mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 01:55:51 +02:00
vfs-7.2-rc1.openat2
Please consider pulling these changes from the signed vfs-7.2-rc1.openat2 tag.
Thanks!
Christian
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQRAhzRXHqcMeLMyaSiRxhvAZXjcogUCaiwLKgAKCRCRxhvAZXjc
ogT3AQCKd2J6Qz6vsVaHK8Bo9oE06Px4v2NGeu+FgCV0QQMpJQD+KTEnVl4ZepJu
JsEw202uWeQw9Aj/SoD1oyuYO0ZIrQw=
=rQxh
-----END PGP SIGNATURE-----
Merge tag 'vfs-7.2-rc1.openat2' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs
Pull openat2 updates from Christian Brauner:
"Features:
- Add O_EMPTYPATH to openat(2)/openat2(2). To get an operable file
descriptor from an O_PATH file descriptor it is possible to use
openat(fd, ".", O_DIRECTORY) for directories, but other file types
require going through open("/proc/<pid>/fd/<nr>") and thus depend
on a functioning procfs.
With O_EMPTYPATH an empty path string is accepted and LOOKUP_EMPTY
is set at path resolution time, allowing to reopen the file behind
the file descriptor directly. Selftests are included.
- Add an OPENAT2_REGULAR flag for openat2(2) which refuses to open
anything but regular files with the new EFTYPE error code.
This implements the "ability to only open regular files" feature
requested by userspace via uapi-group.org and protects services
from being redirected to fifos, device nodes, and friends.
All atomic_open implementations were audited for OPENAT2_REGULAR
handling. Explicit checks were added to ceph, gfs2, nfs (v4), and
cifs/smb - these are the filesystems whose atomic_open can
encounter an existing non-regular file and would otherwise call
finish_open() on it or return a misleading error code.
The remaining implementations (9p, fuse, vboxsf, nfs v2/v3) only
call finish_open() on freshly created files and use
finish_no_open() for lookup hits, letting the VFS catch non-regular
files via the do_open() safety net.
Cleanups:
- Migrate the openat2 selftests to the kselftest harness and move
them under selftests/filesystems/. The tests were written in the
early days of selftests' TAP support and the modern kselftest
harness is much easier to follow and maintain. The contents of the
tests are unchanged and the new emptypath tests are ported on top.
- Make the LAST_XXX last-type constants private to fs/namei.c. The
only user outside of fs/namei.c was ksmbd which only needs to know
whether the last component is a regular one, so
vfs_path_parent_lookup() now performs the LAST_NORM check
internally. The ints are replaced with a dedicated enum last_type"
* tag 'vfs-7.2-rc1.openat2' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs:
vfs: replace ints with enum last_type for LAST_XXX
vfs: make LAST_XXX private to fs/namei.c
selftests: openat2: port emptypath_test to kselftest harness
kselftest/openat2: test for OPENAT2_REGULAR flag
openat2: new OPENAT2_REGULAR flag support
openat2: introduce EFTYPE error code
selftest: add tests for O_EMPTYPATH
vfs: add O_EMPTYPATH to openat(2)/openat2(2)
selftests: openat2: migrate to kselftest harness
selftests: openat2: switch from custom ARRAY_LEN to ARRAY_SIZE
selftests: openat2: move helpers to header
selftests: move openat2 tests to selftests/filesystems/
This commit is contained in:
commit
50b900c564
|
|
@ -127,4 +127,6 @@
|
|||
|
||||
#define EHWPOISON 139 /* Memory page has hardware error */
|
||||
|
||||
#define EFTYPE 140 /* Wrong file type for the intended operation */
|
||||
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -126,6 +126,8 @@
|
|||
|
||||
#define EHWPOISON 168 /* Memory page has hardware error */
|
||||
|
||||
#define EFTYPE 169 /* Wrong file type for the intended operation */
|
||||
|
||||
#define EDQUOT 1133 /* Quota exceeded */
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -124,4 +124,6 @@
|
|||
|
||||
#define EHWPOISON 257 /* Memory page has hardware error */
|
||||
|
||||
#define EFTYPE 258 /* Wrong file type for the intended operation */
|
||||
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -117,4 +117,6 @@
|
|||
|
||||
#define EHWPOISON 135 /* Memory page has hardware error */
|
||||
|
||||
#define EFTYPE 136 /* Wrong file type for the intended operation */
|
||||
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -996,6 +996,10 @@ int ceph_atomic_open(struct inode *dir, struct dentry *dentry,
|
|||
ceph_init_inode_acls(newino, &as_ctx);
|
||||
file->f_mode |= FMODE_CREATED;
|
||||
}
|
||||
if ((flags & __O_REGULAR) && !d_is_reg(dentry)) {
|
||||
err = -EFTYPE;
|
||||
goto out_req;
|
||||
}
|
||||
err = finish_open(file, dentry, ceph_open);
|
||||
}
|
||||
out_req:
|
||||
|
|
|
|||
|
|
@ -1169,10 +1169,10 @@ static int __init fcntl_init(void)
|
|||
* Exceptions: O_NONBLOCK is a two bit define on parisc; O_NDELAY
|
||||
* is defined as O_NONBLOCK on some platforms and not on others.
|
||||
*/
|
||||
BUILD_BUG_ON(20 - 1 /* for O_RDONLY being 0 */ !=
|
||||
BUILD_BUG_ON(22 - 1 /* for O_RDONLY being 0 */ !=
|
||||
HWEIGHT32(
|
||||
(VALID_OPEN_FLAGS & ~(O_NONBLOCK | O_NDELAY)) |
|
||||
__FMODE_EXEC));
|
||||
__FMODE_EXEC | __O_REGULAR));
|
||||
|
||||
fasync_cache = kmem_cache_create("fasync_cache",
|
||||
sizeof(struct fasync_struct), 0,
|
||||
|
|
|
|||
|
|
@ -738,6 +738,13 @@ static int gfs2_create_inode(struct inode *dir, struct dentry *dentry,
|
|||
inode = gfs2_dir_search(dir, &dentry->d_name, !S_ISREG(mode) || excl);
|
||||
error = PTR_ERR(inode);
|
||||
if (!IS_ERR(inode)) {
|
||||
if (file && (file->f_flags & __O_REGULAR) &&
|
||||
!S_ISREG(inode->i_mode)) {
|
||||
iput(inode);
|
||||
inode = NULL;
|
||||
error = -EFTYPE;
|
||||
goto fail_gunlock;
|
||||
}
|
||||
if (S_ISDIR(inode->i_mode)) {
|
||||
iput(inode);
|
||||
inode = NULL;
|
||||
|
|
|
|||
48
fs/namei.c
48
fs/namei.c
|
|
@ -129,6 +129,11 @@
|
|||
static struct kmem_cache *__names_cache __ro_after_init;
|
||||
#define names_cache runtime_const_ptr(__names_cache)
|
||||
|
||||
/*
|
||||
* Type of the last component on LOOKUP_PARENT
|
||||
*/
|
||||
enum last_type {LAST_NORM, LAST_ROOT, LAST_DOT, LAST_DOTDOT};
|
||||
|
||||
void __init filename_init(void)
|
||||
{
|
||||
__names_cache = kmem_cache_create_usercopy("names_cache", sizeof(struct filename), 0,
|
||||
|
|
@ -727,7 +732,7 @@ struct nameidata {
|
|||
struct inode *inode; /* path.dentry.d_inode */
|
||||
unsigned int flags, state;
|
||||
unsigned seq, next_seq, m_seq, r_seq;
|
||||
int last_type;
|
||||
enum last_type last_type;
|
||||
unsigned depth;
|
||||
int total_link_count;
|
||||
struct saved {
|
||||
|
|
@ -2220,7 +2225,7 @@ static struct dentry *follow_dotdot(struct nameidata *nd)
|
|||
return dget(nd->path.dentry);
|
||||
}
|
||||
|
||||
static const char *handle_dots(struct nameidata *nd, int type)
|
||||
static const char *handle_dots(struct nameidata *nd, enum last_type type)
|
||||
{
|
||||
if (type == LAST_DOTDOT) {
|
||||
const char *error = NULL;
|
||||
|
|
@ -2868,7 +2873,7 @@ static int path_parentat(struct nameidata *nd, unsigned flags,
|
|||
/* Note: this does not consume "name" */
|
||||
static int __filename_parentat(int dfd, struct filename *name,
|
||||
unsigned int flags, struct path *parent,
|
||||
struct qstr *last, int *type,
|
||||
struct qstr *last, enum last_type *type,
|
||||
const struct path *root)
|
||||
{
|
||||
int retval;
|
||||
|
|
@ -2893,7 +2898,7 @@ static int __filename_parentat(int dfd, struct filename *name,
|
|||
|
||||
static int filename_parentat(int dfd, struct filename *name,
|
||||
unsigned int flags, struct path *parent,
|
||||
struct qstr *last, int *type)
|
||||
struct qstr *last, enum last_type *type)
|
||||
{
|
||||
return __filename_parentat(dfd, name, flags, parent, last, type, NULL);
|
||||
}
|
||||
|
|
@ -2961,7 +2966,8 @@ static struct dentry *__start_removing_path(int dfd, struct filename *name,
|
|||
struct path parent_path __free(path_put) = {};
|
||||
struct dentry *d;
|
||||
struct qstr last;
|
||||
int type, error;
|
||||
enum last_type type;
|
||||
int error;
|
||||
|
||||
error = filename_parentat(dfd, name, 0, &parent_path, &last, &type);
|
||||
if (error)
|
||||
|
|
@ -3007,7 +3013,8 @@ struct dentry *kern_path_parent(const char *name, struct path *path)
|
|||
CLASS(filename_kernel, filename)(name);
|
||||
struct dentry *d;
|
||||
struct qstr last;
|
||||
int type, error;
|
||||
enum last_type type;
|
||||
int error;
|
||||
|
||||
error = filename_parentat(AT_FDCWD, filename, 0, &parent_path, &last, &type);
|
||||
if (error)
|
||||
|
|
@ -3051,15 +3058,22 @@ EXPORT_SYMBOL(kern_path);
|
|||
* @flags: lookup flags
|
||||
* @parent: pointer to struct path to fill
|
||||
* @last: last component
|
||||
* @type: type of the last component
|
||||
* @root: pointer to struct path of the base directory
|
||||
*/
|
||||
int vfs_path_parent_lookup(struct filename *filename, unsigned int flags,
|
||||
struct path *parent, struct qstr *last, int *type,
|
||||
struct path *parent, struct qstr *last,
|
||||
const struct path *root)
|
||||
{
|
||||
return __filename_parentat(AT_FDCWD, filename, flags, parent, last,
|
||||
type, root);
|
||||
enum last_type type;
|
||||
int err = __filename_parentat(AT_FDCWD, filename, flags, parent, last,
|
||||
&type, root);
|
||||
if (err)
|
||||
return err;
|
||||
if (unlikely(type != LAST_NORM)) {
|
||||
path_put(parent);
|
||||
return -EINVAL;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
EXPORT_SYMBOL(vfs_path_parent_lookup);
|
||||
|
||||
|
|
@ -4679,6 +4693,10 @@ static int do_open(struct nameidata *nd,
|
|||
if (unlikely(error))
|
||||
return error;
|
||||
}
|
||||
|
||||
if ((open_flag & __O_REGULAR) && !d_is_reg(nd->path.dentry))
|
||||
return -EFTYPE;
|
||||
|
||||
if ((nd->flags & LOOKUP_DIRECTORY) && !d_can_lookup(nd->path.dentry))
|
||||
return -ENOTDIR;
|
||||
|
||||
|
|
@ -4925,7 +4943,7 @@ static struct dentry *filename_create(int dfd, struct filename *name,
|
|||
bool want_dir = lookup_flags & LOOKUP_DIRECTORY;
|
||||
unsigned int reval_flag = lookup_flags & LOOKUP_REVAL;
|
||||
