1*57718be8SEnji Cooper /* $NetBSD: t_o_search.c,v 1.4 2013/03/17 04:46:06 jmmv Exp $ */ 2*57718be8SEnji Cooper 3*57718be8SEnji Cooper /*- 4*57718be8SEnji Cooper * Copyright (c) 2012 The NetBSD Foundation, Inc. 5*57718be8SEnji Cooper * All rights reserved. 6*57718be8SEnji Cooper * 7*57718be8SEnji Cooper * This code is derived from software contributed to The NetBSD Foundation 8*57718be8SEnji Cooper * by Emmanuel Dreyfus. 9*57718be8SEnji Cooper * 10*57718be8SEnji Cooper * Redistribution and use in source and binary forms, with or without 11*57718be8SEnji Cooper * modification, are permitted provided that the following conditions 12*57718be8SEnji Cooper * are met: 13*57718be8SEnji Cooper * 1. Redistributions of source code must retain the above copyright 14*57718be8SEnji Cooper * notice, this list of conditions and the following disclaimer. 15*57718be8SEnji Cooper * 2. Redistributions in binary form must reproduce the above copyright 16*57718be8SEnji Cooper * notice, this list of conditions and the following disclaimer in the 17*57718be8SEnji Cooper * documentation and/or other materials provided with the distribution. 18*57718be8SEnji Cooper * 19*57718be8SEnji Cooper * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS 20*57718be8SEnji Cooper * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED 21*57718be8SEnji Cooper * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 22*57718be8SEnji Cooper * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS 23*57718be8SEnji Cooper * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 24*57718be8SEnji Cooper * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 25*57718be8SEnji Cooper * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 26*57718be8SEnji Cooper * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 27*57718be8SEnji Cooper * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 28*57718be8SEnji Cooper * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 29*57718be8SEnji Cooper * POSSIBILITY OF SUCH DAMAGE. 30*57718be8SEnji Cooper */ 31*57718be8SEnji Cooper #include <sys/cdefs.h> 32*57718be8SEnji Cooper __RCSID("$NetBSD: t_o_search.c,v 1.4 2013/03/17 04:46:06 jmmv Exp $"); 33*57718be8SEnji Cooper 34*57718be8SEnji Cooper #include <atf-c.h> 35*57718be8SEnji Cooper #include <errno.h> 36*57718be8SEnji Cooper #include <fcntl.h> 37*57718be8SEnji Cooper #include <limits.h> 38*57718be8SEnji Cooper #include <paths.h> 39*57718be8SEnji Cooper #include <stdio.h> 40*57718be8SEnji Cooper #include <string.h> 41*57718be8SEnji Cooper #include <unistd.h> 42*57718be8SEnji Cooper #include <pwd.h> 43*57718be8SEnji Cooper #include <sys/param.h> 44*57718be8SEnji Cooper 45*57718be8SEnji Cooper /* 46*57718be8SEnji Cooper * dholland 20130112: disable tests that require O_SEARCH semantics 47*57718be8SEnji Cooper * until a decision is reached about the semantics of O_SEARCH and a 48*57718be8SEnji Cooper * non-broken implementation is available. 