xref: /aosp_15_r20/external/ltp/testcases/kernel/syscalls/pkeys/pkey01.c (revision 49cdfc7efb34551c7342be41a7384b9c40d7cab7)
1*49cdfc7eSAndroid Build Coastguard Worker // SPDX-License-Identifier: GPL-2.0-or-later
2*49cdfc7eSAndroid Build Coastguard Worker /*
3*49cdfc7eSAndroid Build Coastguard Worker  * Copyright (c) 2019 Red Hat, Inc.
4*49cdfc7eSAndroid Build Coastguard Worker  *
5*49cdfc7eSAndroid Build Coastguard Worker  * Memory Protection Keys for Userspace (PKU aka PKEYs) is a Skylake-SP
6*49cdfc7eSAndroid Build Coastguard Worker  * server feature that provides a mechanism for enforcing page-based
7*49cdfc7eSAndroid Build Coastguard Worker  * protections, but without requiring modification of the page tables
8*49cdfc7eSAndroid Build Coastguard Worker  * when an application changes protection domains. It works by dedicating
9*49cdfc7eSAndroid Build Coastguard Worker  * 4 previously ignored bits in each page table entry to a "protection key",
10*49cdfc7eSAndroid Build Coastguard Worker  * giving 16 possible keys.
11*49cdfc7eSAndroid Build Coastguard Worker  *
12*49cdfc7eSAndroid Build Coastguard Worker  * Basic method for PKEYs testing:
13*49cdfc7eSAndroid Build Coastguard Worker  *    1. test allocates a pkey(e.g. PKEY_DISABLE_ACCESS) via pkey_alloc()
14*49cdfc7eSAndroid Build Coastguard Worker  *    2. pkey_mprotect() apply this pkey to a piece of memory(buffer)
15*49cdfc7eSAndroid Build Coastguard Worker  *    3. check if access right of the buffer has been changed and take effect
16*49cdfc7eSAndroid Build Coastguard Worker  *    4. remove the access right(pkey) from this buffer via pkey_mprotect()
17*49cdfc7eSAndroid Build Coastguard Worker  *    5. check if buffer area can be read or write after removing pkey
18*49cdfc7eSAndroid Build Coastguard Worker  *    6. pkey_free() releases the pkey after using it
19*49cdfc7eSAndroid Build Coastguard Worker  *
20*49cdfc7eSAndroid Build Coastguard Worker  * Looping around this basic test on diffenrent types of memory.
21*49cdfc7eSAndroid Build Coastguard Worker  */
22*49cdfc7eSAndroid Build Coastguard Worker 
23*49cdfc7eSAndroid Build Coastguard Worker #define _GNU_SOURCE
24*49cdfc7eSAndroid Build Coastguard Worker #include <stdio.h>
25*49cdfc7eSAndroid Build Coastguard Worker #include <unistd.h>
26*49cdfc7eSAndroid Build Coastguard Worker #include <errno.h>
27*49cdfc7eSAndroid Build Coastguard Worker #include <stdlib.h>
28*49cdfc7eSAndroid Build Coastguard Worker #include <sys/syscall.h>
29*49cdfc7eSAndroid Build Coastguard Worker #include <sys/mman.h>
30*49cdfc7eSAndroid Build Coastguard Worker #include <sys/wait.h>
31*49cdfc7eSAndroid Build Coastguard Worker 
32*49cdfc7eSAndroid Build Coastguard Worker #include "pkey.h"
33*49cdfc7eSAndroid Build Coastguard Worker 
34*49cdfc7eSAndroid Build Coastguard Worker #define TEST_FILE "pkey_testfile"
35*49cdfc7eSAndroid Build Coastguard Worker #define STR "abcdefghijklmnopqrstuvwxyz12345\n"
36*49cdfc7eSAndroid Build Coastguard Worker #define PATH_VM_NRHPS "/proc/sys/vm/nr_hugepages"
37*49cdfc7eSAndroid Build Coastguard Worker 
38*49cdfc7eSAndroid Build Coastguard Worker static int size;
39*49cdfc7eSAndroid Build Coastguard Worker 
40*49cdfc7eSAndroid Build Coastguard Worker static struct tcase {
41*49cdfc7eSAndroid Build Coastguard Worker 	unsigned long flags;
42*49cdfc7eSAndroid Build Coastguard Worker 	unsigned long access_rights;
