1*cf84ac9aSAndroid Build Coastguard Worker /*
2*cf84ac9aSAndroid Build Coastguard Worker * Check decoding of struct msghdr.msg_name* arguments of recvmsg syscall.
3*cf84ac9aSAndroid Build Coastguard Worker *
4*cf84ac9aSAndroid Build Coastguard Worker * Copyright (c) 2016 Dmitry V. Levin <[email protected]>
5*cf84ac9aSAndroid Build Coastguard Worker * Copyright (c) 2016-2017 The strace developers.
6*cf84ac9aSAndroid Build Coastguard Worker * All rights reserved.
7*cf84ac9aSAndroid Build Coastguard Worker *
8*cf84ac9aSAndroid Build Coastguard Worker * Redistribution and use in source and binary forms, with or without
9*cf84ac9aSAndroid Build Coastguard Worker * modification, are permitted provided that the following conditions
10*cf84ac9aSAndroid Build Coastguard Worker * are met:
11*cf84ac9aSAndroid Build Coastguard Worker * 1. Redistributions of source code must retain the above copyright
12*cf84ac9aSAndroid Build Coastguard Worker * notice, this list of conditions and the following disclaimer.
13*cf84ac9aSAndroid Build Coastguard Worker * 2. Redistributions in binary form must reproduce the above copyright
14*cf84ac9aSAndroid Build Coastguard Worker * notice, this list of conditions and the following disclaimer in the
15*cf84ac9aSAndroid Build Coastguard Worker * documentation and/or other materials provided with the distribution.
16*cf84ac9aSAndroid Build Coastguard Worker * 3. The name of the author may not be used to endorse or promote products
17*cf84ac9aSAndroid Build Coastguard Worker * derived from this software without specific prior written permission.
18*cf84ac9aSAndroid Build Coastguard Worker *
19*cf84ac9aSAndroid Build Coastguard Worker * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
20*cf84ac9aSAndroid Build Coastguard Worker * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
21*cf84ac9aSAndroid Build Coastguard Worker * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
22*cf84ac9aSAndroid Build Coastguard Worker * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
23*cf84ac9aSAndroid Build Coastguard Worker * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
24*cf84ac9aSAndroid Build Coastguard Worker * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
25*cf84ac9aSAndroid Build Coastguard Worker * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
26*cf84ac9aSAndroid Build Coastguard Worker * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
27*cf84ac9aSAndroid Build Coastguard Worker * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
28*cf84ac9aSAndroid Build Coastguard Worker * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
29*cf84ac9aSAndroid Build Coastguard Worker */
30*cf84ac9aSAndroid Build Coastguard Worker
31*cf84ac9aSAndroid Build Coastguard Worker #include "tests.h"
32*cf84ac9aSAndroid Build Coastguard Worker #include <stddef.h>
33*cf84ac9aSAndroid Build Coastguard Worker #include <stdio.h>
34*cf84ac9aSAndroid Build Coastguard Worker #include <string.h>
35*cf84ac9aSAndroid Build Coastguard Worker #include <unistd.h>
36*cf84ac9aSAndroid Build Coastguard Worker #include <sys/socket.h>
37*cf84ac9aSAndroid Build Coastguard Worker #include <sys/un.h>
38*cf84ac9aSAndroid Build Coastguard Worker
39*cf84ac9aSAndroid Build Coastguard Worker static int
