#include <sys/param.h>
#include <sys/uio.h>
#include <sys/ptrace.h>
#include <sys/time.h>
#include <sys/resource.h>
#include <sys/syscall.h>
#include <sys/wait.h>
#include <sys/ktrace.h>
#include <assert.h>
#include <errno.h>
#include <signal.h>
#include <stdio.h>
#include <string.h>
#include <unistd.h>
struct cred {
uid_t cr_euid, cr_ruid, cr_svuid;
int cr_issetugid;
};
struct scenario {
struct cred *sc_cred1, *sc_cred2;
int sc_canptrace_errno;
int sc_canktrace_errno;
int sc_cansighup_errno;
int sc_cansigsegv_errno;
int sc_cansee_errno;
int sc_cansched_errno;
char *sc_name;
};
static struct cred creds[] = {
{ 0, 0, 0, 0 },
{ 0, 0, 0, 1 },
{ 1000, 1000, 1000, 0 },
{ 1000, 1000, 1000, 1 },
{ 1001, 1001, 1001, 0 },
{ 1001, 1001, 1001, 1 },
{ 1000, 0, 0, 0 },
{ 1000, 0, 0, 1 },
{ 1001, 0, 0, 0 },
{ 1001, 0, 0, 1 },
{ 0, 1000, 1000, 0 },
{ 0, 1000, 1000, 1 },
{ 0, 1001, 1001, 0 },
{ 0, 1001, 1001, 1 },
};
static const struct scenario scenarios[] = {
{ &creds[0], &creds[0], 0, 0, 0, 0, 0, 0, "0. priv on priv"},
{ &creds[0], &creds[1], 0, 0, 0, 0, 0, 0, "1. priv on priv"},
{ &creds[1], &creds[0], 0, 0, 0, 0, 0, 0, "2. priv on priv"},
{ &creds[1], &creds[1], 0, 0, 0, 0, 0, 0, "3. priv on priv"},
{ &creds[0], &creds[2], 0, 0, 0, 0, 0, 0, "4. priv on unpriv1"},
{ &creds[0], &creds[3], 0, 0, 0, 0, 0, 0, "5. priv on unpriv1"},
{ &creds[1], &creds[2], 0, 0, 0, 0, 0, 0, "6. priv on unpriv1"},
{ &creds[1], &creds[3], 0, 0, 0, 0, 0, 0, "7. priv on unpriv1"},
{ &creds[2], &creds[0], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "8. unpriv1 on priv"},
{ &creds[2], &creds[1], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "9. unpriv1 on priv"},
{ &creds[3], &creds[0], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "10. unpriv1 on priv"},
{ &creds[3], &creds[1], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "11. unpriv1 on priv"},
{ &creds[2], &creds[2], 0, 0, 0, 0, 0, 0, "12. unpriv1 on unpriv1"},
{ &creds[2], &creds[3], EPERM, EPERM, 0, EPERM, 0, 0, "13. unpriv1 on unpriv1"},
{ &creds[3], &creds[2], 0, 0, 0, 0, 0, 0, "14. unpriv1 on unpriv1"},
{ &creds[3], &creds[3], EPERM, EPERM, 0, EPERM, 0, 0, "15. unpriv1 on unpriv1"},
{ &creds[2], &creds[4], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "16. unpriv1 on unpriv2"},
{ &creds[2], &creds[5], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "17. unpriv1 on unpriv2"},
{ &creds[3], &creds[4], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "18. unpriv1 on unpriv2"},
{ &creds[3], &creds[5], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "19. unpriv1 on unpriv2"},
{ &creds[2], &creds[6], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "20. unpriv1 on daemon1"},
{ &creds[2], &creds[7], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "21. unpriv1 on daemon1"},
{ &creds[3], &creds[6], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "22. unpriv1 on daemon1"},
{ &creds[3], &creds[7], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "23. unpriv1 on daemon1"},
{ &creds[2], &creds[8], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "24. unpriv1 on daemon2"},
{ &creds[2], &creds[9], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "25. unpriv1 on daemon2"},
{ &creds[3], &creds[8], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "26. unpriv1 on daemon2"},
{ &creds[3], &creds[9], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "27. unpriv1 on daemon2"},
{ &creds[2], &creds[10], EPERM, EPERM, 0, 0, 0, 0, "28. unpriv1 on setuid1"},
{ &creds[2], &creds[11], EPERM, EPERM, 0, EPERM, 0, 0, "29. unpriv1 on setuid1"},
{ &creds[3], &creds[10], EPERM, EPERM, 0, 0, 0, 0, "30. unpriv1 on setuid1"},
{ &creds[3], &creds[11], EPERM, EPERM, 0, EPERM, 0, 0, "31. unpriv1 on setuid1"},
{ &creds[2], &creds[12], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "32. unpriv1 on setuid2"},
{ &creds[2], &creds[13], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "33. unpriv1 on setuid2"},
{ &creds[3], &creds[12], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "34. unpriv1 on setuid2"},
