1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
5 #include "alloc-util.h"
10 #include "id128-util.h"
13 #include "path-util.h"
14 #include "random-util.h"
16 #include "stdio-util.h"
17 #include "string-util.h"
20 #include "tmpfile-util.h"
21 #include "umask-util.h"
22 #include "user-util.h"
26 static const char *arg_test_dir
= NULL
;
28 static void test_chase_symlinks(void) {
29 _cleanup_free_
char *result
= NULL
;
31 const char *top
, *p
, *pslash
, *q
, *qslash
;
35 log_info("/* %s */", __func__
);
37 temp
= strjoina(arg_test_dir
?: "/tmp", "/test-chase.XXXXXX");
38 assert_se(mkdtemp(temp
));
40 top
= strjoina(temp
, "/top");
41 assert_se(mkdir(top
, 0700) >= 0);
43 p
= strjoina(top
, "/dot");
44 if (symlink(".", p
) < 0) {
45 assert_se(IN_SET(errno
, EINVAL
, ENOSYS
, ENOTTY
, EPERM
));
46 log_tests_skipped_errno(errno
, "symlink() not possible");
50 p
= strjoina(top
, "/dotdot");
51 assert_se(symlink("..", p
) >= 0);
53 p
= strjoina(top
, "/dotdota");
54 assert_se(symlink("../a", p
) >= 0);
56 p
= strjoina(temp
, "/a");
57 assert_se(symlink("b", p
) >= 0);
59 p
= strjoina(temp
, "/b");
60 assert_se(symlink("/usr", p
) >= 0);
62 p
= strjoina(temp
, "/start");
63 assert_se(symlink("top/dot/dotdota", p
) >= 0);
65 /* Paths that use symlinks underneath the "root" */
67 r
= chase_symlinks(p
, NULL
, 0, &result
, NULL
);
69 assert_se(path_equal(result
, "/usr"));
70 result
= mfree(result
);
72 pslash
= strjoina(p
, "/");
73 r
= chase_symlinks(pslash
, NULL
, 0, &result
, NULL
);
75 assert_se(path_equal(result
, "/usr/"));
76 result
= mfree(result
);
78 r
= chase_symlinks(p
, temp
, 0, &result
, NULL
);
79 assert_se(r
== -ENOENT
);
81 r
= chase_symlinks(pslash
, temp
, 0, &result
, NULL
);
82 assert_se(r
== -ENOENT
);
84 q
= strjoina(temp
, "/usr");
86 r
= chase_symlinks(p
, temp
, CHASE_NONEXISTENT
, &result
, NULL
);
88 assert_se(path_equal(result
, q
));
89 result
= mfree(result
);
91 qslash
= strjoina(q
, "/");
93 r
= chase_symlinks(pslash
, temp
, CHASE_NONEXISTENT
, &result
, NULL
);
95 assert_se(path_equal(result
, qslash
));
96 result
= mfree(result
);
98 assert_se(mkdir(q
, 0700) >= 0);
100 r
= chase_symlinks(p
, temp
, 0, &result
, NULL
);
102 assert_se(path_equal(result
, q
));
103 result
= mfree(result
);
105 r
= chase_symlinks(pslash
, temp
, 0, &result
, NULL
);
107 assert_se(path_equal(result
, qslash
));
108 result
= mfree(result
);
110 p
= strjoina(temp
, "/slash");
111 assert_se(symlink("/", p
) >= 0);
113 r
= chase_symlinks(p
, NULL
, 0, &result
, NULL
);
115 assert_se(path_equal(result
, "/"));
116 result
= mfree(result
);
118 r
= chase_symlinks(p
, temp
, 0, &result
, NULL
);
120 assert_se(path_equal(result
, temp
));
121 result
= mfree(result
);
123 /* Paths that would "escape" outside of the "root" */
125 p
= strjoina(temp
, "/6dots");
126 assert_se(symlink("../../..", p
) >= 0);
128 r
= chase_symlinks(p
, temp
, 0, &result
, NULL
);
129 assert_se(r
> 0 && path_equal(result
, temp
));
130 result
= mfree(result
);
132 p
= strjoina(temp
, "/6dotsusr");
133 assert_se(symlink("../../../usr", p
) >= 0);
135 r
= chase_symlinks(p
