1*49a6e16fSderaadt /* $OpenBSD: t_kill.c,v 1.4 2021/12/13 16:56:48 deraadt Exp $ */
2a545a52cSbluhm /* $NetBSD: t_kill.c,v 1.1 2011/07/07 06:57:53 jruoho Exp $ */
3a545a52cSbluhm
4a545a52cSbluhm /*-
5a545a52cSbluhm * Copyright (c) 2011 The NetBSD Foundation, Inc.
6a545a52cSbluhm * All rights reserved.
7a545a52cSbluhm *
8a545a52cSbluhm * This code is derived from software contributed to The NetBSD Foundation
9a545a52cSbluhm * by Jukka Ruohonen.
10a545a52cSbluhm *
11a545a52cSbluhm * Redistribution and use in source and binary forms, with or without
12a545a52cSbluhm * modification, are permitted provided that the following conditions
13a545a52cSbluhm * are met:
14a545a52cSbluhm * 1. Redistributions of source code must retain the above copyright
15a545a52cSbluhm * notice, this list of conditions and the following disclaimer.
16a545a52cSbluhm * 2. Redistributions in binary form must reproduce the above copyright
17a545a52cSbluhm * notice, this list of conditions and the following disclaimer in the
18a545a52cSbluhm * documentation and/or other materials provided with the distribution.
19a545a52cSbluhm *
20a545a52cSbluhm * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
21a545a52cSbluhm * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
22a545a52cSbluhm * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
23a545a52cSbluhm * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
24a545a52cSbluhm * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25a545a52cSbluhm * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26a545a52cSbluhm * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27a545a52cSbluhm * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28a545a52cSbluhm * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29a545a52cSbluhm * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
30a545a52cSbluhm * POSSIBILITY OF SUCH DAMAGE.
31a545a52cSbluhm */
32a545a52cSbluhm
33a545a52cSbluhm #include "macros.h"
34a545a52cSbluhm
35a545a52cSbluhm #include <sys/wait.h>
36a545a52cSbluhm
37a545a52cSbluhm #include <errno.h>
38a545a52cSbluhm #include <limits.h>
39a545a52cSbluhm #include <pwd.h>
40a545a52cSbluhm #include <signal.h>
41a545a52cSbluhm #include <stdlib.h>
42a545a52cSbluhm #include <unistd.h>
43a545a52cSbluhm
44a545a52cSbluhm #include "atf-c.h"
45a545a52cSbluhm
46a545a52cSbluhm ATF_TC(kill_basic);
ATF_TC_HEAD(kill_basic,tc)47a545a52cSbluhm ATF_TC_HEAD(kill_basic, tc)
48a545a52cSbluhm {
49a545a52cSbluhm atf_tc_set_md_var(tc, "descr", "Test that kill(2) works");
50a545a52cSbluhm }
51a545a52cSbluhm
ATF_TC_BODY(kill_basic,tc)52a545a52cSbluhm ATF_TC_BODY(kill_basic, tc)
53a545a52cSbluhm {
54a545a52cSbluhm const int sig[] = { SIGHUP, SIGINT, SIGKILL, SIGTERM };
55a545a52cSbluhm pid_t pid;
56a545a52cSbluhm size_t i;
57a545a52cSbluhm int sta;
58a545a52cSbluhm
59a545a52cSbluhm for (i = 0; i < __arraycount(sig); i++) {