49*57718be8SEnji Cooper */ 50*57718be8SEnji Cooper #if (O_MASK & O_SEARCH) != 0 51*57718be8SEnji Cooper #define USE_O_SEARCH 52*57718be8SEnji Cooper #endif 53*57718be8SEnji Cooper 54*57718be8SEnji Cooper #define DIR "dir" 55*57718be8SEnji Cooper #define FILE "dir/o_search" 56*57718be8SEnji Cooper #define BASEFILE "o_search" 57*57718be8SEnji Cooper 58*57718be8SEnji Cooper 59*57718be8SEnji Cooper ATF_TC(o_search_perm1); 60*57718be8SEnji Cooper ATF_TC_HEAD(o_search_perm1, tc) 61*57718be8SEnji Cooper { 62*57718be8SEnji Cooper atf_tc_set_md_var(tc, "descr", "See that openat enforces search permission"); 63*57718be8SEnji Cooper atf_tc_set_md_var(tc, "require.user", "unprivileged"); 64*57718be8SEnji Cooper } 65*57718be8SEnji Cooper ATF_TC_BODY(o_search_perm1, tc) 66*57718be8SEnji Cooper { 67*57718be8SEnji Cooper int dfd; 68*57718be8SEnji Cooper int fd; 69*57718be8SEnji Cooper 70*57718be8SEnji Cooper ATF_REQUIRE(mkdir(DIR, 0755) == 0); 71*57718be8SEnji Cooper ATF_REQUIRE((fd = open(FILE, O_CREAT|O_RDWR, 0644)) != -1); 72*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 73*57718be8SEnji Cooper 74*57718be8SEnji Cooper ATF_REQUIRE((dfd = open(DIR, O_RDONLY, 0)) != -1); 75*57718be8SEnji Cooper 76*57718be8SEnji Cooper ATF_REQUIRE((fd = openat(dfd, BASEFILE, O_RDWR, 0)) != -1); 77*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 78*57718be8SEnji Cooper 79*57718be8SEnji Cooper ATF_REQUIRE(fchmod(dfd, 644) == 0); 80*57718be8SEnji Cooper 81*57718be8SEnji Cooper ATF_REQUIRE((fd = openat(dfd, BASEFILE, O_RDWR, 0)) == -1); 82*57718be8SEnji Cooper ATF_REQUIRE(errno == EACCES); 83*57718be8SEnji Cooper 84*57718be8SEnji Cooper ATF_REQUIRE(close(dfd) == 0); 85*57718be8SEnji Cooper } 86*57718be8SEnji Cooper 87*57718be8SEnji Cooper #ifdef USE_O_SEARCH 88*57718be8SEnji Cooper 89*57718be8SEnji Cooper ATF_TC(o_search_root_flag1); 90*57718be8SEnji Cooper ATF_TC_HEAD(o_search_root_flag1, tc) 91*57718be8SEnji Cooper { 92*57718be8SEnji Cooper atf_tc_set_md_var(tc, "descr", "See that root openat honours O_SEARCH"); 93*57718be8SEnji Cooper atf_tc_set_md_var(tc, "require.user", "root"); 94*57718be8SEnji Cooper } 95*57718be8SEnji Cooper ATF_TC_BODY(o_search_root_flag1, tc) 96*57718be8SEnji Cooper { 97*57718be8SEnji Cooper int dfd; 98*57718be8SEnji Cooper int fd; 99*57718be8SEnji Cooper 100*57718be8SEnji Cooper ATF_REQUIRE(mkdir(DIR, 0755) == 0); 101*57718be8SEnji Cooper ATF_REQUIRE((fd = open(FILE, O_CREAT|O_RDWR, 0644)) != -1); 102*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 103*57718be8SEnji Cooper 104*57718be8SEnji Cooper ATF_REQUIRE((dfd = open(DIR, O_RDONLY|O_SEARCH, 0)) != -1); 105*57718be8SEnji