43*49cdfc7eSAndroid Build Coastguard Worker 	char *name;
44*49cdfc7eSAndroid Build Coastguard Worker } tcases[] = {
45*49cdfc7eSAndroid Build Coastguard Worker 	{0, PKEY_DISABLE_ACCESS, "PKEY_DISABLE_ACCESS"},
46*49cdfc7eSAndroid Build Coastguard Worker 	{0, PKEY_DISABLE_WRITE, "PKEY_DISABLE_WRITE"},
47*49cdfc7eSAndroid Build Coastguard Worker };
48*49cdfc7eSAndroid Build Coastguard Worker 
setup(void)49*49cdfc7eSAndroid Build Coastguard Worker static void setup(void)
50*49cdfc7eSAndroid Build Coastguard Worker {
51*49cdfc7eSAndroid Build Coastguard Worker 	int i, fd;
52*49cdfc7eSAndroid Build Coastguard Worker 
53*49cdfc7eSAndroid Build Coastguard Worker 	check_pkey_support();
54*49cdfc7eSAndroid Build Coastguard Worker 
55*49cdfc7eSAndroid Build Coastguard Worker 	if (tst_hugepages == test.hugepages.number)
56*49cdfc7eSAndroid Build Coastguard Worker 		size = SAFE_READ_MEMINFO("Hugepagesize:") * 1024;
57*49cdfc7eSAndroid Build Coastguard Worker 	else
58*49cdfc7eSAndroid Build Coastguard Worker 		size = getpagesize();
59*49cdfc7eSAndroid Build Coastguard Worker 
60*49cdfc7eSAndroid Build Coastguard Worker 	fd = SAFE_OPEN(TEST_FILE, O_RDWR | O_CREAT, 0664);
61*49cdfc7eSAndroid Build Coastguard Worker 	for (i = 0; i < 128; i++)
62*49cdfc7eSAndroid Build Coastguard Worker 		SAFE_WRITE(SAFE_WRITE_ALL, fd, STR, strlen(STR));
63*49cdfc7eSAndroid Build Coastguard Worker 
64*49cdfc7eSAndroid Build Coastguard Worker 	SAFE_CLOSE(fd);
65*49cdfc7eSAndroid Build Coastguard Worker }
66*49cdfc7eSAndroid Build Coastguard Worker 
67*49cdfc7eSAndroid Build Coastguard Worker static struct mmap_param {
68*49cdfc7eSAndroid Build Coastguard Worker 	int prot;
69*49cdfc7eSAndroid Build Coastguard Worker 	int flags;
70*49cdfc7eSAndroid Build Coastguard Worker 	int fd;
71*49cdfc7eSAndroid Build Coastguard Worker } mmap_params[] = {
72*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ,  MAP_ANONYMOUS | MAP_PRIVATE, -1},
73*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ,  MAP_ANONYMOUS | MAP_SHARED, -1},
74*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ,  MAP_ANONYMOUS | MAP_PRIVATE | MAP_HUGETLB, -1},
75*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ,  MAP_ANONYMOUS | MAP_SHARED  | MAP_HUGETLB, -1},
76*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ,  MAP_PRIVATE, 0},
77*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ,  MAP_SHARED, 0},
78*49cdfc7eSAndroid Build Coastguard Worker 
79*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_WRITE, MAP_ANONYMOUS | MAP_PRIVATE, -1},
80*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_WRITE, MAP_ANONYMOUS | MAP_SHARED, -1},
81*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_WRITE, MAP_PRIVATE, 0},
82*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_WRITE, MAP_SHARED, 0},
83*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_WRITE, MAP_ANONYMOUS | MAP_PRIVATE | MAP_HUGETLB, -1},
84*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_WRITE, MAP_ANONYMOUS | MAP_SHARED  | MAP_HUGETLB, -1},
85*49cdfc7eSAndroid Build Coastguard Worker 
86*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_EXEC,  MAP_ANONYMOUS | MAP_PRIVATE, -1},
87*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_EXEC,  MAP_ANONYMOUS | MAP_SHARED, -1},
88*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_EXEC,  MAP_ANONYMOUS | MAP_PRIVATE | MAP_HUGETLB, -1},