60a545a52cSbluhm
61a545a52cSbluhm pid = fork();
62a545a52cSbluhm ATF_REQUIRE(pid >= 0);
63a545a52cSbluhm
64a545a52cSbluhm switch (pid) {
65a545a52cSbluhm
66a545a52cSbluhm case 0:
67a545a52cSbluhm pause();
68a545a52cSbluhm break;
69a545a52cSbluhm
70a545a52cSbluhm default:
71a545a52cSbluhm ATF_REQUIRE(kill(pid, sig[i]) == 0);
72a545a52cSbluhm }
73a545a52cSbluhm
74a545a52cSbluhm (void)wait(&sta);
75a545a52cSbluhm
76a545a52cSbluhm if (WIFSIGNALED(sta) == 0 || WTERMSIG(sta) != sig[i])
77a545a52cSbluhm atf_tc_fail("kill(2) failed to kill child");
78a545a52cSbluhm }
79a545a52cSbluhm }
80a545a52cSbluhm
81a545a52cSbluhm ATF_TC(kill_err);
ATF_TC_HEAD(kill_err,tc)82a545a52cSbluhm ATF_TC_HEAD(kill_err, tc)
83a545a52cSbluhm {
84a545a52cSbluhm atf_tc_set_md_var(tc, "descr", "Test error conditions of kill(2)");
85a545a52cSbluhm }
86a545a52cSbluhm
ATF_TC_BODY(kill_err,tc)87a545a52cSbluhm ATF_TC_BODY(kill_err, tc)
88a545a52cSbluhm {
89a545a52cSbluhm int rv, sta;
90a545a52cSbluhm pid_t pid;
91a545a52cSbluhm
92a545a52cSbluhm pid = fork();
93a545a52cSbluhm ATF_REQUIRE(pid >= 0);
94a545a52cSbluhm
95a545a52cSbluhm if (pid == 0) {
96a545a52cSbluhm
97a545a52cSbluhm errno = 0;
98a545a52cSbluhm rv = kill(getpid(), -1);
99a545a52cSbluhm
100a545a52cSbluhm if (rv == 0 || errno != EINVAL)
101a545a52cSbluhm _exit(EINVAL);
102a545a52cSbluhm
103a545a52cSbluhm errno = 0;
104a545a52cSbluhm rv = kill(INT_MAX, SIGUSR1);
105a545a52cSbluhm
106a545a52cSbluhm if (rv == 0 || errno != ESRCH)
107a545a52cSbluhm _exit(ESRCH);
108a545a52cSbluhm
109a545a52cSbluhm _exit(EXIT_SUCCESS);
110a545a52cSbluhm }
111a545a52cSbluhm
112a545a52cSbluhm (void)wait(&sta);
113a545a52cSbluhm
114a545a52cSbluhm if (WIFEXITED(sta) == 0 || WEXITSTATUS(sta) != EXIT_SUCCESS) {
115a545a52cSbluhm
116a545a52cSbluhm if (WEXITSTATUS(sta) == EINVAL)
117a545a52cSbluhm atf_tc_fail("expected EINVAL, but kill(2) succeeded");
118a545a52cSbluhm
119a545a52cSbluhm if (WEXITSTATUS(sta) == ESRCH)
120a545a52cSbluhm atf_tc_fail("expected ESRCH, but kill(2) succeeded");
121a545a52cSbluhm
122a545a52cSbluhm atf_tc_fail("unknown error from kill(2)");
123a545a52cSbluhm }
124a545a52cSbluhm }
125a545a52cSbluhm
126a545a52cSbluhm ATF_TC(kill_perm);
ATF_TC_HEAD(kill_perm,tc)127a545a52cSbluhm ATF_TC_HEAD(kill_perm, tc)
128a545a52cSbluhm {
129a545a52cSbluhm atf_tc_set_md_var(tc, "descr", "Test kill(2) permissions");
130a545a52cSbluhm atf_tc_set_md_var(tc, "require.user", "root");
131a545a52cSbluhm }
132a545a52cSbluhm
ATF_TC_BODY(kill_perm,tc)133a545a52cSbluhm ATF_TC_BODY(kill_perm, tc)
134a545a52cSbluhm {
135a545a52cSbluhm struct passwd *pw;
136a545a52cSbluhm pid_t cpid, ppid;
137a545a52cSbluhm uid_t cuid = 0;
138a545a52cSbluhm uid_t puid = 0;
139a545a52cSbluhm int sta;
140a545a52cSbluhm
141a545a52cSbluhm /*
142a545a52cSbluhm * Test that kill(2) fails when called
143a545a52cSbluhm * for a PID owned by another user.