unsigned int create_flags = LOOKUP_CREATE | LOOKUP_EXCL;
|
||||
int type;
|
||||
enum last_type type;
|
||||
int error;
|
||||
|
||||
error = filename_parentat(dfd, name, reval_flag, path, &last, &type);
|
||||
|
|
@ -5397,7 +5415,7 @@ int filename_rmdir(int dfd, struct filename *name)
|
|||
struct dentry *dentry;
|
||||
struct path path;
|
||||
struct qstr last;
|
||||
int type;
|
||||
enum last_type type;
|
||||
unsigned int lookup_flags = 0;
|
||||
struct delegated_inode delegated_inode = { };
|
||||
retry:
|
||||
|
|
@ -5406,6 +5424,8 @@ int filename_rmdir(int dfd, struct filename *name)
|
|||
return error;
|
||||
|
||||
switch (type) {
|
||||
case LAST_NORM:
|
||||
break;
|
||||
case LAST_DOTDOT:
|
||||
error = -ENOTEMPTY;
|
||||
goto exit2;
|
||||
|
|
@ -5539,7 +5559,7 @@ int filename_unlinkat(int dfd, struct filename *name)
|
|||
struct dentry *dentry;
|
||||
struct path path;
|
||||
struct qstr last;
|
||||
int type;
|
||||
enum last_type type;
|
||||
struct inode *inode;
|
||||
struct delegated_inode delegated_inode = { };
|
||||
unsigned int lookup_flags = 0;
|
||||
|
|
@ -6109,7 +6129,7 @@ int filename_renameat2(int olddfd, struct filename *from,
|
|||
struct renamedata rd;
|
||||
struct path old_path, new_path;
|
||||
struct qstr old_last, new_last;
|
||||
int old_type, new_type;
|
||||
enum last_type old_type, new_type;
|
||||
struct delegated_inode delegated_inode = { };
|
||||
unsigned int lookup_flags = 0;
|
||||
bool should_retry = false;
|
||||
|
|
|
|||
|
|
@ -2194,6 +2194,10 @@ int nfs_atomic_open(struct inode *dir, struct dentry *dentry,
|
|||
break;
|
||||
case -EISDIR:
|
||||
case -ENOTDIR:
|
||||
if (open_flags & __O_REGULAR) {
|
||||
err = -EFTYPE;
|
||||
break;
|
||||
}
|
||||
goto no_open;
|
||||
case -ELOOP:
|
||||
if (!(open_flags & O_NOFOLLOW))
|
||||
|
|
|
|||
41
fs/open.c
41
fs/open.c
|
|
@ -960,7 +960,7 @@ static int do_dentry_open(struct file *f,
|
|||
if (f->f_mapping->a_ops && f->f_mapping->a_ops->direct_IO)
|
||||
f->f_mode |= FMODE_CAN_ODIRECT;
|
||||
|
||||
f->f_flags &= ~(O_CREAT | O_EXCL | O_NOCTTY | O_TRUNC);
|
||||
f->f_flags &= ~(O_CREAT | O_EXCL | O_NOCTTY | O_TRUNC | __O_REGULAR);
|
||||
f->f_iocb_flags = iocb_flags(f);
|
||||
|
||||
file_ra_state_init(&f->f_ra, f->f_mapping->host->i_mapping);
|
||||
|
|
@ -1158,7 +1158,7 @@ struct file *kernel_file_open(const struct path *path, int flags,
|
|||
EXPORT_SYMBOL_GPL(kernel_file_open);
|
||||
|
||||
#define WILL_CREATE(flags) (flags & (O_CREAT | __O_TMPFILE))
|
||||
#define O_PATH_FLAGS (O_DIRECTORY | O_NOFOLLOW | O_PATH | O_CLOEXEC)
|
||||
#define O_PATH_FLAGS (O_DIRECTORY | O_NOFOLLOW | O_PATH | O_CLOEXEC | O_EMPTYPATH)
|
||||
|
||||
inline struct open_how build_open_how(int flags, umode_t mode)
|
||||
{
|
||||
|
|
@ -1184,7 +1184,15 @@ inline int build_open_flags(const struct open_how *how, struct open_flags *op)
|
|||
int acc_mode = ACC_MODE(flags);
|
||||
|
||||
BUILD_BUG_ON_MSG(upper_32_bits(VALID_OPEN_FLAGS),
|
||||
"struct open_flags doesn't yet handle flags > 32 bits");
|
||||
"VALID_OPEN_FLAGS must fit in 32 bits");
|
||||
/* The whole point: OPENAT2_REGULAR must be unrepresentable in int. */
|
||||
BUILD_BUG_ON_MSG(!upper_32_bits(OPENAT2_REGULAR),
|
||||
"OPENAT2_REGULAR must live in the upper 32 bits of open_how::flags");
|
||||
/* Prevent a future bit collision between UAPI and internal carrier. */
|
||||
BUILD_BUG_ON_MSG(OPENAT2_REGULAR & VALID_OPEN_FLAGS,
|
||||
"OPENAT2_REGULAR must not alias any open()/openat() flag");
|
||||
BUILD_BUG_ON_MSG(__O_REGULAR & VALID_OPENAT2_FLAGS,
|
||||
"__O_REGULAR must not alias any user-visible flag");
|
||||
|
||||
/*
|
||||
* Strip flags that aren't relevant in determining struct open_flags.
|
||||
|
|
@ -1196,7 +1204,7 @@ inline int build_open_flags(const struct open_how *how, struct open_flags *op)
|
|||
* values before calling build_open_flags(), but openat2(2) checks all
|
||||
* of its arguments.
|
||||
*/
|
||||
if (flags & ~VALID_OPEN_FLAGS)
|
||||
if (flags & ~VALID_OPENAT2_FLAGS)
|
||||
return -EINVAL;
|
||||
if (how->resolve & ~VALID_RESOLVE_FLAGS)
|
||||
return -EINVAL;
|
||||
|
|
@ -1236,6 +1244,14 @@ inline int build_open_flags(const struct open_how *how, struct open_flags *op)
|
|||
if (!(acc_mode & MAY_WRITE))
|
||||
return -EINVAL;
|
||||
}
|
||||
/*
|
||||
* Asking to open a directory and a regular file at the same time is
|
||||
* contradictory.
|
||||
*/
|
||||
if ((flags & (O_DIRECTORY | OPENAT2_REGULAR)) ==
|
||||
(O_DIRECTORY | OPENAT2_REGULAR))
|
||||
return -EINVAL;
|
||||
|
||||
if (flags & O_PATH) {
|
||||
/* O_PATH only permits certain other flags to be set. */
|
||||
if (flags & ~O_PATH_FLAGS)
|
||||
|
|
@ -1252,6 +1268,19 @@ inline int build_open_flags(const struct open_how *how, struct open_flags *op)
|
|||
if (flags & __O_SYNC)
|
||||
flags |= O_DSYNC;
|
||||
|
||||
/*
|
||||
* Translate the upper-32-bit UAPI bit OPENAT2_REGULAR into the
|
||||
* kernel-internal lower-32-bit __O_REGULAR carrier so the bit
|
||||
* survives the assignment to op->open_flag (an int) below and the
|
||||
* subsequent flow through f->f_flags (unsigned int) and the
|
||||
* i_op->atomic_open() callback (unsigned). do_dentry_open() strips
|
||||
* __O_REGULAR before the file becomes visible to userspace.
|
||||
*/
|
||||
if (flags & OPENAT2_REGULAR) {
|
||||
flags &= ~OPENAT2_REGULAR;
|
||||
flags |= __O_REGULAR;
|
||||
}
|
||||
|
||||
op->open_flag = flags;
|
||||
|
||||
/* O_TRUNC implies we need access checks for write permissions */
|
||||
|
|
@ -1279,6 +1308,8 @@ inline int build_open_flags(const struct open_how *how, struct open_flags *op)
|
|||
lookup_flags |= LOOKUP_DIRECTORY;
|
||||
if (!(flags & O_NOFOLLOW))
|
||||
lookup_flags |= LOOKUP_FOLLOW;
|
||||
if (flags & O_EMPTYPATH)
|
||||
lookup_flags |= LOOKUP_EMPTY;
|
||||
|
||||
if (how->resolve & RESOLVE_NO_XDEV)
|
||||
lookup_flags |= LOOKUP_NO_XDEV;
|
||||
|
|
@ -1360,7 +1391,7 @@ static int do_sys_openat2(int dfd, const char __user *filename,
|
|||
if (unlikely(err))
|
||||
return err;
|
||||
|
||||
CLASS(filename, name)(filename);
|
||||
CLASS(filename_flags, name)(filename, op.lookup_flags);
|
||||
return FD_ADD(how->flags, do_file_open(dfd, name, &op));
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -241,6 +241,12 @@ static int __cifs_do_create(struct inode *dir, struct dentry *direntry,
|
|||
goto cifs_create_get_file_info;
|
||||
}
|
||||
|
||||
if ((oflags & __O_REGULAR) && !S_ISREG(newinode->i_mode)) {
|
||||
CIFSSMBClose(xid, tcon, fid->netfid);
|
||||
iput(newinode);
|
||||
return -EFTYPE;
|
||||
}
|
||||
|
||||
if (S_ISDIR(newinode->i_mode)) {
|
||||
CIFSSMBClose(xid, tcon, fid->netfid);
|
||||
iput(newinode);
|
||||
|
|
@ -458,9 +464,15 @@ static int __cifs_do_create(struct inode *dir, struct dentry *direntry,
|
|||
goto out_err;
|
||||
}
|
||||
|
||||
if (newinode && S_ISDIR(newinode->i_mode)) {
|
||||
rc = -EISDIR;
|
||||
goto out_err;
|
||||
if (newinode) {
|
||||
if ((oflags & __O_REGULAR) && !S_ISREG(newinode->i_mode)) {
|
||||
rc = -EFTYPE;
|
||||
goto out_err;
|
||||
}
|
||||
if (S_ISDIR(newinode->i_mode)) {
|
||||
rc = -EISDIR;
|
||||
goto out_err;
|
||||
}
|
||||
}
|
||||
|
||||
*inode = newinode;
|
||||
|
|
|
|||
|
|
@ -19,7 +19,6 @@
|
|||
#include <linux/vmalloc.h>
|
||||
#include <linux/sched/xacct.h>
|
||||
#include <linux/crc32c.h>
|
||||
#include <linux/namei.h>
|
||||
#include <linux/splice.h>
|
||||
|
||||
#include "glob.h"
|
||||
|
|
@ -56,7 +55,7 @@ static int ksmbd_vfs_path_lookup(struct ksmbd_share_config *share_conf,
|
|||
{
|
||||
struct qstr last;
|
||||
const struct path *root_share_path = &share_conf->vfs_path;
|
||||
int err, type;
|
||||
int err;
|
||||
struct dentry *d;
|
||||
|
||||
if (pathname[0] == '\0') {
|
||||
|
|
@ -67,17 +66,11 @@ static int ksmbd_vfs_path_lookup(struct ksmbd_share_config *share_conf,
|
|||
}
|
||||
|
||||
CLASS(filename_kernel, filename)(pathname);
|
||||
err = vfs_path_parent_lookup(filename, flags,
|
||||
path, &last, &type,
|
||||
err = vfs_path_parent_lookup(filename, flags, path, &last,
|
||||
root_share_path);
|
||||
if (err)
|
||||
return err;
|
||||
|
||||
if (unlikely(type != LAST_NORM)) {
|
||||
path_put(path);
|
||||
return -ENOENT;
|
||||
}
|
||||
|
||||
if (for_remove) {
|
||||
err = mnt_want_write(path->mnt);
|
||||
if (err) {
|
||||
|
|
@ -668,7 +661,6 @@ int ksmbd_vfs_rename(struct ksmbd_work *work, const struct path *old_path,
|
|||
struct renamedata rd;
|
||||
struct ksmbd_share_config *share_conf = work->tcon->share_conf;
|
||||
struct ksmbd_file *parent_fp;
|
||||
int new_type;
|
||||
int err, lookup_flags = LOOKUP_NO_SYMLINKS;
|
||||
|
||||
if (ksmbd_override_fsids(work))
|
||||
|
|
@ -678,8 +670,7 @@ int ksmbd_vfs_rename(struct ksmbd_work *work, const struct path *old_path,
|
|||
|
||||
retry:
|
||||
err = vfs_path_parent_lookup(to, lookup_flags | LOOKUP_BENEATH,
|
||||
&new_path, &new_last, &new_type,
|
||||
&share_conf->vfs_path);
|
||||
&new_path, &new_last, &share_conf->vfs_path);
|
||||
if (err)
|
||||
goto out1;
|
||||
|
||||
|
|
|
|||
|
|
@ -4,13 +4,31 @@
|
|||
|
||||
#include <linux/stat.h>
|
||||
#include <uapi/linux/fcntl.h>
|
||||
#include <uapi/linux/openat2.h>
|
||||
|
||||
/* List of all valid flags for the open/openat flags argument: */
|
||||
#define VALID_OPEN_FLAGS \
|
||||
(O_RDONLY | O_WRONLY | O_RDWR | O_CREAT | O_EXCL | O_NOCTTY | O_TRUNC | \
|
||||
O_APPEND | O_NDELAY | O_NONBLOCK | __O_SYNC | O_DSYNC | \
|
||||
FASYNC | O_DIRECT | O_LARGEFILE | O_DIRECTORY | O_NOFOLLOW | \
|
||||
O_NOATIME | O_CLOEXEC | O_PATH | __O_TMPFILE)
|
||||
O_NOATIME | O_CLOEXEC | O_PATH | __O_TMPFILE | O_EMPTYPATH)
|
||||
|
||||
/* List of all valid flags for openat2(2)'s how->flags argument. */
|
||||
#define VALID_OPENAT2_FLAGS (VALID_OPEN_FLAGS | OPENAT2_REGULAR)
|
||||
|
||||
/*
|
||||
* Kernel-internal carrier for OPENAT2_REGULAR. The UAPI bit lives in the
|
||||
* upper 32 bits of open_how::flags so open()/openat() cannot encode it.
