#include <sys/capsicum.h>
#include <sys/filio.h>
#include <sys/socket.h>
#include <sys/wait.h>
#include <netinet/in.h>
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
#include <atf-c.h>
#include "freebsd_test_suite/macros.h"
#define CHILD_REQUIRE(exp) do { \
if (!(exp)) \
child_fail_require(__FILE__, __LINE__, \
#exp " not met"); \
} while (0)
static __dead2 void
child_fail_require(const char *file, int line, const char *str)
{
char buf[128];
snprintf(buf, sizeof(buf), "%s:%d: %s\n", file, line, str);
write(2, buf, strlen(buf));
_exit(32);
}
ATF_TC_WITHOUT_HEAD(cap_ioctls__listen_copy);
ATF_TC_BODY(cap_ioctls__listen_copy, tc)
{
struct sockaddr_in sin;
cap_rights_t rights;
u_long cmds[] = { FIONREAD };
socklen_t len;
pid_t pid;
char dummy;
int s[2], status;
ATF_REQUIRE_FEATURE("security_capabilities");
s[0] = socket(AF_INET, SOCK_STREAM, 0);
ATF_REQUIRE(s[0] > 0);
memset(&sin, 0, sizeof(sin));
sin.sin_len = sizeof(sin);
sin.sin_family = AF_INET;
sin.sin_port = 0;
sin.sin_addr.s_addr = htonl(INADDR_LOOPBACK);
ATF_REQUIRE(bind(s[0], (struct sockaddr *)&sin, sizeof(sin)) == 0);
CHILD_REQUIRE(listen(s[0], 1) == 0);
len = sizeof(sin);
ATF_REQUIRE(getsockname(s[0], (struct sockaddr *)&sin, &len) == 0);
ATF_REQUIRE(len == sizeof(sin));
cap_rights_init(&rights, CAP_ACCEPT, CAP_IOCTL);
ATF_REQUIRE(cap_rights_limit(s[0], &rights) == 0);
ATF_REQUIRE(cap_ioctls_limit(s[0], cmds, nitems(cmds)) == 0);
pid = fork();
if (pid == 0) {
s[1] = accept(s[0], NULL, NULL);
CHILD_REQUIRE(s[1] > 0);
exit(0);
}
ATF_REQUIRE(pid > 0);
ATF_REQUIRE(close(s[0]) == 0);
s[1] = socket(AF_INET, SOCK_STREAM, 0);
ATF_REQUIRE(s[1] > 0);
ATF_REQUIRE(connect(s[1], (struct sockaddr *)&sin, sizeof(sin)) == 0);
ATF_REQUIRE(read(s[1], &dummy, sizeof(dummy)) == 0);
ATF_REQUIRE(close(s[1]) == 0);
ATF_REQUIRE(wait(&status) == pid);
ATF_REQUIRE(WIFEXITED(status));
ATF_REQUIRE(WEXITSTATUS(status) == 0);
}
ATF_TP_ADD_TCS(tp)
{
ATF_TP_ADD_TC(tp, cap_ioctls__listen_copy);
return (atf_no_error());
}