send_recv(const int send_fd,const int recv_fd,struct msghdr * const msg,const int flags)40*cf84ac9aSAndroid Build Coastguard Worker send_recv(const int send_fd, const int recv_fd,
41*cf84ac9aSAndroid Build Coastguard Worker struct msghdr *const msg, const int flags)
42*cf84ac9aSAndroid Build Coastguard Worker {
43*cf84ac9aSAndroid Build Coastguard Worker if (send(send_fd, "A", 1, 0) != 1)
44*cf84ac9aSAndroid Build Coastguard Worker perror_msg_and_skip("send");
45*cf84ac9aSAndroid Build Coastguard Worker return recvmsg(recv_fd, msg, flags);
46*cf84ac9aSAndroid Build Coastguard Worker }
47*cf84ac9aSAndroid Build Coastguard Worker
48*cf84ac9aSAndroid Build Coastguard Worker static void
test_msg_name(const int send_fd,const int recv_fd)49*cf84ac9aSAndroid Build Coastguard Worker test_msg_name(const int send_fd, const int recv_fd)
50*cf84ac9aSAndroid Build Coastguard Worker {
51*cf84ac9aSAndroid Build Coastguard Worker TAIL_ALLOC_OBJECT_CONST_PTR(char, recv_buf);
52*cf84ac9aSAndroid Build Coastguard Worker TAIL_ALLOC_OBJECT_CONST_PTR(struct iovec, iov);
53*cf84ac9aSAndroid Build Coastguard Worker iov->iov_base = recv_buf;
54*cf84ac9aSAndroid Build Coastguard Worker iov->iov_len = sizeof(*recv_buf);
55*cf84ac9aSAndroid Build Coastguard Worker
56*cf84ac9aSAndroid Build Coastguard Worker TAIL_ALLOC_OBJECT_CONST_PTR(struct sockaddr_un, addr);
57*cf84ac9aSAndroid Build Coastguard Worker TAIL_ALLOC_OBJECT_CONST_PTR(struct msghdr, msg);
58*cf84ac9aSAndroid Build Coastguard Worker msg->msg_name = addr;
59*cf84ac9aSAndroid Build Coastguard Worker msg->msg_namelen = sizeof(*addr);
60*cf84ac9aSAndroid Build Coastguard Worker msg->msg_iov = iov;
61*cf84ac9aSAndroid Build Coastguard Worker msg->msg_iovlen = 1;
62*cf84ac9aSAndroid Build Coastguard Worker msg->msg_control = 0;
63*cf84ac9aSAndroid Build Coastguard Worker msg->msg_controllen = 0;
64*cf84ac9aSAndroid Build Coastguard Worker msg->msg_flags = 0;
65*cf84ac9aSAndroid Build Coastguard Worker
66*cf84ac9aSAndroid Build Coastguard Worker int rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
67*cf84ac9aSAndroid Build Coastguard Worker if (rc < 0)
68*cf84ac9aSAndroid Build Coastguard Worker perror_msg_and_skip("recvmsg");
69*cf84ac9aSAndroid Build Coastguard Worker printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX, sun_path=\"%s\"}"
70*cf84ac9aSAndroid Build Coastguard Worker ", msg_namelen=%d->%d, msg_iov=[{iov_base=\"A\", iov_len=1}]"
71*cf84ac9aSAndroid Build Coastguard Worker ", msg_iovlen=1, msg_controllen=0, msg_flags=0}, MSG_DONTWAIT)"
72*cf84ac9aSAndroid Build Coastguard Worker " = %d\n",
73*cf84ac9aSAndroid Build Coastguard Worker recv_fd, addr->sun_path, (int) sizeof(struct sockaddr_un),
74*cf84ac9aSAndroid Build Coastguard Worker (int) msg->msg_namelen, rc);
75*cf84ac9aSAndroid Build Coastguard Worker
76*cf84ac9aSAndroid Build Coastguard Worker memset(addr, 0, sizeof(*addr));
77*cf84ac9aSAndroid Build Coastguard Worker rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
78*cf84ac9aSAndroid Build Coastguard Worker printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX, sun_path=\"%s\"}"
79*cf84ac9aSAndroid Build Coastguard Worker ", msg_namelen=%d, msg_iov=[{iov_base=\"A\", iov_len=1}]"
80*cf84ac9aSAndroid Build Coastguard Worker ", msg_iovlen=1, msg_controllen=0, msg_flags=0}, MSG_DONTWAIT)"
81*cf84ac9aSAndroid Build Coastguard Worker " = %d\n",