|
||||
* build_open_flags() translates it to this internal flag, which then
|
||||
* propagates through op->open_flag and f->f_flags exactly like __FMODE_EXEC.
|
||||
* do_dentry_open() strips it so userspace cannot observe it via
|
||||
* fcntl(F_GETFL).
|
||||
*
|
||||
* Bit 30 is not claimed by any O_* flag on any architecture and stays clear
|
||||
* of the sign bit of the int op->open_flag. fcntl_init() enforces that it
|
||||
* never aliases an open-flag bit.
|
||||
*/
|
||||
#define __O_REGULAR (1 << 30)
|
||||
|
||||
/* List of all valid flags for the how->resolve argument: */
|
||||
#define VALID_RESOLVE_FLAGS \
|
||||
|
|
|
|||
|
|
@ -13,11 +13,6 @@ enum { MAX_NESTED_LINKS = 8 };
|
|||
|
||||
#define MAXSYMLINKS 40
|
||||
|
||||
/*
|
||||
* Type of the last component on LOOKUP_PARENT
|
||||
*/
|
||||
enum {LAST_NORM, LAST_ROOT, LAST_DOT, LAST_DOTDOT};
|
||||
|
||||
/* pathwalk mode */
|
||||
#define LOOKUP_FOLLOW BIT(0) /* follow links at the end */
|
||||
#define LOOKUP_DIRECTORY BIT(1) /* require a directory */
|
||||
|
|
@ -67,7 +62,7 @@ static inline void end_removing_path(const struct path *path , struct dentry *de
|
|||
end_creating_path(path, dentry);
|
||||
}
|
||||
int vfs_path_parent_lookup(struct filename *filename, unsigned int flags,
|
||||
struct path *parent, struct qstr *last, int *type,
|
||||
struct path *parent, struct qstr *last,
|
||||
const struct path *root);
|
||||
int vfs_path_lookup(struct dentry *, struct vfsmount *, const char *,
|
||||
unsigned int, struct path *);
|
||||
|
|
|
|||
|
|
@ -122,4 +122,6 @@
|
|||
|
||||
#define EHWPOISON 133 /* Memory page has hardware error */
|
||||
|
||||
#define EFTYPE 134 /* Wrong file type for the intended operation */
|
||||
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -88,6 +88,10 @@
|
|||
#define __O_TMPFILE 020000000
|
||||
#endif
|
||||
|
||||
#ifndef O_EMPTYPATH
|
||||
#define O_EMPTYPATH (1 << 26) /* allow empty path */
|
||||
#endif
|
||||
|
||||
/* a horrid kludge trying to make sure that this will fail on old kernels */
|
||||
#define O_TMPFILE (__O_TMPFILE | O_DIRECTORY)
|
||||
|
||||
|
|
|
|||
|
|
@ -22,6 +22,13 @@ struct open_how {
|
|||
__u64 resolve;
|
||||
};
|
||||
|
||||
/*
|
||||
* how->flags bits exclusive to openat2(2). These live in the upper 32 bits
|
||||
* of @flags so that they cannot be expressed by open(2) / openat(2), whose
|
||||
* @flags argument is a C int.
|
||||
*/
|
||||
#define OPENAT2_REGULAR ((__u64)1 << 32) /* Only open regular files. */
|
||||
|
||||
/* how->resolve flags for openat2(2). */
|
||||
#define RESOLVE_NO_XDEV 0x01 /* Block mount-point crossings
|
||||
(includes bind-mounts). */
|
||||
|
|
|
|||
|
|
@ -127,4 +127,6 @@
|
|||
|
||||
#define EHWPOISON 139 /* Memory page has hardware error */
|
||||
|
||||
#define EFTYPE 140 /* Wrong file type for the intended operation */
|
||||
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -126,6 +126,8 @@
|
|||
|
||||
#define EHWPOISON 168 /* Memory page has hardware error */
|
||||
|
||||
#define EFTYPE 169 /* Wrong file type for the intended operation */
|
||||
|
||||
#define EDQUOT 1133 /* Quota exceeded */
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -124,4 +124,6 @@
|
|||
|
||||
#define EHWPOISON 257 /* Memory page has hardware error */
|
||||
|
||||
#define EFTYPE 258 /* Wrong file type for the intended operation */
|
||||
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -117,4 +117,6 @@
|
|||
|
||||
#define EHWPOISON 135 /* Memory page has hardware error */
|
||||
|
||||
#define EFTYPE 136 /* Wrong file type for the intended operation */
|
||||
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -122,4 +122,6 @@
|
|||
|
||||
#define EHWPOISON 133 /* Memory page has hardware error */
|
||||
|
||||
#define EFTYPE 134 /* Wrong file type for the intended operation */
|
||||
|
||||
#endif
|
||||
|
|
|
|||
43
tools/include/uapi/linux/openat2.h
Normal file
43
tools/include/uapi/linux/openat2.h
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
/* SPDX-License-Identifier: GPL-2.0 WITH Linux-syscall-note */
|
||||
#ifndef _LINUX_OPENAT2_H
|
||||
#define _LINUX_OPENAT2_H
|
||||
|
||||
#include <linux/types.h>
|
||||
|
||||
/*
|
||||
* Arguments for how openat2(2) should open the target path. If only @flags and
|
||||
* @mode are non-zero, then openat2(2) operates very similarly to openat(2).
|
||||
*
|
||||
* However, unlike openat(2), unknown or invalid bits in @flags result in
|
||||
* -EINVAL rather than being silently ignored. @mode must be zero unless one of
|
||||
* {O_CREAT, O_TMPFILE} are set.
|
||||
*
|
||||
* @flags: O_* flags.
|
||||
* @mode: O_CREAT/O_TMPFILE file mode.
|
||||
* @resolve: RESOLVE_* flags.
|
||||
*/
|
||||
struct open_how {
|
||||
__u64 flags;
|
||||
__u64 mode;
|
||||
__u64 resolve;
|
||||
};
|
||||
|
||||
/* how->resolve flags for openat2(2). */
|
||||
#define RESOLVE_NO_XDEV 0x01 /* Block mount-point crossings
|
||||
(includes bind-mounts). */
|
||||
#define RESOLVE_NO_MAGICLINKS 0x02 /* Block traversal through procfs-style
|
||||
"magic-links". */
|
||||
#define RESOLVE_NO_SYMLINKS 0x04 /* Block traversal through all symlinks
|
||||
(implies OEXT_NO_MAGICLINKS) */
|
||||
#define RESOLVE_BENEATH 0x08 /* Block "lexical" trickery like
|
||||
"..", symlinks, and absolute
|
||||
paths which escape the dirfd. */
|
||||
#define RESOLVE_IN_ROOT 0x10 /* Make all jumps to "/" and ".."
|
||||
be scoped inside the dirfd
|
||||
(similar to chroot(2)). */
|
||||
#define RESOLVE_CACHED 0x20 /* Only complete if resolution can be
|
||||
completed through cached lookup. May
|
||||
return -EAGAIN if that's not
|
||||
possible. */
|
||||
|
||||
#endif /* _LINUX_OPENAT2_H */
|
||||
|
|
@ -1,7 +1,8 @@
|
|||
# SPDX-License-Identifier: GPL-2.0-or-later
|
||||
|
||||
CFLAGS += -Wall -O2 -g -fsanitize=address -fsanitize=undefined
|
||||
TEST_GEN_PROGS := openat2_test resolve_test rename_attack_test
|
||||
CFLAGS += $(KHDR_INCLUDES)
|
||||
CFLAGS += -Wall -O2 -g -fsanitize=address -fsanitize=undefined $(TOOLS_INCLUDES)
|
||||
TEST_GEN_PROGS := openat2_test resolve_test rename_attack_test emptypath_test
|
||||
|
||||
# gcc requires -static-libasan in order to ensure that Address Sanitizer's
|
||||
# library is the first one loaded. However, clang already statically links the
|
||||
|
|
@ -13,6 +14,4 @@ endif
|
|||
|
||||
LOCAL_HDRS += helpers.h
|
||||
|
||||
include ../lib.mk
|
||||
|
||||
$(TEST_GEN_PROGS): helpers.c
|
||||
include ../../lib.mk
|
||||
77
tools/testing/selftests/filesystems/openat2/emptypath_test.c
Normal file
77
tools/testing/selftests/filesystems/openat2/emptypath_test.c
Normal file
|
|
@ -0,0 +1,77 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-or-later
|
||||
|
||||
#define _GNU_SOURCE
|
||||
#define __SANE_USERSPACE_TYPES__
|
||||
#include <fcntl.h>
|
||||
#include <unistd.h>
|
||||
#include <errno.h>
|
||||
#include <string.h>
|
||||
#include <sys/stat.h>
|
||||
|
||||
#include "kselftest_harness.h"
|
||||
|
||||
#ifndef O_EMPTYPATH
|
||||
#define O_EMPTYPATH (1 << 26)
|
||||
#endif
|
||||
|
||||
#define EMPTYPATH_TEST_FILE "/tmp/emptypath_test"
|
||||
|
||||
FIXTURE(emptypath) {
|
||||
int opath_fd;
|
||||
};
|
||||
|
||||
FIXTURE_SETUP(emptypath)
|
||||
{
|
||||
int fd;
|
||||
|
||||
self->opath_fd = -1;
|
||||
|
||||
fd = open(EMPTYPATH_TEST_FILE, O_CREAT | O_WRONLY, S_IRWXU);
|
||||
ASSERT_GE(fd, 0) {
|
||||
TH_LOG("create %s: %s", EMPTYPATH_TEST_FILE, strerror(errno));
|
||||
}
|
||||
close(fd);
|
||||
|
||||
self->opath_fd = open(EMPTYPATH_TEST_FILE, O_PATH);
|
||||
ASSERT_GE(self->opath_fd, 0) {
|
||||
TH_LOG("open %s O_PATH: %s", EMPTYPATH_TEST_FILE, strerror(errno));
|
||||
}
|
||||
}
|
||||
|
||||
FIXTURE_TEARDOWN(emptypath)
|
||||
{
|
||||
if (self->opath_fd >= 0)
|
||||
close(self->opath_fd);
|
||||
unlink(EMPTYPATH_TEST_FILE);
|
||||
}
|
||||
|
||||
/* An empty path is rejected with ENOENT unless O_EMPTYPATH is set. */
|
||||
TEST_F(emptypath, without_flag_returns_enoent)
|
||||
{
|
||||
int fd = openat(self->opath_fd, "", O_RDONLY);
|
||||
|
||||
if (fd >= 0)
|
||||
close(fd);
|
||||
ASSERT_LT(fd, 0) {
|
||||
TH_LOG("empty path without O_EMPTYPATH unexpectedly succeeded");
|
||||
}
|
||||
EXPECT_EQ(errno, ENOENT) {
|
||||
TH_LOG("expected ENOENT, got %s", strerror(errno));
|
||||
}
|
||||
}
|
||||
|
||||
/* O_EMPTYPATH reopens the O_PATH fd through an empty path. */
|
||||
TEST_F(emptypath, reopens_opath_fd)
|
||||
{
|
||||
int fd = openat(self->opath_fd, "", O_RDONLY | O_EMPTYPATH);
|
||||
|
||||
if (fd < 0 && errno == EINVAL)
|
||||
SKIP(return, "O_EMPTYPATH not supported");
|
||||
|
||||
ASSERT_GE(fd, 0) {
|
||||
TH_LOG("O_EMPTYPATH failed: %s", strerror(errno));
|
||||
}
|
||||
close(fd);
|
||||
}
|
||||
|
||||
TEST_HARNESS_MAIN
|
||||
135
tools/testing/selftests/filesystems/openat2/helpers.h
Normal file
135
tools/testing/selftests/filesystems/openat2/helpers.h
Normal file
|
|
@ -0,0 +1,135 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-or-later
|
||||
/*
|
||||
* Author: Aleksa Sarai <cyphar@cyphar.com>
|
||||
* Copyright (C) 2018-2019 SUSE LLC.
