2022-08-07 23:18:33 +00:00
|
|
|
/*-*- mode:c;indent-tabs-mode:nil;c-basic-offset:2;tab-width:8;coding:utf-8 -*-│
|
|
|
|
│vi: set net ft=c ts=2 sts=2 sw=2 fenc=utf-8 :vi│
|
|
|
|
╞══════════════════════════════════════════════════════════════════════════════╡
|
|
|
|
│ Copyright 2022 Justine Alexandra Roberts Tunney │
|
|
|
|
│ │
|
|
|
|
│ Permission to use, copy, modify, and/or distribute this software for │
|
|
|
|
│ any purpose with or without fee is hereby granted, provided that the │
|
|
|
|
│ above copyright notice and this permission notice appear in all copies. │
|
|
|
|
│ │
|
|
|
|
│ THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL │
|
|
|
|
│ WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED │
|
|
|
|
│ WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE │
|
|
|
|
│ AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL │
|
|
|
|
│ DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR │
|
|
|
|
│ PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER │
|
|
|
|
│ TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR │
|
|
|
|
│ PERFORMANCE OF THIS SOFTWARE. │
|
|
|
|
╚─────────────────────────────────────────────────────────────────────────────*/
|
|
|
|
#include "libc/calls/calls.h"
|
2022-08-08 18:41:08 +00:00
|
|
|
#include "libc/calls/pledge.internal.h"
|
2023-06-10 01:02:06 +00:00
|
|
|
#include "libc/calls/struct/seccomp.internal.h"
|
2022-08-07 23:18:33 +00:00
|
|
|
#include "libc/calls/syscall_support-sysv.internal.h"
|
|
|
|
#include "libc/dce.h"
|
2022-08-11 07:15:29 +00:00
|
|
|
#include "libc/errno.h"
|
2022-08-08 18:41:08 +00:00
|
|
|
#include "libc/intrin/promises.internal.h"
|
2022-08-07 23:18:33 +00:00
|
|
|
#include "libc/runtime/runtime.h"
|
|
|
|
#include "libc/sock/sock.h"
|
2023-06-03 15:12:13 +00:00
|
|
|
#include "libc/stdio/stdio.h"
|
2022-08-07 23:18:33 +00:00
|
|
|
#include "libc/sysv/consts/af.h"
|
|
|
|
#include "libc/sysv/consts/ipproto.h"
|
|
|
|
#include "libc/sysv/consts/sig.h"
|
|
|
|
#include "libc/sysv/consts/sock.h"
|
2022-09-04 01:01:38 +00:00
|
|
|
#include "libc/testlib/subprocess.h"
|
2022-08-07 23:18:33 +00:00
|
|
|
#include "libc/testlib/testlib.h"
|
|
|
|
|
|
|
|
void SetUp(void) {
|
2023-06-03 15:12:13 +00:00
|
|
|
if (pledge(0, 0) == -1) {
|
|
|
|
fprintf(stderr, "warning: pledge() not supported on this system\n");
|
|
|
|
exit(0);
|
|
|
|
}
|
2022-08-07 23:18:33 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
TEST(pledge, testSoftError) {
|
|
|
|
if (IsOpenbsd()) return;
|
|
|
|
SPAWN(fork);
|
2022-08-11 18:27:25 +00:00
|
|
|
__pledge_mode = PLEDGE_PENALTY_RETURN_EPERM;
|
2022-08-07 23:18:33 +00:00
|
|
|
ASSERT_SYS(0, 0, pledge("stdio", 0));
|
|
|
|
ASSERT_SYS(EPERM, -1, socket(AF_INET, SOCK_STREAM, IPPROTO_TCP));
|
|
|
|
_Exit(7);
|
|
|
|
EXITS(7);
|
|
|
|
}
|
|
|
|
|
|
|
|
TEST(pledge, testKillThreadMode) {
|
|
|
|
SPAWN(fork);
|
2022-08-11 18:27:25 +00:00
|
|
|
__pledge_mode = PLEDGE_PENALTY_KILL_THREAD | PLEDGE_STDERR_LOGGING;
|
2022-08-07 23:18:33 +00:00
|
|
|