82*cf84ac9aSAndroid Build Coastguard Worker recv_fd, addr->sun_path, (int) msg->msg_namelen, rc);
83*cf84ac9aSAndroid Build Coastguard Worker
84*cf84ac9aSAndroid Build Coastguard Worker msg->msg_name = 0;
85*cf84ac9aSAndroid Build Coastguard Worker rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
86*cf84ac9aSAndroid Build Coastguard Worker printf("recvmsg(%d, {msg_name=NULL, msg_namelen=%d"
87*cf84ac9aSAndroid Build Coastguard Worker ", msg_iov=[{iov_base=\"A\", iov_len=1}], msg_iovlen=1"
88*cf84ac9aSAndroid Build Coastguard Worker ", msg_controllen=0, msg_flags=0}, MSG_DONTWAIT) = %d\n",
89*cf84ac9aSAndroid Build Coastguard Worker recv_fd, (int) msg->msg_namelen, rc);
90*cf84ac9aSAndroid Build Coastguard Worker
91*cf84ac9aSAndroid Build Coastguard Worker const size_t offsetof_sun_path = offsetof(struct sockaddr_un, sun_path);
92*cf84ac9aSAndroid Build Coastguard Worker msg->msg_name = addr;
93*cf84ac9aSAndroid Build Coastguard Worker msg->msg_namelen = offsetof_sun_path;
94*cf84ac9aSAndroid Build Coastguard Worker memset(addr->sun_path, 'A', sizeof(addr->sun_path));
95*cf84ac9aSAndroid Build Coastguard Worker
96*cf84ac9aSAndroid Build Coastguard Worker rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
97*cf84ac9aSAndroid Build Coastguard Worker printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX}, msg_namelen=%d->%d"
98*cf84ac9aSAndroid Build Coastguard Worker ", msg_iov=[{iov_base=\"A\", iov_len=1}], msg_iovlen=1"
99*cf84ac9aSAndroid Build Coastguard Worker ", msg_controllen=0, msg_flags=0}, MSG_DONTWAIT) = %d\n",
100*cf84ac9aSAndroid Build Coastguard Worker recv_fd, (int) offsetof_sun_path, (int) msg->msg_namelen, rc);
101*cf84ac9aSAndroid Build Coastguard Worker
102*cf84ac9aSAndroid Build Coastguard Worker msg->msg_namelen = sizeof(struct sockaddr);
103*cf84ac9aSAndroid Build Coastguard Worker msg->msg_name = ((void *) (addr + 1)) - msg->msg_namelen;
104*cf84ac9aSAndroid Build Coastguard Worker rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
105*cf84ac9aSAndroid Build Coastguard Worker printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX, sun_path=\"%.*s\"}"
106*cf84ac9aSAndroid Build Coastguard Worker ", msg_namelen=%d->%d, msg_iov=[{iov_base=\"A\", iov_len=1}]"
107*cf84ac9aSAndroid Build Coastguard Worker ", msg_iovlen=1, msg_controllen=0, msg_flags=0}, MSG_DONTWAIT)"
108*cf84ac9aSAndroid Build Coastguard Worker " = %d\n",
109*cf84ac9aSAndroid Build Coastguard Worker recv_fd, (int) (sizeof(struct sockaddr) - offsetof_sun_path),
110*cf84ac9aSAndroid Build Coastguard Worker ((struct sockaddr_un *) msg->msg_name)->sun_path,
111*cf84ac9aSAndroid Build Coastguard Worker (int) sizeof(struct sockaddr), (int) msg->msg_namelen, rc);
112*cf84ac9aSAndroid Build Coastguard Worker
113*cf84ac9aSAndroid Build Coastguard Worker rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
114*cf84ac9aSAndroid Build Coastguard Worker printf("recvmsg(%d, {msg_namelen=%d}, MSG_DONTWAIT) = %d %s (%m)\n",
115*cf84ac9aSAndroid Build Coastguard Worker recv_fd, (int) msg->msg_namelen, rc, errno2name());
116*cf84ac9aSAndroid Build Coastguard Worker
117*cf84ac9aSAndroid Build Coastguard Worker /*
118*cf84ac9aSAndroid Build Coastguard Worker * When recvmsg is called with a valid descriptor
119*cf84ac9aSAndroid Build Coastguard Worker * but inaccessible memory, it causes segfaults on some architectures.
