1*cf84ac9aSAndroid Build Coastguard Worker /*
2*cf84ac9aSAndroid Build Coastguard Worker * Check decoding of chown/chown32/lchown/lchown32/fchown/fchown32 syscalls.
3*cf84ac9aSAndroid Build Coastguard Worker *
4*cf84ac9aSAndroid Build Coastguard Worker * Copyright (c) 2016 Dmitry V. Levin <[email protected]>
5*cf84ac9aSAndroid Build Coastguard Worker * Copyright (c) 2016-2017 The strace developers.
6*cf84ac9aSAndroid Build Coastguard Worker * All rights reserved.
7*cf84ac9aSAndroid Build Coastguard Worker *
8*cf84ac9aSAndroid Build Coastguard Worker * Redistribution and use in source and binary forms, with or without
9*cf84ac9aSAndroid Build Coastguard Worker * modification, are permitted provided that the following conditions
10*cf84ac9aSAndroid Build Coastguard Worker * are met:
11*cf84ac9aSAndroid Build Coastguard Worker * 1. Redistributions of source code must retain the above copyright
12*cf84ac9aSAndroid Build Coastguard Worker * notice, this list of conditions and the following disclaimer.
13*cf84ac9aSAndroid Build Coastguard Worker * 2. Redistributions in binary form must reproduce the above copyright
14*cf84ac9aSAndroid Build Coastguard Worker * notice, this list of conditions and the following disclaimer in the
15*cf84ac9aSAndroid Build Coastguard Worker * documentation and/or other materials provided with the distribution.
16*cf84ac9aSAndroid Build Coastguard Worker * 3. The name of the author may not be used to endorse or promote products
17*cf84ac9aSAndroid Build Coastguard Worker * derived from this software without specific prior written permission.
18*cf84ac9aSAndroid Build Coastguard Worker *
19*cf84ac9aSAndroid Build Coastguard Worker * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
20*cf84ac9aSAndroid Build Coastguard Worker * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
21*cf84ac9aSAndroid Build Coastguard Worker * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
22*cf84ac9aSAndroid Build Coastguard Worker * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
23*cf84ac9aSAndroid Build Coastguard Worker * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
24*cf84ac9aSAndroid Build Coastguard Worker * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
25*cf84ac9aSAndroid Build Coastguard Worker * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
26*cf84ac9aSAndroid Build Coastguard Worker * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
27*cf84ac9aSAndroid Build Coastguard Worker * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
28*cf84ac9aSAndroid Build Coastguard Worker * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
29*cf84ac9aSAndroid Build Coastguard Worker */
30*cf84ac9aSAndroid Build Coastguard Worker
31*cf84ac9aSAndroid Build Coastguard Worker #include <fcntl.h>
32*cf84ac9aSAndroid Build Coastguard Worker #include <stdio.h>
33*cf84ac9aSAndroid Build Coastguard Worker #include <unistd.h>
34*cf84ac9aSAndroid Build Coastguard Worker
35*cf84ac9aSAndroid Build Coastguard Worker #ifdef UGID_TYPE_IS_SHORT
36*cf84ac9aSAndroid Build Coastguard Worker # define UGID_TYPE short
37*cf84ac9aSAndroid Build Coastguard Worker # define GETEUID syscall(__NR_geteuid)
38*cf84ac9aSAndroid Build Coastguard Worker # define GETEGID syscall(__NR_getegid)
39*cf84ac9aSAndroid Build Coastguard Worker # define CHECK_OVERFLOWUID(arg) check_overflowuid(arg)
40*cf84ac9aSAndroid Build Coastguard Worker # define CHECK_OVERFLOWGID(arg) check_overflowgid(arg)
41*cf84ac9aSAndroid Build Coastguard Worker #else
42*cf84ac9aSAndroid Build Coastguard Worker # define UGID_TYPE int
43*cf84ac9aSAndroid Build Coastguard Worker # define GETEUID geteuid()
44*cf84ac9aSAndroid Build Coastguard Worker # define GETEGID getegid()
