1*49a6e16fSderaadt /* $OpenBSD: t_getgroups.c,v 1.3 2021/12/13 16:56:48 deraadt Exp $ */
2a545a52cSbluhm /* $NetBSD: t_getgroups.c,v 1.1 2011/07/07 06:57:53 jruoho Exp $ */
3a545a52cSbluhm
4a545a52cSbluhm /*-
5a545a52cSbluhm * Copyright (c) 2011 The NetBSD Foundation, Inc.
6a545a52cSbluhm * All rights reserved.
7a545a52cSbluhm *
8a545a52cSbluhm * This code is derived from software contributed to The NetBSD Foundation
9a545a52cSbluhm * by Jukka Ruohonen.
10a545a52cSbluhm *
11a545a52cSbluhm * Redistribution and use in source and binary forms, with or without
12a545a52cSbluhm * modification, are permitted provided that the following conditions
13a545a52cSbluhm * are met:
14a545a52cSbluhm * 1. Redistributions of source code must retain the above copyright
15a545a52cSbluhm * notice, this list of conditions and the following disclaimer.
16a545a52cSbluhm * 2. Redistributions in binary form must reproduce the above copyright
17a545a52cSbluhm * notice, this list of conditions and the following disclaimer in the
18a545a52cSbluhm * documentation and/or other materials provided with the distribution.
19a545a52cSbluhm *
20a545a52cSbluhm * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
21a545a52cSbluhm * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
22a545a52cSbluhm * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
23a545a52cSbluhm * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
24a545a52cSbluhm * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25a545a52cSbluhm * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26a545a52cSbluhm * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27a545a52cSbluhm * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28a545a52cSbluhm * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29a545a52cSbluhm * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
30a545a52cSbluhm * POSSIBILITY OF SUCH DAMAGE.
31a545a52cSbluhm */
32a545a52cSbluhm
33a545a52cSbluhm #include "macros.h"
34a545a52cSbluhm
35a545a52cSbluhm #include <sys/wait.h>
36a545a52cSbluhm
37a545a52cSbluhm #include "atf-c.h"
38a545a52cSbluhm #include <errno.h>
39a545a52cSbluhm #include <limits.h>
40a545a52cSbluhm #include <stdlib.h>
41a545a52cSbluhm #include <string.h>
42a545a52cSbluhm #include <unistd.h>
43a545a52cSbluhm
44a545a52cSbluhm ATF_TC(getgroups_err);
ATF_TC_HEAD(getgroups_err,tc)45a545a52cSbluhm ATF_TC_HEAD(getgroups_err, tc)
46a545a52cSbluhm {
47a545a52cSbluhm atf_tc_set_md_var(tc, "descr", "Test errors in getgroups(2)");
48a545a52cSbluhm }
49a545a52cSbluhm
ATF_TC_BODY(getgroups_err,tc)50a545a52cSbluhm ATF_TC_BODY(getgroups_err, tc)
51a545a52cSbluhm {
52a545a52cSbluhm gid_t gidset[NGROUPS_MAX];
53a545a52cSbluhm
54a545a52cSbluhm errno = 0;
55a545a52cSbluhm
567496d4e5Sbluhm #if __OpenBSD__
57a545a52cSbluhm ATF_REQUIRE(getgroups(NGROUPS_MAX, (gid_t *)-1) == -1);
587496d4e5Sbluhm #else
597496d4e5Sbluhm ATF_REQUIRE(getgroups(10, (gid_t *)-1) == -1);
607496d4e5Sbluhm #endif
61a545a52cSbluhm ATF_REQUIRE(errno == EFAULT);
62a545a52cSbluhm
63a545a52cSbluhm errno = 0;
64a545a52cSbluhm
65a545a52cSbluhm ATF_REQUIRE(getgroups(-1, gidset) == -1);
66a545a52cSbluhm ATF_REQUIRE(errno == EINVAL);
67a545a52cSbluhm }
68a545a52cSbluhm
69a545a52cSbluhm ATF_TC(getgroups_getgid);
ATF_TC_HEAD(getgroups_getgid,tc)70a545a52cSbluhm ATF_TC_HEAD(getgroups_getgid, tc)
71a545a52cSbluhm {
72a545a52cSbluhm atf_tc_set_md_var(tc, "descr", "Test getgid(2) from getgroups(2)");
73a545a52cSbluhm }
74a545a52cSbluhm
ATF_TC_BODY(getgroups_getgid,tc)75a545a52cSbluhm ATF_TC_BODY(getgroups_getgid, tc)
76a545a52cSbluhm {
77a545a52cSbluhm gid_t gidset[NGROUPS_MAX];
78a545a52cSbluhm gid_t gid = getgid();
79a545a52cSbluhm int i, n;
80a545a52cSbluhm
81a545a52cSbluhm /*
82a545a52cSbluhm * Check that getgid(2) is found from
83a545a52cSbluhm * the GIDs returned by getgroups(2).