|
||||
* Copyright (C) 2026 Amutable GmbH
|
||||
*/
|
||||
|
||||
#ifndef __RESOLVEAT_H__
|
||||
#define __RESOLVEAT_H__
|
||||
|
||||
#define _GNU_SOURCE
|
||||
#include <stdint.h>
|
||||
#include <stdbool.h>
|
||||
#include <errno.h>
|
||||
#include <limits.h>
|
||||
#include <linux/types.h>
|
||||
#include <linux/unistd.h>
|
||||
#include <linux/openat2.h>
|
||||
#include "kselftest_harness.h"
|
||||
|
||||
#define BUILD_BUG_ON(e) ((void)(sizeof(struct { int:(-!!(e)); })))
|
||||
|
||||
#define OPEN_HOW_SIZE_VER0 24 /* sizeof first published struct */
|
||||
#define OPEN_HOW_SIZE_LATEST OPEN_HOW_SIZE_VER0
|
||||
|
||||
__maybe_unused
|
||||
static bool needs_openat2(const struct open_how *how)
|
||||
{
|
||||
return how->resolve != 0;
|
||||
}
|
||||
|
||||
__maybe_unused
|
||||
static int raw_openat2(int dfd, const char *path, void *how, size_t size)
|
||||
{
|
||||
int ret = syscall(__NR_openat2, dfd, path, how, size);
|
||||
|
||||
return ret >= 0 ? ret : -errno;
|
||||
}
|
||||
|
||||
__maybe_unused
|
||||
static int sys_openat2(int dfd, const char *path, struct open_how *how)
|
||||
{
|
||||
return raw_openat2(dfd, path, how, sizeof(*how));
|
||||
}
|
||||
|
||||
__maybe_unused
|
||||
static int sys_openat(int dfd, const char *path, struct open_how *how)
|
||||
{
|
||||
int ret = openat(dfd, path, how->flags, how->mode);
|
||||
|
||||
return ret >= 0 ? ret : -errno;
|
||||
}
|
||||
|
||||
__maybe_unused
|
||||
static int sys_renameat2(int olddirfd, const char *oldpath,
|
||||
int newdirfd, const char *newpath, unsigned int flags)
|
||||
{
|
||||
int ret = syscall(__NR_renameat2, olddirfd, oldpath,
|
||||
newdirfd, newpath, flags);
|
||||
|
||||
return ret >= 0 ? ret : -errno;
|
||||
}
|
||||
|
||||
__maybe_unused
|
||||
static int touchat(int dfd, const char *path)
|
||||
{
|
||||
int fd = openat(dfd, path, O_CREAT, 0700);
|
||||
|
||||
if (fd >= 0)
|
||||
close(fd);
|
||||
return fd;
|
||||
}
|
||||
|
||||
__maybe_unused
|
||||
static char *fdreadlink(struct __test_metadata *_metadata, int fd)
|
||||
{
|
||||
char *target, *tmp;
|
||||
|
||||
ASSERT_GT(asprintf(&tmp, "/proc/self/fd/%d", fd), 0);
|
||||
|
||||
target = malloc(PATH_MAX);
|
||||
ASSERT_NE(target, NULL);
|
||||
memset(target, 0, PATH_MAX);
|
||||
|
||||
ASSERT_GT(readlink(tmp, target, PATH_MAX), 0);
|
||||
|
||||
free(tmp);
|
||||
return target;
|
||||
}
|
||||
|
||||
__maybe_unused
|
||||
static bool fdequal(struct __test_metadata *_metadata, int fd,
|
||||
int dfd, const char *path)
|
||||
{
|
||||
char *fdpath, *dfdpath, *other;
|
||||
bool cmp;
|
||||
|
||||
fdpath = fdreadlink(_metadata, fd);
|
||||
dfdpath = fdreadlink(_metadata, dfd);
|
||||
|
||||
if (!path) {
|
||||
ASSERT_GT(asprintf(&other, "%s", dfdpath), 0);
|
||||
} else if (*path == '/') {
|
||||
ASSERT_GT(asprintf(&other, "%s", path), 0);
|
||||
} else {
|
||||
ASSERT_GT(asprintf(&other, "%s/%s", dfdpath, path), 0);
|
||||
}
|
||||
|
||||
cmp = !strcmp(fdpath, other);
|
||||
|
||||
free(fdpath);
|
||||
free(dfdpath);
|
||||
free(other);
|
||||
return cmp;
|
||||
}
|
||||
|
||||
static bool openat2_supported = false;
|
||||
|
||||
__attribute__((constructor))
|
||||
static void __detect_openat2_supported(void)
|
||||
{
|
||||
struct open_how how = {};
|
||||
int fd;
|
||||
|
||||
BUILD_BUG_ON(sizeof(struct open_how) != OPEN_HOW_SIZE_VER0);
|
||||
|
||||
/* Check openat2(2) support. */
|
||||
fd = sys_openat2(AT_FDCWD, ".", &how);
|
||||
openat2_supported = (fd >= 0);
|
||||
|
||||
if (fd >= 0)
|
||||
close(fd);
|
||||
}
|
||||
|
||||
#endif /* __RESOLVEAT_H__ */
|
||||
|
|
@ -15,8 +15,8 @@
|
|||
#include <stdbool.h>
|
||||
#include <string.h>
|
||||
|
||||
#include "kselftest.h"
|
||||
#include "helpers.h"
|
||||
#include "kselftest_harness.h"
|
||||
|
||||
/*
|
||||
* O_LARGEFILE is set to 0 by glibc.
|
||||
|
|
@ -45,13 +45,29 @@ struct struct_test {
|
|||
int err;
|
||||
};
|
||||
|
||||
#define NUM_OPENAT2_STRUCT_TESTS 7
|
||||
#define NUM_OPENAT2_STRUCT_VARIATIONS 13
|
||||
struct flag_test {
|
||||
const char *name;
|
||||
struct open_how how;
|
||||
int err;
|
||||
};
|
||||
|
||||
void test_openat2_struct(void)
|
||||
FIXTURE(openat2) {};
|
||||
|
||||
FIXTURE_SETUP(openat2)
|
||||
{
|
||||
if (!openat2_supported)
|
||||
SKIP(return, "openat2(2) not supported");
|
||||
}
|
||||
|
||||
FIXTURE_TEARDOWN(openat2) {}
|
||||
|
||||
/*
|
||||
* Verify that the struct size and misalignment handling for openat2(2) is
|
||||
* correct, including that is_zeroed_user() works.
|
||||
*/
|
||||
TEST_F(openat2, struct_argument_sizes)
|
||||
{
|
||||
int misalignments[] = { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 11, 17, 87 };
|
||||
|
||||
struct struct_test tests[] = {
|
||||
/* Normal struct. */
|
||||
{ .name = "normal struct",
|
||||
|
|
@ -83,26 +99,14 @@ void test_openat2_struct(void)
|
|||
.size = sizeof(struct open_how_ext), .err = -E2BIG },
|
||||
};
|
||||
|
||||
BUILD_BUG_ON(ARRAY_LEN(misalignments) != NUM_OPENAT2_STRUCT_VARIATIONS);
|
||||
BUILD_BUG_ON(ARRAY_LEN(tests) != NUM_OPENAT2_STRUCT_TESTS);
|
||||
|
||||
for (int i = 0; i < ARRAY_LEN(tests); i++) {
|
||||
for (int i = 0; i < ARRAY_SIZE(tests); i++) {
|
||||
struct struct_test *test = &tests[i];
|
||||
struct open_how_ext how_ext = test->arg;
|
||||
|
||||
for (int j = 0; j < ARRAY_LEN(misalignments); j++) {
|
||||
for (int j = 0; j < ARRAY_SIZE(misalignments); j++) {
|
||||
int fd, misalign = misalignments[j];
|
||||
char *fdpath = NULL;
|
||||
bool failed;
|
||||
void (*resultfn)(const char *msg, ...) = ksft_test_result_pass;
|
||||
|
||||
void *copy = NULL, *how_copy = &how_ext;
|
||||
|
||||
if (!openat2_supported) {
|
||||
ksft_print_msg("openat2(2) unsupported\n");
|
||||
resultfn = ksft_test_result_skip;
|
||||
goto skip;
|
||||
}
|
||||
char *fdpath = NULL;
|
||||
|
||||
if (misalign) {
|
||||
/*
|
||||
|
|
@ -119,50 +123,42 @@ void test_openat2_struct(void)
|
|||
}
|
||||
|
||||
fd = raw_openat2(AT_FDCWD, ".", how_copy, test->size);
|
||||
if (test->err >= 0)
|
||||
failed = (fd < 0);
|
||||
else
|
||||
failed = (fd != test->err);
|
||||
if (fd >= 0) {
|
||||
fdpath = fdreadlink(fd);
|
||||
fdpath = fdreadlink(_metadata, fd);
|
||||
close(fd);
|
||||
}
|
||||
|
||||
if (failed) {
|
||||
resultfn = ksft_test_result_fail;
|
||||
|
||||
ksft_print_msg("openat2 unexpectedly returned ");
|
||||
if (fdpath)
|
||||
ksft_print_msg("%d['%s']\n", fd, fdpath);
|
||||
else
|
||||
ksft_print_msg("%d (%s)\n", fd, strerror(-fd));
|
||||
if (test->err >= 0) {
|
||||
EXPECT_GE(fd, 0) {
|
||||
TH_LOG("openat2 with %s [misalign=%d] should succeed, got %d (%s)",
|
||||
test->name, misalign,
|
||||
fd, strerror(-fd));
|
||||
}
|
||||
} else {
|
||||
EXPECT_EQ(test->err, fd) {
|
||||
if (fdpath)
|
||||
TH_LOG("openat2 with %s [misalign=%d] should fail with %d (%s), got %d['%s']",
|
||||
test->name, misalign,
|
||||
test->err,
|
||||
strerror(-test->err),
|
||||
fd, fdpath);
|
||||
else
|
||||
TH_LOG("openat2 with %s [misalign=%d] should fail with %d (%s), got %d (%s)",
|
||||
test->name, misalign,
|
||||
test->err,
|
||||
strerror(-test->err),
|
||||
fd, strerror(-fd));
|
||||
}
|
||||
}
|
||||
|
||||
skip:
|
||||
if (test->err >= 0)
|
||||
resultfn("openat2 with %s argument [misalign=%d] succeeds\n",
|
||||
test->name, misalign);
|
||||
else
|
||||
resultfn("openat2 with %s argument [misalign=%d] fails with %d (%s)\n",
|
||||
test->name, misalign, test->err,
|
||||
strerror(-test->err));
|
||||
|
||||
free(copy);
|
||||
free(fdpath);
|
||||
fflush(stdout);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
struct flag_test {
|
||||
const char *name;
|
||||
struct open_how how;
|
||||
int err;
|
||||
};
|
||||
|
||||
#define NUM_OPENAT2_FLAG_TESTS 25
|
||||
|
||||
void test_openat2_flags(void)
|
||||
/* Verify openat2(2) flag and mode validation. */
|
||||
TEST_F(openat2, flag_validation)
|
||||
{
|
||||
struct flag_test tests[] = {
|
||||
/* O_TMPFILE is incompatible with O_PATH and O_CREAT. */
|
||||
|
|
@ -241,20 +237,10 @@ void test_openat2_flags(void)
|
|||
.how.resolve = 0, .err = -EINVAL },
|
||||
};
|
||||
|
||||
BUILD_BUG_ON(ARRAY_LEN(tests) != NUM_OPENAT2_FLAG_TESTS);
|
||||
|
||||
for (int i = 0; i < ARRAY_LEN(tests); i++) {
|
||||
for (int i = 0; i < ARRAY_SIZE(tests); i++) {
|
||||
int fd, fdflags = -1;
|
||||
char *path, *fdpath = NULL;
|
||||
bool failed = false;
|
||||
struct flag_test *test = &tests[i];
|
||||
void (*resultfn)(const char *msg, ...) = ksft_test_result_pass;
|
||||
|
||||
if (!openat2_supported) {
|
||||
ksft_print_msg("openat2(2) unsupported\n");
|
||||
resultfn = ksft_test_result_skip;
|
||||
goto skip;
|
||||
}
|
||||
|
||||
path = (test->how.flags & O_CREAT) ? "/tmp/ksft.openat2_tmpfile" : ".";
|
||||
unlink(path);
|
||||
|
|
@ -265,74 +251,112 @@ void test_openat2_flags(void)
|
|||
* Skip the testcase if it failed because not supported
|
||||
* by FS. (e.g. a valid O_TMPFILE combination on NFS)
|
||||
*/
|
||||
ksft_test_result_skip("openat2 with %s fails with %d (%s)\n",
|
||||
test->name, fd, strerror(-fd));
|
||||
goto next;
|
||||
TH_LOG("openat2 with %s not supported by FS -- skipping",
|
||||
test->name);
|
||||
continue;
|
||||
}
|
||||
|
||||
if (test->err >= 0)
|
||||
failed = (fd < 0);
|
||||
else
|
||||
failed = (fd != test->err);
|
||||
if (fd >= 0) {
|
||||
int otherflags;
|
||||
if (test->err >= 0) {
|
||||
EXPECT_GE(fd, 0) {
|
||||
TH_LOG("openat2 with %s should succeed, got %d (%s)",
|
||||
test->name, fd, strerror(-fd));
|
||||
}
|
||||
if (fd >= 0) {
|
||||
int otherflags;
|
