1 // SPDX-License-Identifier: GPL-2.0
7 #include <linux/types.h>
14 #include <sys/prctl.h>
17 #include <sys/socket.h>
18 #include <linux/kcmp.h>
21 #include "../kselftest_harness.h"
24 * UNKNOWN_FD is an fd number that should never exist in the child, as it is
25 * used to check the negative case.
27 #define UNKNOWN_FD 111
28 #define UID_NOBODY 65535
30 static int sys_kcmp(pid_t pid1, pid_t pid2, int type, unsigned long idx1,
33 return syscall(__NR_kcmp, pid1, pid2, type, idx1, idx2);
36 static int __child(int sk, int memfd)
42 * Ensure we don't leave around a bunch of orphaned children if our
45 ret = prctl(PR_SET_PDEATHSIG, SIGKILL);
47 fprintf(stderr, "%s: Child could not set DEATHSIG\n",
52 ret = send(sk, &memfd, sizeof(memfd), 0);
53 if (ret != sizeof(memfd)) {
54 fprintf(stderr, "%s: Child failed to send fd number\n",
60 * The fixture setup is completed at this point. The tests will run.
62 * This blocking recv enables the parent to message the child.
63 * Either we will read 'P' off of the sk, indicating that we need
64 * to disable ptrace, or we will read a 0, indicating that the other
65 * side has closed the sk. This occurs during fixture teardown time,
66 * indicating that the child should exit.
68 while ((ret = recv(sk, &buf, sizeof(buf), 0)) > 0) {
70 ret = prctl(PR_SET_DUMPABLE, 0);
73 "%s: Child failed to disable ptrace\n",
78 fprintf(stderr, "Child received unknown command %c\n",
82 ret = send(sk, &buf, sizeof(buf), 0);
84 fprintf(stderr, "%s: Child failed to ack\n",
90 fprintf(stderr, "%s: Child failed to read from socket\n",
98 static int child(int sk)
102 memfd = sys_memfd_create("test", 0);
104 fprintf(stderr, "%s: Child could not create memfd\n",
108 ret = __child(sk, memfd);
119 * remote_fd is the number of the FD which we are trying to retrieve
123 /* pid points to the child which we are fetching FDs from */
125 /* pidfd is the pidfd of the child */
128 * sk is our side of the socketpair used to communicate with the child.
129 * When it is closed, the child will exit.
138 ASSERT_EQ(0, socketpair(PF_LOCAL, SOCK_SEQPACKET, 0, sk_pair)) {
139 TH_LOG("%s: failed to create socketpair", strerror(errno));
141 self->sk = sk_pair[0];
144 ASSERT_GE(self->pid, 0);
146 if (self->pid == 0) {
148 if (child(sk_pair[1]))
155 self->pidfd = sys_pidfd_open(self->pid, 0);
156 ASSERT_GE(self->pidfd, 0);
159 * Wait for the child to complete setup. It'll send the remote memfd's
162 ret = recv(sk_pair[0], &self->remote_fd, sizeof(self->remote_fd), 0);
163 ASSERT_EQ(sizeof(self->remote_fd), ret);
166 FIXTURE_TEARDOWN(child)
168 EXPECT_EQ(0, close(self->pidfd));
169 EXPECT_EQ(0, close(self->sk));
171 EXPECT_EQ(0, wait_for_pid(self->pid));
174 TEST_F(child, disable_ptrace)
180 * Turn into nobody if we're root, to avoid CAP_SYS_PTRACE
182 * The tests should run in their own process, so even this test fails,
183 * it shouldn't result in subsequent tests failing.
187 ASSERT_EQ(0, seteuid(UID_NOBODY));
189 ASSERT_EQ(1, send(self->sk, "P", 1, 0));
190 ASSERT_EQ(1, recv(self->sk, &c, 1, 0));
192 fd = sys_pidfd_getfd(self->pidfd, self->remote_fd, 0);
194 EXPECT_EQ(EPERM, errno);
197 ASSERT_EQ(0, seteuid(0));
200 TEST_F(child, fetch_fd)
204 fd = sys_pidfd_getfd(self->pidfd, self->remote_fd, 0);
207 ret = sys_kcmp(getpid(), self->pid, KCMP_FILE, fd, self->remote_fd);
208 if (ret < 0 && errno == ENOSYS)
209 SKIP(return, "kcmp() syscall not supported");
212 ret = fcntl(fd, F_GETFD);
214 EXPECT_GE(ret & FD_CLOEXEC, 0);
219 TEST_F(child, test_unknown_fd)
223 fd = sys_pidfd_getfd(self->pidfd, UNKNOWN_FD, 0);
225 TH_LOG("getfd succeeded while fetching unknown fd");
227 EXPECT_EQ(EBADF, errno) {
228 TH_LOG("%s: getfd did not get EBADF", strerror(errno));
234 ASSERT_EQ(-1, sys_pidfd_getfd(0, 0, 1));
235 EXPECT_EQ(errno, EINVAL);
238 #if __NR_pidfd_getfd == -1
241 fprintf(stderr, "__NR_pidfd_getfd undefined. The pidfd_getfd syscall is unavailable. Test aborting\n");