45*cf84ac9aSAndroid Build Coastguard Worker # define CHECK_OVERFLOWUID(arg)
46*cf84ac9aSAndroid Build Coastguard Worker # define CHECK_OVERFLOWGID(arg)
47*cf84ac9aSAndroid Build Coastguard Worker #endif
48*cf84ac9aSAndroid Build Coastguard Worker
49*cf84ac9aSAndroid Build Coastguard Worker #define UNLINK_SAMPLE \
50*cf84ac9aSAndroid Build Coastguard Worker do { \
51*cf84ac9aSAndroid Build Coastguard Worker if (unlink(sample)) \
52*cf84ac9aSAndroid Build Coastguard Worker perror_msg_and_fail("unlink"); \
53*cf84ac9aSAndroid Build Coastguard Worker } while (0)
54*cf84ac9aSAndroid Build Coastguard Worker
55*cf84ac9aSAndroid Build Coastguard Worker #define CLOSE_SAMPLE \
56*cf84ac9aSAndroid Build Coastguard Worker do { \
57*cf84ac9aSAndroid Build Coastguard Worker if (close(fd)) \
58*cf84ac9aSAndroid Build Coastguard Worker perror_msg_and_fail("close"); \
59*cf84ac9aSAndroid Build Coastguard Worker } while (0)
60*cf84ac9aSAndroid Build Coastguard Worker
61*cf84ac9aSAndroid Build Coastguard Worker #ifdef ACCESS_BY_DESCRIPTOR
62*cf84ac9aSAndroid Build Coastguard Worker # define SYSCALL_ARG1 fd
63*cf84ac9aSAndroid Build Coastguard Worker # define FMT_ARG1 "%d"
64*cf84ac9aSAndroid Build Coastguard Worker # define EOK_CMD CLOSE_SAMPLE
65*cf84ac9aSAndroid Build Coastguard Worker # define CLEANUP_CMD UNLINK_SAMPLE
66*cf84ac9aSAndroid Build Coastguard Worker #else
67*cf84ac9aSAndroid Build Coastguard Worker # define SYSCALL_ARG1 sample
68*cf84ac9aSAndroid Build Coastguard Worker # define FMT_ARG1 "\"%s\""
69*cf84ac9aSAndroid Build Coastguard Worker # define EOK_CMD UNLINK_SAMPLE
70*cf84ac9aSAndroid Build Coastguard Worker # define CLEANUP_CMD CLOSE_SAMPLE
71*cf84ac9aSAndroid Build Coastguard Worker #endif
72*cf84ac9aSAndroid Build Coastguard Worker
73*cf84ac9aSAndroid Build Coastguard Worker static int
ugid2int(const unsigned UGID_TYPE id)74*cf84ac9aSAndroid Build Coastguard Worker ugid2int(const unsigned UGID_TYPE id)
75*cf84ac9aSAndroid Build Coastguard Worker {
76*cf84ac9aSAndroid Build Coastguard Worker if ((unsigned UGID_TYPE) -1U == id)
77*cf84ac9aSAndroid Build Coastguard Worker return -1;
78*cf84ac9aSAndroid Build Coastguard Worker else
79*cf84ac9aSAndroid Build Coastguard Worker return id;
80*cf84ac9aSAndroid Build Coastguard Worker }
81*cf84ac9aSAndroid Build Coastguard Worker
82*cf84ac9aSAndroid Build Coastguard Worker static void
print_int(const unsigned int num)83*cf84ac9aSAndroid Build Coastguard Worker print_int(const unsigned int num)
84*cf84ac9aSAndroid Build Coastguard Worker {
85*cf84ac9aSAndroid Build Coastguard Worker if (num == -1U)
86*cf84ac9aSAndroid Build Coastguard Worker printf(", -1");
87*cf84ac9aSAndroid Build Coastguard Worker else
88*cf84ac9aSAndroid Build Coastguard Worker printf(", %u", num);
89*cf84ac9aSAndroid Build Coastguard Worker }
90*cf84ac9aSAndroid Build Coastguard Worker
91*cf84ac9aSAndroid Build Coastguard Worker static int
num_matches_id(const unsigned int num,const unsigned int id)92*cf84ac9aSAndroid Build Coastguard Worker num_matches_id(const unsigned int num, const unsigned int id)
93*cf84ac9aSAndroid Build Coastguard Worker {
94*cf84ac9aSAndroid Build Coastguard Worker return num == id || num == -1U;
95*cf84ac9aSAndroid Build Coastguard Worker }
96*cf84ac9aSAndroid Build Coastguard Worker
97*cf84ac9aSAndroid Build Coastguard Worker #define PAIR(val) { val, gid }, { uid, val }
98*cf84ac9aSAndroid Build Coastguard Worker
99*cf84ac9aSAndroid Build Coastguard Worker int
main(void)100*cf84ac9aSAndroid Build Coastguard Worker main(void)
101*cf84ac9aSAndroid Build Coastguard Worker {
102*cf84ac9aSAndroid Build Coastguard Worker static const char sample[] = SYSCALL_NAME "_sample";
103*cf84ac9aSAndroid Build Coastguard Worker
