#include <sys/types.h>
#include <sys/sysctl.h>
#include <err.h>
#include <errno.h>
#include <stdio.h>
#include "main.h"
#define MSGBUF_CONTROL_NAME "security.bsd.unprivileged_read_msgbuf"
#define MSGBUF_NAME "kern.msgbuf"
static int unprivileged_read_msgbuf;
static int unprivileged_read_msgbuf_initialized;
int
priv_msgbuf_privonly_setup(int asroot, int injail, struct test *test)
{
size_t len;
int newval;
len = sizeof(unprivileged_read_msgbuf);
if (sysctlbyname(MSGBUF_CONTROL_NAME, &unprivileged_read_msgbuf,
&len, NULL, 0) < 0) {
warn("priv_msgbuf_privonly_setup: sysctlbyname query");
return (-1);
}
newval = 0;
if (sysctlbyname(MSGBUF_CONTROL_NAME, NULL, NULL, &newval,
sizeof(newval)) < 0) {
warn("priv_msgbuf_privonly_setup: sysctlbyname set");
return (-1);
}
unprivileged_read_msgbuf_initialized = 1;
return (0);
}
void
priv_msgbuf_privonly(int asroot, int injail, struct test *test)
{
size_t len;
int error;
error = sysctlbyname(MSGBUF_NAME, NULL, &len, NULL, 0);
if (asroot && injail)
expect("priv_msgbuf_privonly(asroot, injail)", error, -1,
EPERM);
if (asroot && !injail)
expect("priv_msgbuf_privonly(asroot, !injail)", error, 0, 0);
if (!asroot && injail)
expect("priv_msgbuf_privonly(!asroot, injail)", error, -1,
EPERM);
if (!asroot && !injail)
expect("priv_msgbuf_privonly(!asroot, !injail)", error, -1,
EPERM);
}
int
priv_msgbuf_unprivok_setup(int asroot, int injail, struct test *test)
{
size_t len;
int newval;
len = sizeof(unprivileged_read_msgbuf);
if (sysctlbyname(MSGBUF_CONTROL_NAME, &unprivileged_read_msgbuf, &len,
NULL, 0) < 0) {
warn("priv_msgbuf_unprivok_setup: sysctlbyname query");
return (-1);
}
newval = 1;
if (sysctlbyname(MSGBUF_CONTROL_NAME, NULL, NULL, &newval,
sizeof(newval)) < 0) {
warn("priv_msgbuf_unprivok_setup: sysctlbyname set");
return (-1);
}
unprivileged_read_msgbuf_initialized = 1;
return (0);
}
void
priv_msgbuf_unprivok(int asroot, int injail, struct test *test)
{
size_t len;
int error;
error = sysctlbyname(MSGBUF_NAME, NULL, &len, NULL, 0);
if (asroot && injail)
expect("priv_msgbuf_unprivok(asroot, injail)", error, 0, 0);
if (asroot && !injail)
expect("priv_msgbuf_unprivok(asroot, !injail)", error, 0, 0);
if (!asroot && injail)
expect("priv_msgbuf_unprivok(!asroot, injail)", error, 0, 0);
if (!asroot && !injail)
expect("priv_msgbuf_unprivok(!asroot, !injail)", error, 0, 0);
}
void
priv_msgbuf_cleanup(int asroot, int injail, struct test *test)
{
if (unprivileged_read_msgbuf_initialized) {
(void)sysctlbyname(MSGBUF_NAME, NULL, NULL,
&unprivileged_read_msgbuf,
sizeof(unprivileged_read_msgbuf));
unprivileged_read_msgbuf_initialized = 0;
}
}