{ &creds[3], &creds[13], EPERM, EPERM, EPERM, EPERM, 0, EPERM, "35. unpriv1 on setuid2"},
};
int scenarios_count = sizeof(scenarios) / sizeof(struct scenario);
static char *
errno_to_string(int error)
{
switch (error) {
case EPERM:
return ("EPERM");
case EACCES:
return ("EACCES");
case EINVAL:
return ("EINVAL");
case ENOSYS:
return ("ENOSYS");
case ESRCH:
return ("ESRCH");
case EOPNOTSUPP:
return ("EOPNOTSUPP");
case 0:
return ("0");
default:
printf("%d\n", error);
return ("unknown");
}
}
static int
cred_get(struct cred *cred)
{
int error;
error = getresuid(&cred->cr_ruid, &cred->cr_euid, &cred->cr_svuid);
if (error)
return (error);
cred->cr_issetugid = issetugid();
return (0);
}
int
setugid(int flag)
{
#ifdef SETSUGID_SUPPORTED
return (__setugid(flag));
#else
#ifdef SETSUGID_SUPPORTED_BUT_NO_LIBC_STUB
return (syscall(374, flag));
#else
return (ENOSYS);
#endif
#endif
}
static int
cred_set(struct cred *cred)
{
int error;
error = setresuid(cred->cr_ruid, cred->cr_euid, cred->cr_svuid);
if (error)
return (error);
error = setugid(cred->cr_issetugid);
if (error) {
perror("__setugid");
return (error);
}
#ifdef CHECK_CRED_SET
{
uid_t ruid, euid, svuid;
error = getresuid(&ruid, &euid, &svuid);
if (error) {
perror("getresuid");
return (-1);
}
assert(ruid == cred->cr_ruid);
assert(euid == cred->cr_euid);
assert(svuid == cred->cr_svuid);
assert(cred->cr_issetugid == issetugid());
}
#endif
return (0);
}
static void
cred_print(FILE *output, struct cred *cred)
{
fprintf(output, "(e:%d r:%d s:%d P_SUGID:%d)", cred->cr_euid,
cred->cr_ruid, cred->cr_svuid, cred->cr_issetugid);
}
#define LOOP_PTRACE 0
#define LOOP_KTRACE 1
#define LOOP_SIGHUP 2
#define LOOP_SIGSEGV 3
#define LOOP_SEE 4
#define LOOP_SCHED 5
#define LOOP_MAX LOOP_SCHED
static int
enact_scenario(int scenario)
{
pid_t pid1, pid2;
char *name, *tracefile;
int error, desirederror, loop;
for (loop = 0; loop < LOOP_MAX+1; loop++) {
pid1 = fork();
switch (pid1) {
case -1:
return (-1);
case 0:
error = cred_set(scenarios[scenario].sc_cred2);
if (error) {
perror("cred_set");
return (error);
}
sleep(200);
exit(0);
default:
break;
}
sleep(1);
pid2 = fork();
switch (pid2) {
case -1:
return (-1);
case 0:
error = cred_set(scenarios[scenario].sc_cred1);
if (error) {
perror("cred_set");
return (error);
}
errno = 0;
switch (loop) {
case LOOP_PTRACE:
error = ptrace(PT_ATTACH, pid1, NULL, 0);
error = errno;
name = "ptrace";
desirederror =
scenarios[scenario].sc_canptrace_errno;
break;
case LOOP_KTRACE:
tracefile = mktemp("/tmp/testuid_ktrace.XXXXXX");
if (tracefile == NULL) {
error = errno;
perror("mktemp");
break;
}
error = ktrace(tracefile, KTROP_SET,
KTRFAC_SYSCALL, pid1);
error = errno;
name = "ktrace";
desirederror =
scenarios[scenario].sc_canktrace_errno;
unlink(tracefile);
break;
case LOOP_SIGHUP:
error = kill(pid1, SIGHUP);
error = errno;
name = "sighup";
desirederror =
scenarios[scenario].sc_cansighup_errno;
break;
case LOOP_SIGSEGV:
error = kill(pid1, SIGSEGV);
error = errno;
name = "sigsegv";
desirederror =
scenarios[scenario].sc_cansigsegv_errno;
break;
case LOOP_SEE:
getpriority(PRIO_PROCESS, pid1);
error = errno;
name = "see";
desirederror =
scenarios[scenario].sc_cansee_errno;
break;
case LOOP_SCHED:
error = setpriority(PRIO_PROCESS, pid1,
0);
error = errno;
name = "sched";
desirederror =
scenarios[scenario].sc_cansched_errno;
break;
default:
name = "broken";
}
if (error != desirederror) {
fprintf(stdout,
"[%s].%s: expected %s, got %s\n ",
scenarios[scenario].sc_name, name,
errno_to_string(desirederror),
errno_to_string(error));
cred_print(stdout,
scenarios[scenario].sc_cred1);
cred_print(stdout,
scenarios[scenario].sc_cred2);
fprintf(stdout, "\n");
}
exit(0);
default:
break;
}
error = waitpid(pid2, NULL, 0);
kill(pid1, SIGKILL);
error = waitpid(pid2, NULL, 0);
}
return (0);
}
void
enact_scenarios(void)
{
int i, error;
for (i = 0; i < scenarios_count; i++) {
error = enact_scenario(i);
if (error)
perror("enact_scenario");
}
}