144a545a52cSbluhm */
145a545a52cSbluhm pw = getpwnam("operator");
146a545a52cSbluhm
147a545a52cSbluhm if (pw != NULL)
148a545a52cSbluhm cuid = pw->pw_uid;
149a545a52cSbluhm
150a545a52cSbluhm pw = getpwnam("nobody");
151a545a52cSbluhm
152a545a52cSbluhm if (pw != NULL)
153a545a52cSbluhm puid = pw->pw_uid;
154a545a52cSbluhm
155a545a52cSbluhm if (cuid == 0 || puid == 0 || cuid == puid)
156a545a52cSbluhm atf_tc_fail("getpwnam(3) failed");
157a545a52cSbluhm
158a545a52cSbluhm ppid = fork();
159a545a52cSbluhm
160a545a52cSbluhm if (ppid < 0)
161a545a52cSbluhm _exit(EXIT_FAILURE);
162a545a52cSbluhm
163a545a52cSbluhm if (ppid == 0) {
164a545a52cSbluhm
165a545a52cSbluhm cpid = fork();
166a545a52cSbluhm
167a545a52cSbluhm if (cpid < 0)
168a545a52cSbluhm _exit(EXIT_FAILURE);
169a545a52cSbluhm
170a545a52cSbluhm if (cpid == 0) {
171a545a52cSbluhm
172a545a52cSbluhm if (setuid(cuid) < 0)
173a545a52cSbluhm _exit(EXIT_FAILURE);
174a545a52cSbluhm else {
175a545a52cSbluhm (void)sleep(1);
176a545a52cSbluhm }
177a545a52cSbluhm
178a545a52cSbluhm _exit(EXIT_SUCCESS);
179a545a52cSbluhm }
180a545a52cSbluhm
181a545a52cSbluhm /*
182a545a52cSbluhm * Try to kill the child after having
183a545a52cSbluhm * set the real and effective UID.
184a545a52cSbluhm */
185a545a52cSbluhm if (setuid(puid) != 0)
186a545a52cSbluhm _exit(EXIT_FAILURE);
187a545a52cSbluhm
188a545a52cSbluhm errno = 0;
189a545a52cSbluhm
190a545a52cSbluhm if (kill(cpid, SIGKILL) == 0)
191a545a52cSbluhm _exit(EPERM);
192a545a52cSbluhm
193a545a52cSbluhm if (errno != EPERM)
194a545a52cSbluhm _exit(EPERM);
195a545a52cSbluhm
196a545a52cSbluhm (void)waitpid(cpid, &sta, 0);
197a545a52cSbluhm
198a545a52cSbluhm _exit(EXIT_SUCCESS);
199a545a52cSbluhm }
200a545a52cSbluhm
201a545a52cSbluhm (void)waitpid(ppid, &sta, 0);
202a545a52cSbluhm
203a545a52cSbluhm if (WIFEXITED(sta) == 0 || WEXITSTATUS(sta) == EPERM)
204a545a52cSbluhm atf_tc_fail("killed a process of another user");
205a545a52cSbluhm
206a545a52cSbluhm if (WIFEXITED(sta) == 0 || WEXITSTATUS(sta) != EXIT_SUCCESS)
207a545a52cSbluhm atf_tc_fail("unknown error from kill(2)");
208a545a52cSbluhm }
209a545a52cSbluhm
210a545a52cSbluhm ATF_TC(kill_pgrp_neg);
ATF_TC_HEAD(kill_pgrp_neg,tc)211a545a52cSbluhm ATF_TC_HEAD(kill_pgrp_neg, tc)
212a545a52cSbluhm {
213a545a52cSbluhm atf_tc_set_md_var(tc, "descr", "Test kill(2) with process group, #2");
214a545a52cSbluhm }
215a545a52cSbluhm
ATF_TC_BODY(kill_pgrp_neg,tc)216a545a52cSbluhm ATF_TC_BODY(kill_pgrp_neg, tc)
217a545a52cSbluhm {
218a545a52cSbluhm const int maxiter = 3;
219a545a52cSbluhm pid_t cpid, ppid;
220a545a52cSbluhm int i, sta;
221a545a52cSbluhm
222a545a52cSbluhm ppid = fork();
223a545a52cSbluhm ATF_REQUIRE(ppid >= 0);
224a545a52cSbluhm
225a545a52cSbluhm if (ppid == 0) {
226a545a52cSbluhm
227a545a52cSbluhm ATF_REQUIRE(setpgid(0, 0) == 0);
228a545a52cSbluhm
229a545a52cSbluhm for (i = 0; i < maxiter; i++) {
230a545a52cSbluhm
231a545a52cSbluhm cpid = fork();
232a545a52cSbluhm ATF_REQUIRE(cpid >= 0);
233a545a52cSbluhm
234a545a52cSbluhm if (cpid == 0)
235a545a52cSbluhm pause();
236a545a52cSbluhm }
237a545a52cSbluhm
238a545a52cSbluhm /*
239a545a52cSbluhm * Test the variant of killpg(3); if the process number
240a545a52cSbluhm * is negative but not -1, the signal should be sent to
241a545a52cSbluhm * all processes whose process group ID is equal to the
242a545a52cSbluhm * absolute value of the process number.