104*cf84ac9aSAndroid Build Coastguard Worker unsigned int uid = GETEUID;
105*cf84ac9aSAndroid Build Coastguard Worker CHECK_OVERFLOWUID(uid);
106*cf84ac9aSAndroid Build Coastguard Worker unsigned int gid = GETEGID;
107*cf84ac9aSAndroid Build Coastguard Worker CHECK_OVERFLOWUID(gid);
108*cf84ac9aSAndroid Build Coastguard Worker
109*cf84ac9aSAndroid Build Coastguard Worker const struct {
110*cf84ac9aSAndroid Build Coastguard Worker const long uid, gid;
111*cf84ac9aSAndroid Build Coastguard Worker } tests[] = {
112*cf84ac9aSAndroid Build Coastguard Worker { uid, gid },
113*cf84ac9aSAndroid Build Coastguard Worker { (unsigned long) 0xffffffff00000000ULL | uid, gid },
114*cf84ac9aSAndroid Build Coastguard Worker { uid, (unsigned long) 0xffffffff00000000ULL | gid },
115*cf84ac9aSAndroid Build Coastguard Worker PAIR(-1U),
116*cf84ac9aSAndroid Build Coastguard Worker PAIR(-1L),
117*cf84ac9aSAndroid Build Coastguard Worker { 0xffff0000U | uid, gid },
118*cf84ac9aSAndroid Build Coastguard Worker { uid, 0xffff0000U | gid },
119*cf84ac9aSAndroid Build Coastguard Worker PAIR(0xffff),
120*cf84ac9aSAndroid Build Coastguard Worker PAIR(0xc0deffffU),
121*cf84ac9aSAndroid Build Coastguard Worker PAIR(0xfacefeedU),
122*cf84ac9aSAndroid Build Coastguard Worker PAIR((long) 0xfacefeeddeadbeefULL)
123*cf84ac9aSAndroid Build Coastguard Worker };
124*cf84ac9aSAndroid Build Coastguard Worker
125*cf84ac9aSAndroid Build Coastguard Worker int fd = open(sample, O_RDONLY | O_CREAT, 0400);
126*cf84ac9aSAndroid Build Coastguard Worker if (fd < 0)
127*cf84ac9aSAndroid Build Coastguard Worker perror_msg_and_fail("open");
128*cf84ac9aSAndroid Build Coastguard Worker
129*cf84ac9aSAndroid Build Coastguard Worker CLEANUP_CMD;
130*cf84ac9aSAndroid Build Coastguard Worker
131*cf84ac9aSAndroid Build Coastguard Worker unsigned int i;
132*cf84ac9aSAndroid Build Coastguard Worker long expected = 0;
133*cf84ac9aSAndroid Build Coastguard Worker
134*cf84ac9aSAndroid Build Coastguard Worker for (i = 0; i < ARRAY_SIZE(tests); ++i) {
135*cf84ac9aSAndroid Build Coastguard Worker const unsigned int unum = ugid2int(tests[i].uid);
136*cf84ac9aSAndroid Build Coastguard Worker const unsigned int gnum = ugid2int(tests[i].gid);
137*cf84ac9aSAndroid Build Coastguard Worker
138*cf84ac9aSAndroid Build Coastguard Worker if (num_matches_id(unum, uid) &&
139*cf84ac9aSAndroid Build Coastguard Worker num_matches_id(gnum, gid)) {
140*cf84ac9aSAndroid Build Coastguard Worker if (expected)
141*cf84ac9aSAndroid Build Coastguard Worker continue;
142*cf84ac9aSAndroid Build Coastguard Worker } else {
143*cf84ac9aSAndroid Build Coastguard Worker if (!expected) {
144*cf84ac9aSAndroid Build Coastguard Worker expected = -1;
145*cf84ac9aSAndroid Build Coastguard Worker EOK_CMD;
146*cf84ac9aSAndroid Build Coastguard Worker }
147*cf84ac9aSAndroid Build Coastguard Worker }
148*cf84ac9aSAndroid Build Coastguard Worker
149*cf84ac9aSAndroid Build Coastguard Worker const long rc = syscall(SYSCALL_NR, SYSCALL_ARG1,
150*cf84ac9aSAndroid Build Coastguard Worker tests[i].uid, tests[i].gid);
151*cf84ac9aSAndroid Build Coastguard Worker const char *errstr = sprintrc(rc);
152*cf84ac9aSAndroid Build Coastguard Worker printf("%s(" FMT_ARG1, SYSCALL_NAME, SYSCALL_ARG1);
153*cf84ac9aSAndroid Build Coastguard Worker print_int(unum);
154*cf84ac9aSAndroid Build Coastguard Worker print_int(gnum);
155*cf84ac9aSAndroid Build Coastguard Worker printf(") = %s\n", errstr);
156*cf84ac9aSAndroid Build Coastguard Worker }
157*cf84ac9aSAndroid Build Coastguard Worker
158*cf84ac9aSAndroid Build Coastguard Worker puts("+++ exited with 0 +++");
159*cf84ac9aSAndroid Build Coastguard Worker return 0;
160*cf84ac9aSAndroid Build Coastguard Worker }
161