||||
|
||||
fdpath = fdreadlink(fd);
|
||||
fdflags = fcntl(fd, F_GETFL);
|
||||
otherflags = fcntl(fd, F_GETFD);
|
||||
close(fd);
|
||||
fdpath = fdreadlink(_metadata, fd);
|
||||
fdflags = fcntl(fd, F_GETFL);
|
||||
otherflags = fcntl(fd, F_GETFD);
|
||||
close(fd);
|
||||
|
||||
E_assert(fdflags >= 0, "fcntl F_GETFL of new fd");
|
||||
E_assert(otherflags >= 0, "fcntl F_GETFD of new fd");
|
||||
ASSERT_GE(fdflags, 0);
|
||||
ASSERT_GE(otherflags, 0);
|
||||
|
||||
/* O_CLOEXEC isn't shown in F_GETFL. */
|
||||
if (otherflags & FD_CLOEXEC)
|
||||
fdflags |= O_CLOEXEC;
|
||||
/* O_CREAT is hidden from F_GETFL. */
|
||||
if (test->how.flags & O_CREAT)
|
||||
fdflags |= O_CREAT;
|
||||
if (!(test->how.flags & O_LARGEFILE))
|
||||
fdflags &= ~O_LARGEFILE;
|
||||
failed |= (fdflags != test->how.flags);
|
||||
/* O_CLOEXEC isn't shown in F_GETFL. */
|
||||
if (otherflags & FD_CLOEXEC)
|
||||
fdflags |= O_CLOEXEC;
|
||||
/* O_CREAT is hidden from F_GETFL. */
|
||||
if (test->how.flags & O_CREAT)
|
||||
fdflags |= O_CREAT;
|
||||
if (!(test->how.flags & O_LARGEFILE))
|
||||
fdflags &= ~O_LARGEFILE;
|
||||
|
||||
EXPECT_EQ(fdflags, (int)test->how.flags) {
|
||||
TH_LOG("openat2 with %s: flags mismatch %X != %llX",
|
||||
test->name, fdflags,
|
||||
(unsigned long long)test->how.flags);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
EXPECT_EQ(test->err, fd) {
|
||||
if (fd >= 0) {
|
||||
fdpath = fdreadlink(_metadata, fd);
|
||||
TH_LOG("openat2 with %s should fail with %d (%s), got %d['%s']",
|
||||
test->name, test->err,
|
||||
strerror(-test->err),
|
||||
fd, fdpath);
|
||||
} else {
|
||||
TH_LOG("openat2 with %s should fail with %d (%s), got %d (%s)",
|
||||
test->name, test->err,
|
||||
strerror(-test->err),
|
||||
fd, strerror(-fd));
|
||||
}
|
||||
}
|
||||
if (fd >= 0)
|
||||
close(fd);
|
||||
}
|
||||
|
||||
if (failed) {
|
||||
resultfn = ksft_test_result_fail;
|
||||
|
||||
ksft_print_msg("openat2 unexpectedly returned ");
|
||||
if (fdpath)
|
||||
ksft_print_msg("%d['%s'] with %X (!= %llX)\n",
|
||||
fd, fdpath, fdflags,
|
||||
test->how.flags);
|
||||
else
|
||||
ksft_print_msg("%d (%s)\n", fd, strerror(-fd));
|
||||
}
|
||||
|
||||
skip:
|
||||
if (test->err >= 0)
|
||||
resultfn("openat2 with %s succeeds\n", test->name);
|
||||
else
|
||||
resultfn("openat2 with %s fails with %d (%s)\n",
|
||||
test->name, test->err, strerror(-test->err));
|
||||
next:
|
||||
free(fdpath);
|
||||
fflush(stdout);
|
||||
}
|
||||
}
|
||||
|
||||
#define NUM_TESTS (NUM_OPENAT2_STRUCT_VARIATIONS * NUM_OPENAT2_STRUCT_TESTS + \
|
||||
NUM_OPENAT2_FLAG_TESTS)
|
||||
#ifndef OPENAT2_REGULAR
|
||||
#define OPENAT2_REGULAR ((__u64)1 << 32)
|
||||
#endif
|
||||
|
||||
int main(int argc, char **argv)
|
||||
#ifndef EFTYPE
|
||||
#define EFTYPE 134
|
||||
#endif
|
||||
|
||||
/* Kernel-internal carrier for OPENAT2_REGULAR (see __O_REGULAR in fcntl.h). */
|
||||
#ifndef __O_REGULAR
|
||||
#define __O_REGULAR (1 << 30)
|
||||
#endif
|
||||
|
||||
/* Verify that OPENAT2_REGULAR rejects non-regular files with EFTYPE. */
|
||||
TEST_F(openat2, regular_flag)
|
||||
{
|
||||
ksft_print_header();
|
||||
ksft_set_plan(NUM_TESTS);
|
||||
struct open_how how = {
|
||||
.flags = OPENAT2_REGULAR | O_RDONLY,
|
||||
};
|
||||
int fd;
|
||||
|
||||
test_openat2_struct();
|
||||
test_openat2_flags();
|
||||
fd = sys_openat2(AT_FDCWD, "/dev/null", &how);
|
||||
if (fd == -ENOENT)
|
||||
SKIP(return, "/dev/null does not exist");
|
||||
|
||||
if (ksft_get_fail_cnt() + ksft_get_error_cnt() > 0)
|
||||
ksft_exit_fail();
|
||||
else
|
||||
ksft_exit_pass();
|
||||
EXPECT_EQ(-EFTYPE, fd) {
|
||||
TH_LOG("openat2 with OPENAT2_REGULAR should fail with %d (%s), got %d (%s)",
|
||||
-EFTYPE, strerror(EFTYPE), fd, strerror(-fd));
|
||||
}
|
||||
if (fd >= 0)
|
||||
close(fd);
|
||||
}
|
||||
|
||||
/* open()/openat() must keep ignoring the internal __O_REGULAR bit. */
|
||||
TEST(legacy_openat_ignores_o_regular)
|
||||
{
|
||||
int fd;
|
||||
|
||||
fd = openat(AT_FDCWD, "/dev/null", O_RDONLY | __O_REGULAR);
|
||||
if (fd < 0 && errno == ENOENT)
|
||||
SKIP(return, "/dev/null does not exist");
|
||||
|
||||
ASSERT_GE(fd, 0) {
|
||||
TH_LOG("legacy openat() must ignore the __O_REGULAR carrier bit, got errno %d (%s)",
|
||||
errno, strerror(errno));
|
||||
}
|
||||
close(fd);
|
||||
}
|
||||
|
||||
TEST_HARNESS_MAIN
|
||||
159
tools/testing/selftests/filesystems/openat2/rename_attack_test.c
Normal file
159
tools/testing/selftests/filesystems/openat2/rename_attack_test.c
Normal file
|
|
@ -0,0 +1,159 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-or-later
|
||||
/*
|
||||
* Author: Aleksa Sarai <cyphar@cyphar.com>
|
||||
* Copyright (C) 2018-2019 SUSE LLC.
|
||||
*/
|
||||
|
||||
#define _GNU_SOURCE
|
||||
#include <errno.h>
|
||||
#include <fcntl.h>
|
||||
#include <sched.h>
|
||||
#include <sys/stat.h>
|
||||
#include <sys/types.h>
|
||||
#include <sys/mount.h>
|
||||
#include <sys/mman.h>
|
||||
#include <sys/prctl.h>
|
||||
#include <signal.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <stdbool.h>
|
||||
#include <string.h>
|
||||
#include <syscall.h>
|
||||
#include <limits.h>
|
||||
#include <unistd.h>
|
||||
|
||||
#include "helpers.h"
|
||||
#include "kselftest_harness.h"
|
||||
|
||||
#define ROUNDS 400000
|
||||
|
||||
/* Swap @dirfd/@a and @dirfd/@b constantly. Parent must kill this process. */
|
||||
pid_t spawn_attack(struct __test_metadata *_metadata,
|
||||
int dirfd, char *a, char *b)
|
||||
{
|
||||
pid_t child = fork();
|
||||
if (child != 0)
|
||||
return child;
|
||||
|
||||
/* If the parent (the test process) dies, kill ourselves too. */
|
||||
ASSERT_EQ(prctl(PR_SET_PDEATHSIG, SIGKILL), 0);
|
||||
|
||||
/* Swap @a and @b. */
|
||||
for (;;)
|
||||
renameat2(dirfd, a, dirfd, b, RENAME_EXCHANGE);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/*
|
||||
* Construct a test directory with the following structure:
|
||||
*
|
||||
* root/
|
||||
* |-- a/
|
||||
* | `-- c/
|
||||
* `-- b/
|
||||
*/
|
||||
FIXTURE(rename_attack) {
|
||||
int dfd;
|
||||
int afd;
|
||||
pid_t child;
|
||||
};
|
||||
|
||||
FIXTURE_SETUP(rename_attack)
|
||||
{
|
||||
char dirname[] = "/tmp/ksft-openat2-rename-attack.XXXXXX";
|
||||
|
||||
self->dfd = -1;
|
||||
self->afd = -1;
|
||||
self->child = 0;
|
||||
|
||||
/* Make the top-level directory. */
|
||||
ASSERT_NE(mkdtemp(dirname), NULL);
|
||||
self->dfd = open(dirname, O_PATH | O_DIRECTORY);
|
||||
ASSERT_GE(self->dfd, 0);
|
||||
|
||||
ASSERT_EQ(mkdirat(self->dfd, "a", 0755), 0);
|
||||
ASSERT_EQ(mkdirat(self->dfd, "b", 0755), 0);
|
||||
ASSERT_EQ(mkdirat(self->dfd, "a/c", 0755), 0);
|
||||
|
||||
self->afd = openat(self->dfd, "a", O_PATH);
|
||||
ASSERT_GE(self->afd, 0);
|
||||
|
||||
self->child = spawn_attack(_metadata, self->dfd, "a/c", "b");
|
||||
ASSERT_GT(self->child, 0);
|
||||
}
|
||||
|
||||
FIXTURE_TEARDOWN(rename_attack)
|
||||
{
|
||||
if (self->child > 0)
|
||||
kill(self->child, SIGKILL);
|
||||
if (self->afd >= 0)
|
||||
close(self->afd);
|
||||
if (self->dfd >= 0)
|
||||
close(self->dfd);
|
||||
}
|
||||
|
||||
FIXTURE_VARIANT(rename_attack) {
|
||||
int resolve;
|
||||
const char *name;
|
||||
};
|
||||
|
||||
FIXTURE_VARIANT_ADD(rename_attack, resolve_beneath) {
|
||||
.resolve = RESOLVE_BENEATH,
|
||||
.name = "RESOLVE_BENEATH",
|
||||
};
|
||||
|
||||
FIXTURE_VARIANT_ADD(rename_attack, resolve_in_root) {
|
||||
.resolve = RESOLVE_IN_ROOT,
|
||||
.name = "RESOLVE_IN_ROOT",
|
||||
};
|
||||
|
||||
TEST_F_TIMEOUT(rename_attack, test, 120)
|
||||
{
|
||||
int escapes = 0, successes = 0, other_errs = 0, exdevs = 0, eagains = 0;
|
||||
char *victim_path = "c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../..";
|
||||
struct open_how how = {
|
||||
.flags = O_PATH,
|
||||
.resolve = variant->resolve,
|
||||
};
|
||||
|
||||
if (!openat2_supported) {
|
||||
how.resolve = 0;
|
||||
TH_LOG("openat2(2) unsupported -- using openat(2) instead");
|
||||
}
|
||||
|
||||
for (int i = 0; i < ROUNDS; i++) {
|
||||
int fd;
|
||||
|
||||
if (openat2_supported)
|
||||
fd = sys_openat2(self->afd, victim_path, &how);
|
||||
else
|
||||
fd = sys_openat(self->afd, victim_path, &how);
|
||||
|
||||
if (fd < 0) {
|
||||
if (fd == -EAGAIN)
|
||||
eagains++;
|
||||
else if (fd == -EXDEV)
|
||||
exdevs++;
|
||||
else if (fd == -ENOENT)
|
||||
escapes++; /* escaped outside and got ENOENT... */
|
||||
else
|
||||
other_errs++; /* unexpected error */
|
||||
} else {
|
||||
if (fdequal(_metadata, fd, self->afd, NULL))
|
||||
successes++;
|
||||
else
|
||||
escapes++; /* we got an unexpected fd */
|
||||
}
|
||||
if (fd >= 0)
|
||||
close(fd);
|
||||
}
|
||||
|
||||
TH_LOG("non-escapes: EAGAIN=%d EXDEV=%d E<other>=%d success=%d",
|
||||
eagains, exdevs, other_errs, successes);
|
||||
ASSERT_EQ(escapes, 0) {
|
||||
TH_LOG("rename attack with %s (%d runs, got %d escapes)",
|
||||
variant->name, ROUNDS, escapes);
|
||||
}
|
||||
}
|
||||
|
||||
TEST_HARNESS_MAIN
|
||||
|
|
@ -14,8 +14,81 @@
|
|||
#include <stdbool.h>
|
||||
#include <string.h>
|
||||
|
||||
#include "kselftest.h"
|
||||
#include "helpers.h"
|
||||
#include "kselftest_harness.h"
|
||||
|
||||
struct resolve_test {
|
||||
const char *name;
|
||||
const char *dir;
|
||||
const char *path;
|
||||
struct open_how how;
|
||||
bool pass;
|
||||
union {
|
||||
int err;
|
||||
const char *path;
|
||||
} out;
|
||||
};
|
||||
|
||||
/*
|
||||
* Verify a single resolve test case. This must be called from within a TEST_F
|
||||
* function with _metadata in scope.