243a545a52cSbluhm */
244a545a52cSbluhm ATF_REQUIRE(kill(-getpgrp(), SIGKILL) == 0);
245a545a52cSbluhm
246a545a52cSbluhm (void)sleep(1);
247a545a52cSbluhm
248a545a52cSbluhm _exit(EXIT_SUCCESS);
249a545a52cSbluhm }
250a545a52cSbluhm
251a545a52cSbluhm (void)waitpid(ppid, &sta, 0);
252a545a52cSbluhm
253a545a52cSbluhm if (WIFSIGNALED(sta) == 0 || WTERMSIG(sta) != SIGKILL)
254a545a52cSbluhm atf_tc_fail("failed to kill(2) a process group");
255a545a52cSbluhm }
256a545a52cSbluhm
257a545a52cSbluhm ATF_TC(kill_pgrp_zero);
ATF_TC_HEAD(kill_pgrp_zero,tc)258a545a52cSbluhm ATF_TC_HEAD(kill_pgrp_zero, tc)
259a545a52cSbluhm {
260a545a52cSbluhm atf_tc_set_md_var(tc, "descr", "Test kill(2) with process group, #1");
261a545a52cSbluhm }
262a545a52cSbluhm
ATF_TC_BODY(kill_pgrp_zero,tc)263a545a52cSbluhm ATF_TC_BODY(kill_pgrp_zero, tc)
264a545a52cSbluhm {
265a545a52cSbluhm const int maxiter = 3;
266a545a52cSbluhm pid_t cpid, ppid;
267a545a52cSbluhm int i, sta;
268a545a52cSbluhm
269a545a52cSbluhm ppid = fork();
270a545a52cSbluhm ATF_REQUIRE(ppid >= 0);
271a545a52cSbluhm
272a545a52cSbluhm if (ppid == 0) {
273a545a52cSbluhm
274a545a52cSbluhm ATF_REQUIRE(setpgid(0, 0) == 0);
275a545a52cSbluhm
276a545a52cSbluhm for (i = 0; i < maxiter; i++) {
277a545a52cSbluhm
278a545a52cSbluhm cpid = fork();
279a545a52cSbluhm ATF_REQUIRE(cpid >= 0);
280a545a52cSbluhm
281a545a52cSbluhm if (cpid == 0)
282a545a52cSbluhm pause();
283a545a52cSbluhm }
284a545a52cSbluhm
285a545a52cSbluhm /*
286a545a52cSbluhm * If the supplied process number is zero,
287a545a52cSbluhm * the signal should be sent to all processes
288a545a52cSbluhm * under the current process group.
289a545a52cSbluhm */
290a545a52cSbluhm ATF_REQUIRE(kill(0, SIGKILL) == 0);
291a545a52cSbluhm
292a545a52cSbluhm (void)sleep(1);
293a545a52cSbluhm
294a545a52cSbluhm _exit(EXIT_SUCCESS);
295a545a52cSbluhm }
296a545a52cSbluhm
297a545a52cSbluhm (void)waitpid(ppid, &sta, 0);
298a545a52cSbluhm
299a545a52cSbluhm if (WIFSIGNALED(sta) == 0 || WTERMSIG(sta) != SIGKILL)
300a545a52cSbluhm atf_tc_fail("failed to kill(2) a process group");
301a545a52cSbluhm }
302a545a52cSbluhm
ATF_TP_ADD_TCS(tp)303a545a52cSbluhm ATF_TP_ADD_TCS(tp)
304a545a52cSbluhm {
305a545a52cSbluhm
306a545a52cSbluhm ATF_TP_ADD_TC(tp, kill_basic);
307a545a52cSbluhm ATF_TP_ADD_TC(tp, kill_err);
308a545a52cSbluhm ATF_TP_ADD_TC(tp, kill_perm);
309a545a52cSbluhm ATF_TP_ADD_TC(tp, kill_pgrp_neg);
310a545a52cSbluhm ATF_TP_ADD_TC(tp, kill_pgrp_zero);
311a545a52cSbluhm
312a545a52cSbluhm return atf_no_error();
313a545a52cSbluhm }
314