_no_sealing);
446d3ba7ba3Schristos ATF_TP_ADD_TC(tp, seal_seal);
447d3ba7ba3Schristos ATF_TP_ADD_TC(tp, seal_shrink);
448d3ba7ba3Schristos ATF_TP_ADD_TC(tp, seal_grow);
449d3ba7ba3Schristos ATF_TP_ADD_TC(tp, seal_write);
450d3ba7ba3Schristos ATF_TP_ADD_TC(tp, seal_write_mmap);
451d3ba7ba3Schristos ATF_TP_ADD_TC(tp, seal_future_write);
452d3ba7ba3Schristos ATF_TP_ADD_TC(tp, seal_future_write_mmap);
453d3ba7ba3Schristos
454d3ba7ba3Schristos return atf_no_error();
455d3ba7ba3Schristos }
456