|
||||
*/
|
||||
static void verify_resolve_test(struct __test_metadata *_metadata,
|
||||
int rootfd, int hardcoded_fd,
|
||||
const struct resolve_test *test)
|
||||
{
|
||||
struct open_how how = test->how;
|
||||
int dfd, fd;
|
||||
char *fdpath = NULL;
|
||||
|
||||
/* Auto-set O_PATH. */
|
||||
if (!(how.flags & O_CREAT))
|
||||
how.flags |= O_PATH;
|
||||
|
||||
if (test->dir)
|
||||
dfd = openat(rootfd, test->dir, O_PATH | O_DIRECTORY);
|
||||
else
|
||||
dfd = dup(rootfd);
|
||||
ASSERT_GE(dfd, 0) TH_LOG("failed to open dir '%s': %m", test->dir ?: ".");
|
||||
ASSERT_EQ(dup2(dfd, hardcoded_fd), hardcoded_fd);
|
||||
|
||||
fd = sys_openat2(dfd, test->path, &how);
|
||||
|
||||
if (test->pass) {
|
||||
EXPECT_GE(fd, 0) {
|
||||
TH_LOG("%s: expected success, got %d (%s)",
|
||||
test->name, fd, strerror(-fd));
|
||||
}
|
||||
if (fd >= 0) {
|
||||
EXPECT_TRUE(fdequal(_metadata, fd, rootfd, test->out.path)) {
|
||||
fdpath = fdreadlink(_metadata, fd);
|
||||
TH_LOG("%s: wrong path '%s', expected '%s'",
|
||||
test->name, fdpath,
|
||||
test->out.path ?: ".");
|
||||
free(fdpath);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
EXPECT_EQ(test->out.err, fd) {
|
||||
if (fd >= 0) {
|
||||
fdpath = fdreadlink(_metadata, fd);
|
||||
TH_LOG("%s: expected %d (%s), got %d['%s']",
|
||||
test->name, test->out.err,
|
||||
strerror(-test->out.err), fd, fdpath);
|
||||
free(fdpath);
|
||||
} else {
|
||||
TH_LOG("%s: expected %d (%s), got %d (%s)",
|
||||
test->name, test->out.err,
|
||||
strerror(-test->out.err),
|
||||
fd, strerror(-fd));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if (fd >= 0)
|
||||
close(fd);
|
||||
close(dfd);
|
||||
}
|
||||
|
||||
/*
|
||||
* Construct a test directory with the following structure:
|
||||
|
|
@ -39,101 +112,110 @@
|
|||
* |-- absself -> /
|
||||
* |-- self -> ../../root/
|
||||
* |-- garbageself -> /../../root/
|
||||
* |-- passwd -> ../cheeky/../cheeky/../etc/../etc/passwd
|
||||
* |-- abspasswd -> /../cheeky/../cheeky/../etc/../etc/passwd
|
||||
* |-- passwd -> ../cheeky/../etc/../etc/passwd
|
||||
* |-- abspasswd -> /../cheeky/../etc/../etc/passwd
|
||||
* |-- dotdotlink -> ../../../../../../../../../../../../../../etc/passwd
|
||||
* `-- garbagelink -> /../../../../../../../../../../../../../../etc/passwd
|
||||
*/
|
||||
int setup_testdir(void)
|
||||
FIXTURE(openat2_resolve) {
|
||||
int rootfd;
|
||||
int hardcoded_fd;
|
||||
char *hardcoded_fdpath;
|
||||
char *procselfexe;
|
||||
};
|
||||
|
||||
FIXTURE_SETUP(openat2_resolve)
|
||||
{
|
||||
int dfd, tmpfd;
|
||||
char dirname[] = "/tmp/ksft-openat2-testdir.XXXXXX";
|
||||
int dfd, tmpfd;
|
||||
|
||||
self->rootfd = -1;
|
||||
self->hardcoded_fd = -1;
|
||||
self->hardcoded_fdpath = NULL;
|
||||
self->procselfexe = NULL;
|
||||
|
||||
/* NOTE: We should be checking for CAP_SYS_ADMIN here... */
|
||||
if (geteuid() != 0)
|
||||
SKIP(return, "all tests require euid == 0");
|
||||
if (!openat2_supported)
|
||||
SKIP(return, "openat2(2) not supported");
|
||||
|
||||
/* Unshare and make /tmp a new directory. */
|
||||
E_unshare(CLONE_NEWNS);
|
||||
E_mount("", "/tmp", "", MS_PRIVATE, "");
|
||||
ASSERT_EQ(unshare(CLONE_NEWNS), 0);
|
||||
ASSERT_EQ(mount("", "/tmp", "", MS_PRIVATE, ""), 0);
|
||||
|
||||
/* Make the top-level directory. */
|
||||
if (!mkdtemp(dirname))
|
||||
ksft_exit_fail_msg("setup_testdir: failed to create tmpdir\n");
|
||||
ASSERT_NE(mkdtemp(dirname), NULL);
|
||||
dfd = open(dirname, O_PATH | O_DIRECTORY);
|
||||
if (dfd < 0)
|
||||
ksft_exit_fail_msg("setup_testdir: failed to open tmpdir\n");
|
||||
ASSERT_GE(dfd, 0);
|
||||
|
||||
/* A sub-directory which is actually used for tests. */
|
||||
E_mkdirat(dfd, "root", 0755);
|
||||
ASSERT_EQ(mkdirat(dfd, "root", 0755), 0);
|
||||
tmpfd = openat(dfd, "root", O_PATH | O_DIRECTORY);
|
||||
if (tmpfd < 0)
|
||||
ksft_exit_fail_msg("setup_testdir: failed to open tmpdir\n");
|
||||
ASSERT_GE(tmpfd, 0);
|
||||
close(dfd);
|
||||
dfd = tmpfd;
|
||||
|
||||
E_symlinkat("/proc/self/exe", dfd, "procexe");
|
||||
E_symlinkat("/proc/self/root", dfd, "procroot");
|
||||
E_mkdirat(dfd, "root", 0755);
|
||||
ASSERT_EQ(symlinkat("/proc/self/exe", dfd, "procexe"), 0);
|
||||
ASSERT_EQ(symlinkat("/proc/self/root", dfd, "procroot"), 0);
|
||||
ASSERT_EQ(mkdirat(dfd, "root", 0755), 0);
|
||||
|
||||
/* There is no mountat(2), so use chdir. */
|
||||
E_mkdirat(dfd, "mnt", 0755);
|
||||
E_fchdir(dfd);
|
||||
E_mount("tmpfs", "./mnt", "tmpfs", MS_NOSUID | MS_NODEV, "");
|
||||
E_symlinkat("../mnt/", dfd, "mnt/self");
|
||||
E_symlinkat("/mnt/", dfd, "mnt/absself");
|
||||
ASSERT_EQ(mkdirat(dfd, "mnt", 0755), 0);
|
||||
ASSERT_EQ(fchdir(dfd), 0);
|
||||
ASSERT_EQ(mount("tmpfs", "./mnt", "tmpfs", MS_NOSUID | MS_NODEV, ""), 0);
|
||||
ASSERT_EQ(symlinkat("../mnt/", dfd, "mnt/self"), 0);
|
||||
ASSERT_EQ(symlinkat("/mnt/", dfd, "mnt/absself"), 0);
|
||||
|
||||
E_mkdirat(dfd, "etc", 0755);
|
||||
E_touchat(dfd, "etc/passwd");
|
||||
ASSERT_EQ(mkdirat(dfd, "etc", 0755), 0);
|
||||
ASSERT_GE(touchat(dfd, "etc/passwd"), 0);
|
||||
|
||||
E_symlinkat("/newfile3", dfd, "creatlink");
|
||||
E_symlinkat("etc/", dfd, "reletc");
|
||||
E_symlinkat("etc/passwd", dfd, "relsym");
|
||||
E_symlinkat("/etc/", dfd, "absetc");
|
||||
E_symlinkat("/etc/passwd", dfd, "abssym");
|
||||
E_symlinkat("/cheeky", dfd, "abscheeky");
|
||||
ASSERT_EQ(symlinkat("/newfile3", dfd, "creatlink"), 0);
|
||||
ASSERT_EQ(symlinkat("etc/", dfd, "reletc"), 0);
|
||||
ASSERT_EQ(symlinkat("etc/passwd", dfd, "relsym"), 0);
|
||||
ASSERT_EQ(symlinkat("/etc/", dfd, "absetc"), 0);
|
||||
ASSERT_EQ(symlinkat("/etc/passwd", dfd, "abssym"), 0);
|
||||
ASSERT_EQ(symlinkat("/cheeky", dfd, "abscheeky"), 0);
|
||||
|
||||
E_mkdirat(dfd, "cheeky", 0755);
|
||||
ASSERT_EQ(mkdirat(dfd, "cheeky", 0755), 0);
|
||||
|
||||
E_symlinkat("/", dfd, "cheeky/absself");
|
||||
E_symlinkat("../../root/", dfd, "cheeky/self");
|
||||
E_symlinkat("/../../root/", dfd, "cheeky/garbageself");
|
||||
ASSERT_EQ(symlinkat("/", dfd, "cheeky/absself"), 0);
|
||||
ASSERT_EQ(symlinkat("../../root/", dfd, "cheeky/self"), 0);
|
||||
ASSERT_EQ(symlinkat("/../../root/", dfd, "cheeky/garbageself"), 0);
|
||||
|
||||
E_symlinkat("../cheeky/../etc/../etc/passwd", dfd, "cheeky/passwd");
|
||||
E_symlinkat("/../cheeky/../etc/../etc/passwd", dfd, "cheeky/abspasswd");
|
||||
ASSERT_EQ(symlinkat("../cheeky/../etc/../etc/passwd",
|
||||
dfd, "cheeky/passwd"), 0);
|
||||
ASSERT_EQ(symlinkat("/../cheeky/../etc/../etc/passwd",
|
||||
dfd, "cheeky/abspasswd"), 0);
|
||||
|
||||
E_symlinkat("../../../../../../../../../../../../../../etc/passwd",
|
||||
dfd, "cheeky/dotdotlink");
|
||||
E_symlinkat("/../../../../../../../../../../../../../../etc/passwd",
|
||||
dfd, "cheeky/garbagelink");
|
||||
ASSERT_EQ(symlinkat("../../../../../../../../../../../../../../etc/passwd",
|
||||
dfd, "cheeky/dotdotlink"), 0);
|
||||
ASSERT_EQ(symlinkat("/../../../../../../../../../../../../../../etc/passwd",
|
||||
dfd, "cheeky/garbagelink"), 0);
|
||||
|
||||
return dfd;
|
||||
self->rootfd = dfd;
|
||||
|
||||
self->hardcoded_fd = open("/dev/null", O_RDONLY);
|
||||
ASSERT_GE(self->hardcoded_fd, 0);
|
||||
ASSERT_GE(asprintf(&self->hardcoded_fdpath, "self/fd/%d",
|
||||
self->hardcoded_fd), 0);
|
||||
ASSERT_GE(asprintf(&self->procselfexe, "/proc/%d/exe", getpid()), 0);
|
||||
}
|
||||
|
||||
struct basic_test {
|
||||
const char *name;
|
||||
const char *dir;
|
||||
const char *path;
|
||||
struct open_how how;
|
||||
bool pass;
|
||||
union {
|
||||
int err;
|
||||
const char *path;
|
||||
} out;
|
||||
};
|
||||
|
||||
#define NUM_OPENAT2_OPATH_TESTS 88
|
||||
|
||||
void test_openat2_opath_tests(void)
|
||||
FIXTURE_TEARDOWN(openat2_resolve)
|
||||
{
|
||||
int rootfd, hardcoded_fd;
|
||||
char *procselfexe, *hardcoded_fdpath;
|
||||
free(self->procselfexe);
|
||||
free(self->hardcoded_fdpath);
|
||||
if (self->hardcoded_fd >= 0)
|
||||
close(self->hardcoded_fd);
|
||||
if (self->rootfd >= 0)
|
||||
close(self->rootfd);
|
||||
}
|
||||
|
||||
E_asprintf(&procselfexe, "/proc/%d/exe", getpid());
|
||||
rootfd = setup_testdir();
|
||||
|
||||
hardcoded_fd = open("/dev/null", O_RDONLY);
|
||||
E_assert(hardcoded_fd >= 0, "open fd to hardcode");
|
||||
E_asprintf(&hardcoded_fdpath, "self/fd/%d", hardcoded_fd);
|
||||
|
||||
struct basic_test tests[] = {
|
||||
/** RESOLVE_BENEATH **/
|
||||
/* Attempts to cross the dirfd should be blocked with -EXDEV. */
|
||||
TEST_F(openat2_resolve, resolve_beneath)
|
||||
{
|
||||
struct resolve_test tests[] = {
|
||||
/* Attempts to cross dirfd should be blocked. */
|
||||
{ .name = "[beneath] jump to /",
|
||||
.path = "/", .how.resolve = RESOLVE_BENEATH,
|
||||
|
|
@ -206,9 +288,17 @@ void test_openat2_opath_tests(void)
|
|||
{ .name = "[beneath] tricky absolute + garbage link outside $root",
|
||||
.path = "abscheeky/garbagelink", .how.resolve = RESOLVE_BENEATH,
|
||||
.out.err = -EXDEV, .pass = false },
|
||||
};
|
||||
|
||||
/** RESOLVE_IN_ROOT **/
|
||||
/* All attempts to cross the dirfd will be scoped-to-root. */
|
||||
for (int i = 0; i < ARRAY_SIZE(tests); i++)
|
||||