Cooper 106*57718be8SEnji Cooper ATF_REQUIRE((fd = openat(dfd, BASEFILE, O_RDWR, 0)) != -1); 107*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 108*57718be8SEnji Cooper 109*57718be8SEnji Cooper ATF_REQUIRE(fchmod(dfd, 644) == 0); 110*57718be8SEnji Cooper 111*57718be8SEnji Cooper ATF_REQUIRE((fd = openat(dfd, BASEFILE, O_RDWR, 0)) != -1); 112*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 113*57718be8SEnji Cooper 114*57718be8SEnji Cooper ATF_REQUIRE(fchmod(dfd, 444) == 0); 115*57718be8SEnji Cooper 116*57718be8SEnji Cooper ATF_REQUIRE((fd = openat(dfd, BASEFILE, O_RDWR, 0)) != -1); 117*57718be8SEnji Cooper 118*57718be8SEnji Cooper ATF_REQUIRE(close(dfd) == 0); 119*57718be8SEnji Cooper } 120*57718be8SEnji Cooper 121*57718be8SEnji Cooper ATF_TC(o_search_unpriv_flag1); 122*57718be8SEnji Cooper ATF_TC_HEAD(o_search_unpriv_flag1, tc) 123*57718be8SEnji Cooper { 124*57718be8SEnji Cooper atf_tc_set_md_var(tc, "descr", "See that openat honours O_SEARCH"); 125*57718be8SEnji Cooper atf_tc_set_md_var(tc, "require.user", "unprivileged"); 126*57718be8SEnji Cooper } 127*57718be8SEnji Cooper ATF_TC_BODY(o_search_unpriv_flag1, tc) 128*57718be8SEnji Cooper { 129*57718be8SEnji Cooper int dfd; 130*57718be8SEnji Cooper int fd; 131*57718be8SEnji Cooper 132*57718be8SEnji Cooper ATF_REQUIRE(mkdir(DIR, 0755) == 0); 133*57718be8SEnji Cooper ATF_REQUIRE((fd = open(FILE, O_CREAT|O_RDWR, 0644)) != -1); 134*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 135*57718be8SEnji Cooper 136*57718be8SEnji Cooper ATF_REQUIRE((dfd = open(DIR, O_RDONLY|O_SEARCH, 0)) != -1); 137*57718be8SEnji Cooper 138*57718be8SEnji Cooper ATF_REQUIRE((fd = openat(dfd, BASEFILE, O_RDWR, 0)) != -1); 139*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 140*57718be8SEnji Cooper 141*57718be8SEnji Cooper ATF_REQUIRE(fchmod(dfd, 644) == 0); 142*57718be8SEnji Cooper 143*57718be8SEnji Cooper ATF_REQUIRE((fd = openat(dfd, BASEFILE, O_RDWR, 0)) != -1); 144*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 145*57718be8SEnji Cooper 146*57718be8SEnji Cooper ATF_REQUIRE(fchmod(dfd, 444) == 0); 147*57718be8SEnji Cooper 148*57718be8SEnji Cooper ATF_REQUIRE((fd = openat(dfd, BASEFILE, O_RDWR, 0)) != -1); 149*57718be8SEnji Cooper 150*57718be8SEnji Cooper ATF_REQUIRE(close(dfd) == 0); 151*57718be8SEnji Cooper } 152*57718be8SEnji Cooper 153*57718be8SEnji Cooper #endif /* USE_O_SEARCH */ 154*57718be8SEnji Cooper 155*57718be8SEnji Cooper ATF_TC(o_search_perm2); 156*57718be8SEnji Cooper ATF_TC_HEAD(o_search_perm2, tc) 157*57718be8SEnji Cooper { 158*57718be8SEnji Cooper atf_tc_set_md_var(tc, "descr", "See that faccessat enforces search permission"); 159*57718be8SEnji Cooper atf_tc_set_md_var(tc, "require.user", "unprivileged"); 160*57718be8SEnji Cooper } 161*57718be8SEnji Cooper