84a545a52cSbluhm */
85a545a52cSbluhm n = getgroups(NGROUPS_MAX, gidset);
86a545a52cSbluhm
87a545a52cSbluhm for (i = 0; i < n; i++) {
88a545a52cSbluhm
89a545a52cSbluhm if (gidset[i] == gid)
90a545a52cSbluhm return;
91a545a52cSbluhm }
92a545a52cSbluhm
93a545a52cSbluhm atf_tc_fail("getgid(2) not found from getgroups(2)");
94a545a52cSbluhm }
95a545a52cSbluhm
96a545a52cSbluhm ATF_TC(getgroups_setgid);
ATF_TC_HEAD(getgroups_setgid,tc)97a545a52cSbluhm ATF_TC_HEAD(getgroups_setgid, tc)
98a545a52cSbluhm {
99a545a52cSbluhm atf_tc_set_md_var(tc, "descr", "Test setgid(2) from getgroups(2)");
100a545a52cSbluhm atf_tc_set_md_var(tc, "require.user", "root");
101a545a52cSbluhm }
102a545a52cSbluhm
ATF_TC_BODY(getgroups_setgid,tc)103a545a52cSbluhm ATF_TC_BODY(getgroups_setgid, tc)
104a545a52cSbluhm {
105a545a52cSbluhm gid_t gidset[NGROUPS_MAX];
106a545a52cSbluhm int i, n, rv, sta;
107a545a52cSbluhm pid_t pid;
108a545a52cSbluhm
109a545a52cSbluhm /*
110a545a52cSbluhm * Check that we can setgid(2)
111a545a52cSbluhm * to the returned group IDs.
112a545a52cSbluhm */
113a545a52cSbluhm n = getgroups(NGROUPS_MAX, gidset);
114a545a52cSbluhm ATF_REQUIRE(n >= 0);
115a545a52cSbluhm
116a545a52cSbluhm for (i = 0; i < n; i++) {
117a545a52cSbluhm
118a545a52cSbluhm pid = fork();
119a545a52cSbluhm ATF_REQUIRE(pid >= 0);
120a545a52cSbluhm
121a545a52cSbluhm if (pid == 0) {
122a545a52cSbluhm
123a545a52cSbluhm rv = setgid(gidset[i]);
124a545a52cSbluhm
125a545a52cSbluhm if (rv != 0)
126a545a52cSbluhm _exit(EXIT_FAILURE);
127a545a52cSbluhm
128a545a52cSbluhm _exit(EXIT_SUCCESS);
129a545a52cSbluhm }
130a545a52cSbluhm
131a545a52cSbluhm (void)wait(&sta);
132a545a52cSbluhm
133a545a52cSbluhm if (WIFEXITED(sta) == 0 || WEXITSTATUS(sta) != EXIT_SUCCESS)
134a545a52cSbluhm atf_tc_fail("getgroups(2) is inconsistent");
135a545a52cSbluhm }
136a545a52cSbluhm }
137a545a52cSbluhm
138a545a52cSbluhm ATF_TC(getgroups_zero);
ATF_TC_HEAD(getgroups_zero,tc)139a545a52cSbluhm ATF_TC_HEAD(getgroups_zero, tc)
140a545a52cSbluhm {
141a545a52cSbluhm atf_tc_set_md_var(tc, "descr", "Test getgroups(2) with zero param");
142a545a52cSbluhm }
143a545a52cSbluhm
ATF_TC_BODY(getgroups_zero,tc)144a545a52cSbluhm ATF_TC_BODY(getgroups_zero, tc)
145a545a52cSbluhm {
146a545a52cSbluhm const gid_t val = 123456789;
147a545a52cSbluhm gid_t gidset[NGROUPS_MAX];
148a545a52cSbluhm size_t i;
149a545a52cSbluhm
150a545a52cSbluhm /*
151a545a52cSbluhm * If the first parameter is zero, the number
152a545a52cSbluhm * of groups should be returned but the supplied
153a545a52cSbluhm * buffer should remain intact.
154a545a52cSbluhm */
155a545a52cSbluhm for (i = 0; i < __arraycount(gidset); i++)
156a545a52cSbluhm gidset[i] = val;
157a545a52cSbluhm
158a545a52cSbluhm ATF_REQUIRE(getgroups(0, gidset) >= 0);
159a545a52cSbluhm
160a545a52cSbluhm for (i = 0; i < __arraycount(gidset); i++) {
161a545a52cSbluhm
162a545a52cSbluhm if (gidset[i] != val)
163a545a52cSbluhm atf_tc_fail("getgroups(2) modified the buffer");
164a545a52cSbluhm }
165a545a52cSbluhm }
166a545a52cSbluhm
ATF_TP_ADD_TCS(tp)167a545a52cSbluhm ATF_TP_ADD_TCS(tp)
168a545a52cSbluhm {
169a545a52cSbluhm
170a545a52cSbluhm ATF_TP_ADD_TC(tp, getgroups_err);
171a545a52cSbluhm ATF_TP_ADD_TC(tp, getgroups_getgid);
172a545a52cSbluhm ATF_TP_ADD_TC(tp, getgroups_setgid);
173a545a52cSbluhm ATF_TP_ADD_TC(tp, getgroups_zero);
174a545a52cSbluhm
175a545a52cSbluhm return atf_no_error();
176a545a52cSbluhm }
177