120*cf84ac9aSAndroid Build Coastguard Worker * As in these cases we test decoding of failed recvmsg calls,
121*cf84ac9aSAndroid Build Coastguard Worker * it's ok to fail recvmsg with any reason as long as
122*cf84ac9aSAndroid Build Coastguard Worker * it doesn't read that inaccessible memory.
123*cf84ac9aSAndroid Build Coastguard Worker */
124*cf84ac9aSAndroid Build Coastguard Worker
125*cf84ac9aSAndroid Build Coastguard Worker /*
126*cf84ac9aSAndroid Build Coastguard Worker * Sadly, musl recvmsg wrapper blindly dereferences 2nd argument,
127*cf84ac9aSAndroid Build Coastguard Worker * so limit this test to glibc that doesn't.
128*cf84ac9aSAndroid Build Coastguard Worker */
129*cf84ac9aSAndroid Build Coastguard Worker #ifdef __GLIBC__
130*cf84ac9aSAndroid Build Coastguard Worker rc = send_recv(send_fd, -1, msg + 1, 0);
131*cf84ac9aSAndroid Build Coastguard Worker printf("recvmsg(-1, %p, 0) = %d %s (%m)\n",
132*cf84ac9aSAndroid Build Coastguard Worker msg + 1, rc, errno2name());
133*cf84ac9aSAndroid Build Coastguard Worker #endif
134*cf84ac9aSAndroid Build Coastguard Worker
135*cf84ac9aSAndroid Build Coastguard Worker rc = send_recv(send_fd, -1, 0, 0);
136*cf84ac9aSAndroid Build Coastguard Worker printf("recvmsg(-1, NULL, 0) = %d %s (%m)\n",
137*cf84ac9aSAndroid Build Coastguard Worker rc, errno2name());
138*cf84ac9aSAndroid Build Coastguard Worker }
139*cf84ac9aSAndroid Build Coastguard Worker
140*cf84ac9aSAndroid Build Coastguard Worker int
main(void)141*cf84ac9aSAndroid Build Coastguard Worker main(void)
142*cf84ac9aSAndroid Build Coastguard Worker {
143*cf84ac9aSAndroid Build Coastguard Worker int fds[2];
144*cf84ac9aSAndroid Build Coastguard Worker if (socketpair(AF_UNIX, SOCK_STREAM, 0, fds))
145*cf84ac9aSAndroid Build Coastguard Worker perror_msg_and_skip("socketpair");
146*cf84ac9aSAndroid Build Coastguard Worker
147*cf84ac9aSAndroid Build Coastguard Worker const struct sockaddr_un un = {
148*cf84ac9aSAndroid Build Coastguard Worker .sun_family = AF_UNIX,
149*cf84ac9aSAndroid Build Coastguard Worker .sun_path = "msg_name-recvmsg.test.send.socket"
150*cf84ac9aSAndroid Build Coastguard Worker };
151*cf84ac9aSAndroid Build Coastguard Worker
152*cf84ac9aSAndroid Build Coastguard Worker (void) unlink(un.sun_path);
153*cf84ac9aSAndroid Build Coastguard Worker if (bind(fds[1], (const void *) &un, sizeof(un)))
154*cf84ac9aSAndroid Build Coastguard Worker perror_msg_and_skip("bind");
155*cf84ac9aSAndroid Build Coastguard Worker (void) unlink(un.sun_path);
156*cf84ac9aSAndroid Build Coastguard Worker
157*cf84ac9aSAndroid Build Coastguard Worker test_msg_name(fds[1], fds[0]);
158*cf84ac9aSAndroid Build Coastguard Worker
159*cf84ac9aSAndroid Build Coastguard Worker puts("+++ exited with 0 +++");
160*cf84ac9aSAndroid Build Coastguard Worker return 0;
161*cf84ac9aSAndroid Build Coastguard Worker }
162