ATF_TC_BODY(o_search_perm2, tc) 162*57718be8SEnji Cooper { 163*57718be8SEnji Cooper int dfd; 164*57718be8SEnji Cooper int fd; 165*57718be8SEnji Cooper ATF_REQUIRE(mkdir(DIR, 0755) == 0); 166*57718be8SEnji Cooper ATF_REQUIRE((fd = open(FILE, O_CREAT|O_RDWR, 0644)) != -1); 167*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 168*57718be8SEnji Cooper 169*57718be8SEnji Cooper ATF_REQUIRE((dfd = open(DIR, O_RDONLY, 0)) != -1); 170*57718be8SEnji Cooper 171*57718be8SEnji Cooper ATF_REQUIRE(faccessat(dfd, BASEFILE, W_OK, 0) == 0); 172*57718be8SEnji Cooper 173*57718be8SEnji Cooper ATF_REQUIRE(fchmod(dfd, 644) == 0); 174*57718be8SEnji Cooper 175*57718be8SEnji Cooper ATF_REQUIRE(faccessat(dfd, BASEFILE, W_OK, 0) == -1); 176*57718be8SEnji Cooper ATF_REQUIRE(errno == EACCES); 177*57718be8SEnji Cooper 178*57718be8SEnji Cooper ATF_REQUIRE(close(dfd) == 0); 179*57718be8SEnji Cooper } 180*57718be8SEnji Cooper 181*57718be8SEnji Cooper #ifdef USE_O_SEARCH 182*57718be8SEnji Cooper 183*57718be8SEnji Cooper ATF_TC(o_search_root_flag2); 184*57718be8SEnji Cooper ATF_TC_HEAD(o_search_root_flag2, tc) 185*57718be8SEnji Cooper { 186*57718be8SEnji Cooper atf_tc_set_md_var(tc, "descr", "See that root fstatat honours O_SEARCH"); 187*57718be8SEnji Cooper atf_tc_set_md_var(tc, "require.user", "root"); 188*57718be8SEnji Cooper } 189*57718be8SEnji Cooper ATF_TC_BODY(o_search_root_flag2, tc) 190*57718be8SEnji Cooper { 191*57718be8SEnji Cooper int dfd; 192*57718be8SEnji Cooper int fd; 193*57718be8SEnji Cooper 194*57718be8SEnji Cooper ATF_REQUIRE(mkdir(DIR, 0755) == 0); 195*57718be8SEnji Cooper ATF_REQUIRE((fd = open(FILE, O_CREAT|O_RDWR, 0644)) != -1); 196*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 197*57718be8SEnji Cooper 198*57718be8SEnji Cooper ATF_REQUIRE((dfd = open(DIR, O_RDONLY|O_SEARCH, 0)) != -1); 199*57718be8SEnji Cooper 200*57718be8SEnji Cooper ATF_REQUIRE(faccessat(dfd, BASEFILE, W_OK, 0) == 0); 201*57718be8SEnji Cooper 202*57718be8SEnji Cooper ATF_REQUIRE(fchmod(dfd, 644) == 0); 203*57718be8SEnji Cooper 204*57718be8SEnji Cooper ATF_REQUIRE(faccessat(dfd, BASEFILE, W_OK, 0) == 0); 205*57718be8SEnji Cooper 206*57718be8SEnji Cooper ATF_REQUIRE(fchmod(dfd, 444) == 0); 207*57718be8SEnji Cooper 208*57718be8SEnji Cooper ATF_REQUIRE(faccessat(dfd, BASEFILE, W_OK, 0) == 0); 209*57718be8SEnji Cooper 210*57718be8SEnji Cooper ATF_REQUIRE(close(dfd) == 0); 211*57718be8SEnji Cooper } 212*57718be8SEnji Cooper 213*57718be8SEnji Cooper ATF_TC(o_search_unpriv_flag2); 214*57718be8SEnji Cooper ATF_TC_HEAD(o_search_unpriv_flag2, tc) 215*57718be8SEnji Cooper { 216*57718be8SEnji Cooper atf_tc_set_md_var(tc, "descr", "See that fstatat honours O_SEARCH"); 217*57718be8SEnji Cooper atf_tc_set_md_var(tc, "require.user", "unprivileged"); 218*57718be8SEnji Cooper } 219*57718be8SEnji