89*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_EXEC,  MAP_ANONYMOUS | MAP_SHARED  | MAP_HUGETLB, -1},
90*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_EXEC,  MAP_PRIVATE, 0},
91*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_EXEC,  MAP_SHARED, 0},
92*49cdfc7eSAndroid Build Coastguard Worker 
93*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE, MAP_ANONYMOUS | MAP_PRIVATE, -1},
94*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE, MAP_ANONYMOUS | MAP_SHARED, -1},
95*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE, MAP_ANONYMOUS | MAP_PRIVATE | MAP_HUGETLB, -1},
96*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE, MAP_ANONYMOUS | MAP_SHARED  | MAP_HUGETLB, -1},
97*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE, MAP_PRIVATE, 0},
98*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE, MAP_SHARED, 0},
99*49cdfc7eSAndroid Build Coastguard Worker 
100*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE | PROT_EXEC, MAP_ANONYMOUS | MAP_PRIVATE, -1},
101*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE | PROT_EXEC, MAP_ANONYMOUS | MAP_SHARED, -1},
102*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE | PROT_EXEC, MAP_ANONYMOUS | MAP_PRIVATE | MAP_HUGETLB, -1},
103*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE | PROT_EXEC, MAP_ANONYMOUS | MAP_SHARED  | MAP_HUGETLB, -1},
104*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE | PROT_EXEC, MAP_PRIVATE, 0},
105*49cdfc7eSAndroid Build Coastguard Worker 	{PROT_READ | PROT_WRITE | PROT_EXEC, MAP_SHARED, 0},
106*49cdfc7eSAndroid Build Coastguard Worker };
107*49cdfc7eSAndroid Build Coastguard Worker 
flag_to_str(int flags)108*49cdfc7eSAndroid Build Coastguard Worker static char *flag_to_str(int flags)
109*49cdfc7eSAndroid Build Coastguard Worker {
110*49cdfc7eSAndroid Build Coastguard Worker 	switch (flags) {
111*49cdfc7eSAndroid Build Coastguard Worker 	case MAP_PRIVATE:
112*49cdfc7eSAndroid Build Coastguard Worker 		return "MAP_PRIVATE";
113*49cdfc7eSAndroid Build Coastguard Worker 	case MAP_SHARED:
114*49cdfc7eSAndroid Build Coastguard Worker 		return "MAP_SHARED";
115*49cdfc7eSAndroid Build Coastguard Worker 	case MAP_ANONYMOUS | MAP_PRIVATE:
116*49cdfc7eSAndroid Build Coastguard Worker 		return "MAP_ANONYMOUS|MAP_PRIVATE";
117*49cdfc7eSAndroid Build Coastguard Worker 	case MAP_ANONYMOUS | MAP_SHARED:
118*49cdfc7eSAndroid Build Coastguard Worker 		return "MAP_ANONYMOUS|MAP_SHARED";
119*49cdfc7eSAndroid Build Coastguard Worker 	case MAP_ANONYMOUS | MAP_PRIVATE | MAP_HUGETLB:
120*49cdfc7eSAndroid Build Coastguard Worker 		return "MAP_ANONYMOUS|MAP_PRIVATE|MAP_HUGETLB";
121*49cdfc7eSAndroid Build Coastguard Worker 	case MAP_ANONYMOUS | MAP_SHARED  | MAP_HUGETLB:
122*49cdfc7eSAndroid Build Coastguard Worker 		return "MAP_ANONYMOUS|MAP_SHARED|MAP_HUGETLB";
123*49cdfc7eSAndroid Build Coastguard Worker 	default:
124*49cdfc7eSAndroid Build Coastguard Worker 		return "UNKNOWN FLAGS";
125*49cdfc7eSAndroid Build Coastguard Worker 	}
126*49cdfc7eSAndroid Build Coastguard Worker }
127*49cdfc7eSAndroid Build Coastguard Worker 
pkey_test(struct tcase * tc,struct mmap_param * mpa)128*49cdfc7eSAndroid Build Coastguard Worker static void pkey_test(struct tcase *tc, struct mmap_param *mpa)
129*49cdfc7eSAndroid Build Coastguard Worker {
130*49cdfc7eSAndroid Build Coastguard Worker 	pid_t pid;
131*49cdfc7eSAndroid Build Coastguard Worker 	char *buffer;