verify_resolve_test(_metadata, self->rootfd,
|
||||
self->hardcoded_fd, &tests[i]);
|
||||
}
|
||||
|
||||
/* All attempts to cross the dirfd will be scoped-to-root. */
|
||||
TEST_F(openat2_resolve, resolve_in_root)
|
||||
{
|
||||
struct resolve_test tests[] = {
|
||||
{ .name = "[in_root] jump to /",
|
||||
.path = "/", .how.resolve = RESOLVE_IN_ROOT,
|
||||
.out.path = NULL, .pass = true },
|
||||
|
|
@ -297,8 +387,17 @@ void test_openat2_opath_tests(void)
|
|||
.how.mode = 0700,
|
||||
.how.resolve = RESOLVE_IN_ROOT,
|
||||
.out.path = "newfile3", .pass = true },
|
||||
};
|
||||
|
||||
/** RESOLVE_NO_XDEV **/
|
||||
for (int i = 0; i < ARRAY_SIZE(tests); i++)
|
||||
verify_resolve_test(_metadata, self->rootfd,
|
||||
self->hardcoded_fd, &tests[i]);
|
||||
}
|
||||
|
||||
/* Crossing mount boundaries should be blocked. */
|
||||
TEST_F(openat2_resolve, resolve_no_xdev)
|
||||
{
|
||||
struct resolve_test tests[] = {
|
||||
/* Crossing *down* into a mountpoint is disallowed. */
|
||||
{ .name = "[no_xdev] cross into $mnt",
|
||||
.path = "mnt", .how.resolve = RESOLVE_NO_XDEV,
|
||||
|
|
@ -347,10 +446,19 @@ void test_openat2_opath_tests(void)
|
|||
.out.err = -EXDEV, .pass = false },
|
||||
/* Except magic-link jumps inside the same vfsmount. */
|
||||
{ .name = "[no_xdev] jump through magic-link to same procfs",
|
||||
.dir = "/proc", .path = hardcoded_fdpath, .how.resolve = RESOLVE_NO_XDEV,
|
||||
.out.path = "/proc", .pass = true, },
|
||||
.dir = "/proc", .path = self->hardcoded_fdpath, .how.resolve = RESOLVE_NO_XDEV,
|
||||
.out.path = "/proc", .pass = true, },
|
||||
};
|
||||
|
||||
/** RESOLVE_NO_MAGICLINKS **/
|
||||
for (int i = 0; i < ARRAY_SIZE(tests); i++)
|
||||
verify_resolve_test(_metadata, self->rootfd,
|
||||
self->hardcoded_fd, &tests[i]);
|
||||
}
|
||||
|
||||
/* Procfs-style magic-link resolution should be blocked. */
|
||||
TEST_F(openat2_resolve, resolve_no_magiclinks)
|
||||
{
|
||||
struct resolve_test tests[] = {
|
||||
/* Regular symlinks should work. */
|
||||
{ .name = "[no_magiclinks] ordinary relative symlink",
|
||||
.path = "relsym", .how.resolve = RESOLVE_NO_MAGICLINKS,
|
||||
|
|
@ -365,7 +473,7 @@ void test_openat2_opath_tests(void)
|
|||
{ .name = "[no_magiclinks] normal path to magic-link with O_NOFOLLOW",
|
||||
.path = "/proc/self/exe", .how.flags = O_NOFOLLOW,
|
||||
.how.resolve = RESOLVE_NO_MAGICLINKS,
|
||||
.out.path = procselfexe, .pass = true },
|
||||
.out.path = self->procselfexe, .pass = true },
|
||||
{ .name = "[no_magiclinks] symlink to magic-link path component",
|
||||
.path = "procroot/etc", .how.resolve = RESOLVE_NO_MAGICLINKS,
|
||||
.out.err = -ELOOP, .pass = false },
|
||||
|
|
@ -376,8 +484,17 @@ void test_openat2_opath_tests(void)
|
|||
.path = "/proc/self/root/etc", .how.flags = O_NOFOLLOW,
|
||||
.how.resolve = RESOLVE_NO_MAGICLINKS,
|
||||
.out.err = -ELOOP, .pass = false },
|
||||
};
|
||||
|
||||
/** RESOLVE_NO_SYMLINKS **/
|
||||
for (int i = 0; i < ARRAY_SIZE(tests); i++)
|
||||
verify_resolve_test(_metadata, self->rootfd,
|
||||
self->hardcoded_fd, &tests[i]);
|
||||
}
|
||||
|
||||
/* All symlink resolution should be blocked. */
|
||||
TEST_F(openat2_resolve, resolve_no_symlinks)
|
||||
{
|
||||
struct resolve_test tests[] = {
|
||||
/* Normal paths should work. */
|
||||
{ .name = "[no_symlinks] ordinary path to '.'",
|
||||
.path = ".", .how.resolve = RESOLVE_NO_SYMLINKS,
|
||||
|
|
@ -436,88 +553,9 @@ void test_openat2_opath_tests(void)
|
|||
.out.err = -ELOOP, .pass = false },
|
||||
};
|
||||
|
||||
BUILD_BUG_ON(ARRAY_LEN(tests) != NUM_OPENAT2_OPATH_TESTS);
|
||||
|
||||
for (int i = 0; i < ARRAY_LEN(tests); i++) {
|
||||
int dfd, fd;
|
||||
char *fdpath = NULL;
|
||||
bool failed;
|
||||
void (*resultfn)(const char *msg, ...) = ksft_test_result_pass;
|
||||
struct basic_test *test = &tests[i];
|
||||
|
||||
if (!openat2_supported) {
|
||||
ksft_print_msg("openat2(2) unsupported\n");
|
||||
resultfn = ksft_test_result_skip;
|
||||
goto skip;
|
||||
}
|
||||
|
||||
/* Auto-set O_PATH. */
|
||||
if (!(test->how.flags & O_CREAT))
|
||||
test->how.flags |= O_PATH;
|
||||
|
||||
if (test->dir)
|
||||
dfd = openat(rootfd, test->dir, O_PATH | O_DIRECTORY);
|
||||
else
|
||||
dfd = dup(rootfd);
|
||||
E_assert(dfd, "failed to openat root '%s': %m", test->dir);
|
||||
|
||||
E_dup2(dfd, hardcoded_fd);
|
||||
|
||||
fd = sys_openat2(dfd, test->path, &test->how);
|
||||
if (test->pass)
|
||||
failed = (fd < 0 || !fdequal(fd, rootfd, test->out.path));
|
||||
else
|
||||
failed = (fd != test->out.err);
|
||||
if (fd >= 0) {
|
||||
fdpath = fdreadlink(fd);
|
||||
close(fd);
|
||||
}
|
||||
close(dfd);
|
||||
|
||||
if (failed) {
|
||||
resultfn = ksft_test_result_fail;
|
||||
|
||||
ksft_print_msg("openat2 unexpectedly returned ");
|
||||
if (fdpath)
|
||||
ksft_print_msg("%d['%s']\n", fd, fdpath);
|
||||
else
|
||||
ksft_print_msg("%d (%s)\n", fd, strerror(-fd));
|
||||
}
|
||||
|
||||
skip:
|
||||
if (test->pass)
|
||||
resultfn("%s gives path '%s'\n", test->name,
|
||||
test->out.path ?: ".");
|
||||
else
|
||||
resultfn("%s fails with %d (%s)\n", test->name,
|
||||
test->out.err, strerror(-test->out.err));
|
||||
|
||||
fflush(stdout);
|
||||
free(fdpath);
|
||||
}
|
||||
|
||||
free(procselfexe);
|
||||
close(rootfd);
|
||||
|
||||
free(hardcoded_fdpath);
|
||||
close(hardcoded_fd);
|
||||
for (int i = 0; i < ARRAY_SIZE(tests); i++)
|
||||
verify_resolve_test(_metadata, self->rootfd,
|
||||
self->hardcoded_fd, &tests[i]);
|
||||
}
|
||||
|
||||
#define NUM_TESTS NUM_OPENAT2_OPATH_TESTS
|
||||
|
||||
int main(int argc, char **argv)
|
||||
{
|
||||
ksft_print_header();
|
||||
ksft_set_plan(NUM_TESTS);
|
||||
|
||||
/* NOTE: We should be checking for CAP_SYS_ADMIN here... */
|
||||
if (geteuid() != 0)
|
||||
ksft_exit_skip("all tests require euid == 0\n");
|
||||
|
||||
test_openat2_opath_tests();
|
||||
|
||||
if (ksft_get_fail_cnt() + ksft_get_error_cnt() > 0)
|
||||
ksft_exit_fail();
|
||||
else
|
||||
ksft_exit_pass();
|
||||
}
|
||||
TEST_HARNESS_MAIN
|
||||
|
|
@ -1,109 +0,0 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-or-later
|
||||
/*
|
||||
* Author: Aleksa Sarai <cyphar@cyphar.com>
|
||||
* Copyright (C) 2018-2019 SUSE LLC.
|
||||
*/
|
||||
|
||||
#define _GNU_SOURCE
|
||||
#include <errno.h>
|
||||
#include <fcntl.h>
|
||||
#include <stdbool.h>
|
||||
#include <string.h>
|
||||
#include <syscall.h>
|
||||
#include <limits.h>
|
||||
|
||||
#include "helpers.h"
|
||||
|
||||
bool needs_openat2(const struct open_how *how)
|
||||
{
|
||||
return how->resolve != 0;
|
||||
}
|
||||
|
||||
int raw_openat2(int dfd, const char *path, void *how, size_t size)
|
||||
{
|
||||
int ret = syscall(__NR_openat2, dfd, path, how, size);
|
||||
return ret >= 0 ? ret : -errno;
|
||||
}
|
||||
|
||||
int sys_openat2(int dfd, const char *path, struct open_how *how)
|
||||
{
|
||||
return raw_openat2(dfd, path, how, sizeof(*how));
|
||||
}
|
||||
|
||||
int sys_openat(int dfd, const char *path, struct open_how *how)
|
||||
{
|
||||
int ret = openat(dfd, path, how->flags, how->mode);
|
||||
return ret >= 0 ? ret : -errno;
|
||||
}
|
||||
|
||||
int sys_renameat2(int olddirfd, const char *oldpath,
|
||||
int newdirfd, const char *newpath, unsigned int flags)
|
||||
{
|
||||
int ret = syscall(__NR_renameat2, olddirfd, oldpath,
|
||||
newdirfd, newpath, flags);
|
||||
return ret >= 0 ? ret : -errno;
|
||||
}
|
||||
|
||||
int touchat(int dfd, const char *path)
|
||||
{
|
||||
int fd = openat(dfd, path, O_CREAT, 0700);
|
||||
if (fd >= 0)
|
||||
close(fd);
|
||||
return fd;
|
||||
}
|
||||
|
||||
char *fdreadlink(int fd)
|
||||
{
|
||||
char *target, *tmp;
|
||||
|
||||
E_asprintf(&tmp, "/proc/self/fd/%d", fd);
|
||||
|
||||
target = malloc(PATH_MAX);
|
||||
if (!target)
|
||||
ksft_exit_fail_msg("fdreadlink: malloc failed\n");
|
||||
memset(target, 0, PATH_MAX);
|
||||
|
||||
E_readlink(tmp, target, PATH_MAX);
|
||||
free(tmp);
|
||||
return target;
|
||||
}
|
||||
|
||||
bool fdequal(int fd, int dfd, const char *path)
|
||||
{
|
||||
char *fdpath, *dfdpath, *other;
|
||||
bool cmp;
|
||||
|
||||
fdpath = fdreadlink(fd);
|
||||
dfdpath = fdreadlink(dfd);
|
||||
|
||||
if (!path)
|
||||
E_asprintf(&other, "%s", dfdpath);
|
||||
else if (*path == '/')
|
||||
E_asprintf(&other, "%s", path);
|
||||
else
|
||||
E_asprintf(&other, "%s/%s", dfdpath, path);
|
||||
|
||||
cmp = !strcmp(fdpath, other);
|
||||
|
||||
free(fdpath);
|
||||
free(dfdpath);
|
||||
free(other);
|
||||
return cmp;
|
||||
}
|
||||
|
||||
bool openat2_supported = false;
|
||||
|
||||
void __attribute__((constructor)) init(void)
|
||||
{
|
||||
struct open_how how = {};
|
||||
int fd;
|
||||
|
||||
BUILD_BUG_ON(sizeof(struct open_how) != OPEN_HOW_SIZE_VER0);
|
||||
|
||||
/* Check openat2(2) support. */
|
||||
fd = sys_openat2(AT_FDCWD, ".", &how);
|
||||
openat2_supported = (fd >= 0);
|
||||
|
||||
if (fd >= 0)
|
||||
close(fd);
|
||||
}
|
||||
|
|
@ -1,108 +0,0 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-or-later
|
||||
/*
|
||||
* Author: Aleksa Sarai <cyphar@cyphar.com>
|
||||
* Copyright (C) 2018-2019 SUSE LLC.