Cooper ATF_TC_BODY(o_search_unpriv_flag2, tc) 220*57718be8SEnji Cooper { 221*57718be8SEnji Cooper int dfd; 222*57718be8SEnji Cooper int fd; 223*57718be8SEnji Cooper 224*57718be8SEnji Cooper ATF_REQUIRE(mkdir(DIR, 0755) == 0); 225*57718be8SEnji Cooper ATF_REQUIRE((fd = open(FILE, O_CREAT|O_RDWR, 0644)) != -1); 226*57718be8SEnji Cooper ATF_REQUIRE(close(fd) == 0); 227*57718be8SEnji Cooper 228*57718be8SEnji Cooper ATF_REQUIRE((dfd = open(DIR, O_RDONLY|O_SEARCH, 0)) != -1); 229*57718be8SEnji Cooper 230*57718be8SEnji Cooper ATF_REQUIRE(faccessat(dfd, BASEFILE, W_OK, 0) == 0); 231*57718be8SEnji Cooper 232*57718be8SEnji Cooper ATF_REQUIRE(fchmod(dfd, 644) == 0); 233*57718be8SEnji Cooper 234*57718be8SEnji Cooper ATF_REQUIRE(faccessat(dfd, BASEFILE, W_OK, 0) == 0); 235*57718be8SEnji Cooper 236*57718be8SEnji Cooper ATF_REQUIRE(fchmod(dfd, 444) == 0); 237*57718be8SEnji Cooper 238*57718be8SEnji Cooper ATF_REQUIRE(faccessat(dfd, BASEFILE, W_OK, 0) == 0); 239*57718be8SEnji Cooper 240*57718be8SEnji Cooper ATF_REQUIRE(close(dfd) == 0); 241*57718be8SEnji Cooper } 242*57718be8SEnji Cooper 243*57718be8SEnji Cooper #endif /* USE_O_SEARCH */ 244*57718be8SEnji Cooper 245*57718be8SEnji Cooper 246*57718be8SEnji Cooper ATF_TC(o_search_notdir); 247*57718be8SEnji Cooper ATF_TC_HEAD(o_search_notdir, tc) 248*57718be8SEnji Cooper { 249*57718be8SEnji Cooper atf_tc_set_md_var(tc, "descr", "See that openat fails with non dir fd"); 250*57718be8SEnji Cooper } 251*57718be8SEnji Cooper ATF_TC_BODY(o_search_notdir, tc) 252*57718be8SEnji Cooper { 253*57718be8SEnji Cooper int dfd; 254*57718be8SEnji Cooper int fd; 255*57718be8SEnji Cooper 256*57718be8SEnji Cooper ATF_REQUIRE(mkdir(DIR, 0755) == 0); 257*57718be8SEnji Cooper ATF_REQUIRE((dfd = open(FILE, O_CREAT|O_RDWR|O_SEARCH, 0644)) != -1); 258*57718be8SEnji Cooper ATF_REQUIRE((fd = openat(dfd, BASEFILE, O_RDWR, 0)) == -1); 259*57718be8SEnji Cooper ATF_REQUIRE(errno == ENOTDIR); 260*57718be8SEnji Cooper } 261*57718be8SEnji Cooper 262*57718be8SEnji Cooper ATF_TP_ADD_TCS(tp) 263*57718be8SEnji Cooper { 264*57718be8SEnji Cooper 265*57718be8SEnji Cooper ATF_TP_ADD_TC(tp, o_search_perm1); 266*57718be8SEnji Cooper #ifdef USE_O_SEARCH 267*57718be8SEnji Cooper ATF_TP_ADD_TC(tp, o_search_root_flag1); 268*57718be8SEnji Cooper ATF_TP_ADD_TC(tp, o_search_unpriv_flag1); 269*57718be8SEnji Cooper #endif 270*57718be8SEnji Cooper ATF_TP_ADD_TC(tp, o_search_perm2); 271*57718be8SEnji Cooper #ifdef USE_O_SEARCH 272*57718be8SEnji Cooper ATF_TP_ADD_TC(tp, o_search_root_flag2); 273*57718be8SEnji Cooper ATF_TP_ADD_TC(tp, o_search_unpriv_flag2); 274*57718be8SEnji Cooper #endif 275*57718be8SEnji Cooper ATF_TP_ADD_TC(tp, o_search_notdir); 276*57718be8SEnji Cooper 277*57718be8SEnji Cooper return atf_no_error(); 278*57718be8SEnji Cooper } 279