ASSERT_SYS(0, 0, pledge("stdio", 0));
|
|
|
|
socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);
|
2022-08-08 18:41:08 +00:00
|
|
|
TERMS(SIGABRT);
|
2022-08-07 23:18:33 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
TEST(pledge, testKillProcessMode) {
|
|
|
|
SPAWN(fork);
|
2022-08-11 18:27:25 +00:00
|
|
|
__pledge_mode = PLEDGE_PENALTY_KILL_PROCESS | PLEDGE_STDERR_LOGGING;
|
2022-08-07 23:18:33 +00:00
|
|
|
ASSERT_SYS(0, 0, pledge("stdio", 0));
|
|
|
|
socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);
|
2022-08-08 18:41:08 +00:00
|
|
|
TERMS(SIGABRT);
|
2022-08-07 23:18:33 +00:00
|
|
|
}
|
|
|
|
|
2022-08-08 18:41:08 +00:00
|
|
|
TEST(pledge, testLogMessage_inSoftyMode) {
|
2022-08-07 23:18:33 +00:00
|
|
|
if (IsOpenbsd()) return;
|
|
|
|
int fds[2];
|
2022-08-09 04:23:37 +00:00
|
|
|
char msg[256] = {0};
|
2022-08-07 23:18:33 +00:00
|
|
|
ASSERT_SYS(0, 0, pipe(fds));
|
|
|
|
SPAWN(fork);
|
2022-08-11 18:27:25 +00:00
|
|
|
__pledge_mode = PLEDGE_PENALTY_RETURN_EPERM | PLEDGE_STDERR_LOGGING;
|
2022-08-07 23:18:33 +00:00
|
|
|
ASSERT_SYS(0, 2, dup2(fds[1], 2));
|
|
|
|
ASSERT_SYS(0, 0, pledge("stdio", 0));
|
|
|
|
ASSERT_SYS(EPERM, -1, socket(AF_INET, SOCK_STREAM, IPPROTO_TCP));
|
|
|
|
EXITS(0);
|
|
|
|
close(fds[1]);
|
|
|
|
read(fds[0], msg, sizeof(msg));
|
|
|
|
close(fds[0]);
|
|
|
|
if (IsLinux()) {
|
2023-06-03 14:50:29 +00:00
|
|
|
ASSERT_STARTSWITH("error: protected syscall socket", msg);
|
2022-08-07 23:18:33 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
TEST(pledge, testLogMessage_onKillProcess) {
|
|
|
|
int fds[2];
|
2022-08-09 04:23:37 +00:00
|
|
|
char msg[256] = {0};
|
2022-08-07 23:18:33 +00:00
|
|
|
ASSERT_SYS(0, 0, pipe(fds));
|
|
|
|
SPAWN(fork);
|
2022-08-11 18:27:25 +00:00
|
|
|
__pledge_mode = PLEDGE_PENALTY_KILL_THREAD | PLEDGE_STDERR_LOGGING;
|
2022-08-07 23:18:33 +00:00
|
|
|
ASSERT_SYS(0, 2, dup2(fds[1], 2));
|
|
|
|
ASSERT_SYS(0, 0, pledge("stdio", 0));
|
|
|
|
socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);
|
2022-08-08 18:41:08 +00:00
|
|
|
TERMS(SIGABRT);
|
2022-08-07 23:18:33 +00:00
|
|
|
close(fds[1]);
|
|
|
|
read(fds[0], msg, sizeof(msg));
|
|
|
|
close(fds[0]);
|
|
|
|
if (IsLinux()) {
|
2023-06-03 14:50:29 +00:00
|
|
|
ASSERT_STARTSWITH("error: protected syscall socket", msg);
|
2022-08-07 23:18:33 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-08-08 18:41:08 +00:00
|
|
|
TEST(pledge, testDoublePledge_isFine) {
|
|
|
|
SPAWN(fork);
|
2022-08-11 18:27:25 +00:00
|
|
|
__pledge_mode = PLEDGE_PENALTY_KILL_THREAD;
|
2022-08-08 18:41:08 +00:00
|
|
|
ASSERT_SYS(0, 0, pledge("stdio", 0));
|
|
|
|
ASSERT_SYS(0, 0, pledge("stdio", 0));
|
|
|
|
EXITS(0);
|
|
|
|
}
|
2022-08-11 18:27:25 +00:00
|
|
|
|
|
|
|
TEST(pledge, testEmptyPledge_doesntUseTrapping) {
|
|
|
|
SPAWN(fork);
|
|
|
|
__pledge_mode = PLEDGE_PENALTY_KILL_PROCESS;
|
|
|
|
ASSERT_SYS(0, 0, pledge("", 0));
|
|
|
|
socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);
|
|
|
|
TERMS(IsOpenbsd() ? SIGABRT : SIGSYS);
|
|
|
|
}
|