|
||||
*/
|
||||
|
||||
#ifndef __RESOLVEAT_H__
|
||||
#define __RESOLVEAT_H__
|
||||
|
||||
#define _GNU_SOURCE
|
||||
#include <stdint.h>
|
||||
#include <stdbool.h>
|
||||
#include <errno.h>
|
||||
#include <linux/types.h>
|
||||
#include "kselftest.h"
|
||||
|
||||
#define ARRAY_LEN(X) (sizeof (X) / sizeof (*(X)))
|
||||
#define BUILD_BUG_ON(e) ((void)(sizeof(struct { int:(-!!(e)); })))
|
||||
|
||||
#ifndef SYS_openat2
|
||||
#ifndef __NR_openat2
|
||||
#define __NR_openat2 437
|
||||
#endif /* __NR_openat2 */
|
||||
#define SYS_openat2 __NR_openat2
|
||||
#endif /* SYS_openat2 */
|
||||
|
||||
/*
|
||||
* Arguments for how openat2(2) should open the target path. If @resolve is
|
||||
* zero, then openat2(2) operates very similarly to openat(2).
|
||||
*
|
||||
* However, unlike openat(2), unknown bits in @flags result in -EINVAL rather
|
||||
* than being silently ignored. @mode must be zero unless one of {O_CREAT,
|
||||
* O_TMPFILE} are set.
|
||||
*
|
||||
* @flags: O_* flags.
|
||||
* @mode: O_CREAT/O_TMPFILE file mode.
|
||||
* @resolve: RESOLVE_* flags.
|
||||
*/
|
||||
struct open_how {
|
||||
__u64 flags;
|
||||
__u64 mode;
|
||||
__u64 resolve;
|
||||
};
|
||||
|
||||
#define OPEN_HOW_SIZE_VER0 24 /* sizeof first published struct */
|
||||
#define OPEN_HOW_SIZE_LATEST OPEN_HOW_SIZE_VER0
|
||||
|
||||
bool needs_openat2(const struct open_how *how);
|
||||
|
||||
#ifndef RESOLVE_IN_ROOT
|
||||
/* how->resolve flags for openat2(2). */
|
||||
#define RESOLVE_NO_XDEV 0x01 /* Block mount-point crossings
|
||||
(includes bind-mounts). */
|
||||
#define RESOLVE_NO_MAGICLINKS 0x02 /* Block traversal through procfs-style
|
||||
"magic-links". */
|
||||
#define RESOLVE_NO_SYMLINKS 0x04 /* Block traversal through all symlinks
|
||||
(implies OEXT_NO_MAGICLINKS) */
|
||||
#define RESOLVE_BENEATH 0x08 /* Block "lexical" trickery like
|
||||
"..", symlinks, and absolute
|
||||
paths which escape the dirfd. */
|
||||
#define RESOLVE_IN_ROOT 0x10 /* Make all jumps to "/" and ".."
|
||||
be scoped inside the dirfd
|
||||
(similar to chroot(2)). */
|
||||
#endif /* RESOLVE_IN_ROOT */
|
||||
|
||||
#define E_func(func, ...) \
|
||||
do { \
|
||||
errno = 0; \
|
||||
if (func(__VA_ARGS__) < 0) \
|
||||
ksft_exit_fail_msg("%s:%d %s failed - errno:%d\n", \
|
||||
__FILE__, __LINE__, #func, errno); \
|
||||
} while (0)
|
||||
|
||||
#define E_asprintf(...) E_func(asprintf, __VA_ARGS__)
|
||||
#define E_chmod(...) E_func(chmod, __VA_ARGS__)
|
||||
#define E_dup2(...) E_func(dup2, __VA_ARGS__)
|
||||
#define E_fchdir(...) E_func(fchdir, __VA_ARGS__)
|
||||
#define E_fstatat(...) E_func(fstatat, __VA_ARGS__)
|
||||
#define E_kill(...) E_func(kill, __VA_ARGS__)
|
||||
#define E_mkdirat(...) E_func(mkdirat, __VA_ARGS__)
|
||||
#define E_mount(...) E_func(mount, __VA_ARGS__)
|
||||
#define E_prctl(...) E_func(prctl, __VA_ARGS__)
|
||||
#define E_readlink(...) E_func(readlink, __VA_ARGS__)
|
||||
#define E_setresuid(...) E_func(setresuid, __VA_ARGS__)
|
||||
#define E_symlinkat(...) E_func(symlinkat, __VA_ARGS__)
|
||||
#define E_touchat(...) E_func(touchat, __VA_ARGS__)
|
||||
#define E_unshare(...) E_func(unshare, __VA_ARGS__)
|
||||
|
||||
#define E_assert(expr, msg, ...) \
|
||||
do { \
|
||||
if (!(expr)) \
|
||||
ksft_exit_fail_msg("ASSERT(%s:%d) failed (%s): " msg "\n", \
|
||||
__FILE__, __LINE__, #expr, ##__VA_ARGS__); \
|
||||
} while (0)
|
||||
|
||||
int raw_openat2(int dfd, const char *path, void *how, size_t size);
|
||||
int sys_openat2(int dfd, const char *path, struct open_how *how);
|
||||
int sys_openat(int dfd, const char *path, struct open_how *how);
|
||||
int sys_renameat2(int olddirfd, const char *oldpath,
|
||||
int newdirfd, const char *newpath, unsigned int flags);
|
||||
|
||||
int touchat(int dfd, const char *path);
|
||||
char *fdreadlink(int fd);
|
||||
bool fdequal(int fd, int dfd, const char *path);
|
||||
|
||||
extern bool openat2_supported;
|
||||
|
||||
#endif /* __RESOLVEAT_H__ */
|
||||
|
|
@ -1,160 +0,0 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-or-later
|
||||
/*
|
||||
* Author: Aleksa Sarai <cyphar@cyphar.com>
|
||||
* Copyright (C) 2018-2019 SUSE LLC.
|
||||
*/
|
||||
|
||||
#define _GNU_SOURCE
|
||||
#include <errno.h>
|
||||
#include <fcntl.h>
|
||||
#include <sched.h>
|
||||
#include <sys/stat.h>
|
||||
#include <sys/types.h>
|
||||
#include <sys/mount.h>
|
||||
#include <sys/mman.h>
|
||||
#include <sys/prctl.h>
|
||||
#include <signal.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <stdbool.h>
|
||||
#include <string.h>
|
||||
#include <syscall.h>
|
||||
#include <limits.h>
|
||||
#include <unistd.h>
|
||||
|
||||
#include "kselftest.h"
|
||||
#include "helpers.h"
|
||||
|
||||
/* Construct a test directory with the following structure:
|
||||
*
|
||||
* root/
|
||||
* |-- a/
|
||||
* | `-- c/
|
||||
* `-- b/
|
||||
*/
|
||||
int setup_testdir(void)
|
||||
{
|
||||
int dfd;
|
||||
char dirname[] = "/tmp/ksft-openat2-rename-attack.XXXXXX";
|
||||
|
||||
/* Make the top-level directory. */
|
||||
if (!mkdtemp(dirname))
|
||||
ksft_exit_fail_msg("setup_testdir: failed to create tmpdir\n");
|
||||
dfd = open(dirname, O_PATH | O_DIRECTORY);
|
||||
if (dfd < 0)
|
||||
ksft_exit_fail_msg("setup_testdir: failed to open tmpdir\n");
|
||||
|
||||
E_mkdirat(dfd, "a", 0755);
|
||||
E_mkdirat(dfd, "b", 0755);
|
||||
E_mkdirat(dfd, "a/c", 0755);
|
||||
|
||||
return dfd;
|
||||
}
|
||||
|
||||
/* Swap @dirfd/@a and @dirfd/@b constantly. Parent must kill this process. */
|
||||
pid_t spawn_attack(int dirfd, char *a, char *b)
|
||||
{
|
||||
pid_t child = fork();
|
||||
if (child != 0)
|
||||
return child;
|
||||
|
||||
/* If the parent (the test process) dies, kill ourselves too. */
|
||||
E_prctl(PR_SET_PDEATHSIG, SIGKILL);
|
||||
|
||||
/* Swap @a and @b. */
|
||||
for (;;)
|
||||
renameat2(dirfd, a, dirfd, b, RENAME_EXCHANGE);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
#define NUM_RENAME_TESTS 2
|
||||
#define ROUNDS 400000
|
||||
|
||||
const char *flagname(int resolve)
|
||||
{
|
||||
switch (resolve) {
|
||||
case RESOLVE_IN_ROOT:
|
||||
return "RESOLVE_IN_ROOT";
|
||||
case RESOLVE_BENEATH:
|
||||
return "RESOLVE_BENEATH";
|
||||
}
|
||||
return "(unknown)";
|
||||
}
|
||||
|
||||
void test_rename_attack(int resolve)
|
||||
{
|
||||
int dfd, afd;
|
||||
pid_t child;
|
||||
void (*resultfn)(const char *msg, ...) = ksft_test_result_pass;
|
||||
int escapes = 0, other_errs = 0, exdevs = 0, eagains = 0, successes = 0;
|
||||
|
||||
struct open_how how = {
|
||||
.flags = O_PATH,
|
||||
.resolve = resolve,
|
||||
};
|
||||
|
||||
if (!openat2_supported) {
|
||||
how.resolve = 0;
|
||||
ksft_print_msg("openat2(2) unsupported -- using openat(2) instead\n");
|
||||
}
|
||||
|
||||
dfd = setup_testdir();
|
||||
afd = openat(dfd, "a", O_PATH);
|
||||
if (afd < 0)
|
||||
ksft_exit_fail_msg("test_rename_attack: failed to open 'a'\n");
|
||||
|
||||
child = spawn_attack(dfd, "a/c", "b");
|
||||
|
||||
for (int i = 0; i < ROUNDS; i++) {
|
||||
int fd;
|
||||
char *victim_path = "c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../../c/../..";
|
||||
|
||||
if (openat2_supported)
|
||||
fd = sys_openat2(afd, victim_path, &how);
|
||||
else
|
||||
fd = sys_openat(afd, victim_path, &how);
|
||||
|
||||
if (fd < 0) {
|
||||
if (fd == -EAGAIN)
|
||||
eagains++;
|
||||
else if (fd == -EXDEV)
|
||||
exdevs++;
|
||||
else if (fd == -ENOENT)
|
||||
escapes++; /* escaped outside and got ENOENT... */
|
||||
else
|
||||
other_errs++; /* unexpected error */
|
||||
} else {
|
||||
if (fdequal(fd, afd, NULL))
|
||||
successes++;
|
||||
else
|
||||
escapes++; /* we got an unexpected fd */
|
||||
}
|
||||
close(fd);
|
||||
}
|
||||
|
||||
if (escapes > 0)
|
||||
resultfn = ksft_test_result_fail;
|
||||
ksft_print_msg("non-escapes: EAGAIN=%d EXDEV=%d E<other>=%d success=%d\n",
|
||||
eagains, exdevs, other_errs, successes);
|
||||
resultfn("rename attack with %s (%d runs, got %d escapes)\n",
|
||||
flagname(resolve), ROUNDS, escapes);
|
||||
|
||||
/* Should be killed anyway, but might as well make sure. */
|
||||
E_kill(child, SIGKILL);
|
||||
}
|
||||
|
||||
#define NUM_TESTS NUM_RENAME_TESTS
|
||||
|
||||
int main(int argc, char **argv)
|
||||
{
|
||||
ksft_print_header();
|
||||
ksft_set_plan(NUM_TESTS);
|
||||
|
||||
test_rename_attack(RESOLVE_BENEATH);
|
||||
test_rename_attack(RESOLVE_IN_ROOT);
|
||||
|
||||
if (ksft_get_fail_cnt() + ksft_get_error_cnt() > 0)
|
||||
ksft_exit_fail();
|
||||
else
|
||||
ksft_exit_pass();
|
||||
}
|
||||
Loading…
Reference in New Issue
Block a user