132*49cdfc7eSAndroid Build Coastguard Worker 	int pkey, status;
133*49cdfc7eSAndroid Build Coastguard Worker 	int fd = mpa->fd;
134*49cdfc7eSAndroid Build Coastguard Worker 
135*49cdfc7eSAndroid Build Coastguard Worker 	if (!tst_hugepages && (mpa->flags & MAP_HUGETLB)) {
136*49cdfc7eSAndroid Build Coastguard Worker 		tst_res(TINFO, "Skip test on (%s) buffer", flag_to_str(mpa->flags));
137*49cdfc7eSAndroid Build Coastguard Worker 		return;
138*49cdfc7eSAndroid Build Coastguard Worker 	}
139*49cdfc7eSAndroid Build Coastguard Worker 
140*49cdfc7eSAndroid Build Coastguard Worker 	if (fd == 0)
141*49cdfc7eSAndroid Build Coastguard Worker 		fd = SAFE_OPEN(TEST_FILE, O_RDWR | O_CREAT, 0664);
142*49cdfc7eSAndroid Build Coastguard Worker 
143*49cdfc7eSAndroid Build Coastguard Worker 	buffer = SAFE_MMAP(NULL, size, mpa->prot, mpa->flags, fd, 0);
144*49cdfc7eSAndroid Build Coastguard Worker 
145*49cdfc7eSAndroid Build Coastguard Worker 	pkey = ltp_pkey_alloc(tc->flags, tc->access_rights);
146*49cdfc7eSAndroid Build Coastguard Worker 	if (pkey == -1)
147*49cdfc7eSAndroid Build Coastguard Worker 		tst_brk(TBROK | TERRNO, "pkey_alloc failed");
148*49cdfc7eSAndroid Build Coastguard Worker 
149*49cdfc7eSAndroid Build Coastguard Worker 	tst_res(TINFO, "Set %s on (%s) buffer", tc->name, flag_to_str(mpa->flags));
150*49cdfc7eSAndroid Build Coastguard Worker 	if (ltp_pkey_mprotect(buffer, size, mpa->prot, pkey) == -1)
151*49cdfc7eSAndroid Build Coastguard Worker 		tst_brk(TBROK | TERRNO, "pkey_mprotect failed");
152*49cdfc7eSAndroid Build Coastguard Worker 
153*49cdfc7eSAndroid Build Coastguard Worker 	pid = SAFE_FORK();
154*49cdfc7eSAndroid Build Coastguard Worker 	if (pid == 0) {
155*49cdfc7eSAndroid Build Coastguard Worker 		tst_no_corefile(0);
156*49cdfc7eSAndroid Build Coastguard Worker 
157*49cdfc7eSAndroid Build Coastguard Worker 		switch (tc->access_rights) {
158*49cdfc7eSAndroid Build Coastguard Worker 		case PKEY_DISABLE_ACCESS:
159*49cdfc7eSAndroid Build Coastguard Worker 			tst_res(TFAIL | TERRNO,
160*49cdfc7eSAndroid Build Coastguard Worker 				"Read buffer success, buffer[0] = %d", *buffer);
161*49cdfc7eSAndroid Build Coastguard Worker 		break;
162*49cdfc7eSAndroid Build Coastguard Worker 		case PKEY_DISABLE_WRITE:
163*49cdfc7eSAndroid Build Coastguard Worker 			*buffer = 'a';
164*49cdfc7eSAndroid Build Coastguard Worker 			tst_res(TFAIL | TERRNO,
165*49cdfc7eSAndroid Build Coastguard Worker 				"Write buffer success, buffer[0] = %d", *buffer);
166*49cdfc7eSAndroid Build Coastguard Worker 		break;
167*49cdfc7eSAndroid Build Coastguard Worker 		}
168*49cdfc7eSAndroid Build Coastguard Worker 		exit(0);
169*49cdfc7eSAndroid Build Coastguard Worker 	}
170*49cdfc7eSAndroid Build Coastguard Worker 
171*49cdfc7eSAndroid Build Coastguard Worker 	SAFE_WAITPID(pid, &status, 0);
172*49cdfc7eSAndroid Build Coastguard Worker 
173*49cdfc7eSAndroid Build Coastguard Worker         if (WIFSIGNALED(status) && WTERMSIG(status) == SIGSEGV)
174*49cdfc7eSAndroid Build Coastguard Worker 		tst_res(TPASS, "Child ended by %s as expected", tst_strsig(SIGSEGV));
175*49cdfc7eSAndroid Build Coastguard Worker         else
176*49cdfc7eSAndroid Build Coastguard Worker                 tst_res(TFAIL, "Child: %s", tst_strstatus(status));
177*49cdfc7eSAndroid Build Coastguard Worker 
178*49cdfc7eSAndroid Build Coastguard Worker 	tst_res(TINFO, "Remove %s from the buffer", tc->name);
179*49cdfc7eSAndroid Build Coastguard Worker 	if (ltp_pkey_mprotect(buffer, size, mpa->prot, 0x0) == -1)
180*49cdfc7eSAndroid Build Coastguard Worker 		tst_brk(TBROK | TERRNO, "pkey_mprotect failed");
181*49cdfc7eSAndroid Build Coastguard Worker 
182*49cdfc7eSAndroid Build Coastguard Worker 	switch (mpa->prot) {
183*49cdfc7eSAndroid Build Coastguard Worker 	case PROT_READ:
184*49cdfc7eSAndroid Build Coastguard Worker 		tst_res(TPASS, "Read buffer success, buffer[0] = %d", *buffer);
185*49cdfc7eSAndroid Build Coastguard Worker 	break;
186*49cdfc7eSAndroid Build Coastguard Worker 	case PROT_WRITE:
187*49cdfc7eSAndroid Build Coastguard Worker 		*buffer = 'a';
188*49cdfc7eSAndroid Build Coastguard Worker 		tst_res(TPASS, "Write buffer success, buffer[0] = %d", *buffer);
189*49cdfc7eSAndroid Build Coastguard Worker 	break;
190*49cdfc7eSAndroid Build Coastguard Worker 	case PROT_READ | PROT_WRITE:
191*49cdfc7eSAndroid Build Coastguard Worker 	case PROT_READ | PROT_WRITE | PROT_EXEC:
192*49cdfc7eSAndroid Build Coastguard Worker 		*buffer = 'a';
193*49cdfc7eSAndroid Build Coastguard Worker 		tst_res(TPASS, "Read & Write buffer success, buffer[0] = %d", *buffer);
194*49cdfc7eSAndroid Build Coastguard Worker 	break;
195*49cdfc7eSAndroid Build Coastguard Worker 	}
196*49cdfc7eSAndroid Build Coastguard Worker 
197*49cdfc7eSAndroid Build Coastguard Worker 	if (fd >= 0)
198*49cdfc7eSAndroid Build Coastguard Worker 		SAFE_CLOSE(fd);
199*49cdfc7eSAndroid Build Coastguard Worker 
200*49cdfc7eSAndroid Build Coastguard Worker 	SAFE_MUNMAP(buffer, size);
201*49cdfc7eSAndroid Build Coastguard Worker 
202*49cdfc7eSAndroid Build Coastguard Worker 	if (ltp_pkey_free(pkey) == -1)
203*49cdfc7eSAndroid Build Coastguard Worker 		tst_brk(TBROK | TERRNO, "pkey_free failed");
204*49cdfc7eSAndroid Build Coastguard Worker }
205*49cdfc7eSAndroid Build Coastguard Worker 
verify_pkey(unsigned int i)206*49cdfc7eSAndroid Build Coastguard Worker static void verify_pkey(unsigned int i)
207*49cdfc7eSAndroid Build Coastguard Worker {
208*49cdfc7eSAndroid Build Coastguard Worker 	long unsigned int j;
209*49cdfc7eSAndroid Build Coastguard Worker 	struct mmap_param *mpa;
210*49cdfc7eSAndroid Build Coastguard Worker 
211*49cdfc7eSAndroid Build Coastguard Worker 	struct tcase *tc = &tcases[i];
212*49cdfc7eSAndroid Build Coastguard Worker 
213*49cdfc7eSAndroid Build Coastguard Worker 	for (j = 0; j < ARRAY_SIZE(mmap_params); j++) {
214*49cdfc7eSAndroid Build Coastguard Worker 		mpa = &mmap_params[j];
215*49cdfc7eSAndroid Build Coastguard Worker 
216*49cdfc7eSAndroid Build Coastguard Worker 		pkey_test(tc, mpa);
217*49cdfc7eSAndroid Build Coastguard Worker 	}
218*49cdfc7eSAndroid Build Coastguard Worker }
219*49cdfc7eSAndroid Build Coastguard Worker 
220*49cdfc7eSAndroid Build Coastguard Worker static struct tst_test test = {
221*49cdfc7eSAndroid Build Coastguard Worker 	.tcnt = ARRAY_SIZE(tcases),
222*49cdfc7eSAndroid Build Coastguard Worker 	.needs_root = 1,
223*49cdfc7eSAndroid Build Coastguard Worker 	.needs_tmpdir = 1,
224*49cdfc7eSAndroid Build Coastguard Worker 	.forks_child = 1,
225*49cdfc7eSAndroid Build Coastguard Worker 	.test = verify_pkey,
226*49cdfc7eSAndroid Build Coastguard Worker 	.setup = setup,
227*49cdfc7eSAndroid Build Coastguard Worker 	.hugepages = {1, TST_REQUEST},
228*49cdfc7eSAndroid Build Coastguard Worker };
229