, temp
, 0, &result
, NULL
);
136 assert_se(r
> 0 && path_equal(result
, q
));
137 result
= mfree(result
);
139 p
= strjoina(temp
, "/top/8dotsusr");
140 assert_se(symlink("../../../../usr", p
) >= 0);
142 r
= chase_symlinks(p
, temp
, 0, &result
, NULL
);
143 assert_se(r
> 0 && path_equal(result
, q
));
144 result
= mfree(result
);
146 /* Paths that contain repeated slashes */
148 p
= strjoina(temp
, "/slashslash");
149 assert_se(symlink("///usr///", p
) >= 0);
151 r
= chase_symlinks(p
, NULL
, 0, &result
, NULL
);
153 assert_se(path_equal(result
, "/usr"));
154 assert_se(streq(result
, "/usr")); /* we guarantee that we drop redundant slashes */
155 result
= mfree(result
);
157 r
= chase_symlinks(p
, temp
, 0, &result
, NULL
);
159 assert_se(path_equal(result
, q
));
160 result
= mfree(result
);
162 /* Paths underneath the "root" with different UIDs while using CHASE_SAFE */
164 if (geteuid() == 0) {
165 p
= strjoina(temp
, "/user");
166 assert_se(mkdir(p
, 0755) >= 0);
167 assert_se(chown(p
, UID_NOBODY
, GID_NOBODY
) >= 0);
169 q
= strjoina(temp
, "/user/root");
170 assert_se(mkdir(q
, 0755) >= 0);
172 p
= strjoina(q
, "/link");
173 assert_se(symlink("/", p
) >= 0);
175 /* Fail when user-owned directories contain root-owned subdirectories. */
176 r
= chase_symlinks(p
, temp
, CHASE_SAFE
, &result
, NULL
);
177 assert_se(r
== -ENOLINK
);
178 result
= mfree(result
);
180 /* Allow this when the user-owned directories are all in the "root". */
181 r
= chase_symlinks(p
, q
, CHASE_SAFE
, &result
, NULL
);
183 result
= mfree(result
);
188 r
= chase_symlinks("/etc/./.././", NULL
, 0, &result
, NULL
);
190 assert_se(path_equal(result
, "/"));
191 result
= mfree(result
);
193 r
= chase_symlinks("/etc/./.././", "/etc", 0, &result
, NULL
);
194 assert_se(r
> 0 && path_equal(result
, "/etc"));
195 result
= mfree(result
);
197 r
= chase_symlinks("/../.././//../../etc", NULL
, 0, &result
, NULL
);
199 assert_se(streq(result
, "/etc"));
200 result
= mfree(result
);
202 r
= chase_symlinks("/../.././//../../test-chase.fsldajfl", NULL
, CHASE_NONEXISTENT
, &result
, NULL
);
204 assert_se(streq(result
, "/test-chase.fsldajfl"));
205 result
= mfree(result
);
207 r
= chase_symlinks("/../.././//../../etc", "/", CHASE_PREFIX_ROOT
, &result
, NULL
);
209 assert_se(streq(result
, "/etc"));
210 result
= mfree(result
);
212 r
= chase_symlinks("/../.././//../../test-chase.fsldajfl", "/", CHASE_PREFIX_ROOT
|CHASE_NONEXISTENT
, &result
, NULL
);
214 assert_se(streq(result
, "/test-chase.fsldajfl"));
215 result
= mfree(result
);
217 r
= chase_symlinks("/etc/machine-id/foo", NULL
, 0, &result
, NULL
);
218 assert_se(r
== -ENOTDIR
);
219 result
= mfree(result
);
221 /* Path that loops back to self */
223 p
= strjoina(temp
, "/recursive-symlink");
224 assert_se(symlink("recursive-symlink", p
) >= 0);
225 r
= chase_symlinks(p
, NULL
, 0, &result
, NULL
);
226 assert_se(r
== -ELOOP
);
228 /* Path which doesn't exist */
230 p
= strjoina(temp
, "/idontexist");
231 r
= chase_symlinks(p
, NULL
, 0, &result
, NULL
);
232 assert_se(r
== -ENOENT
);
234 r
= chase_symlinks(p
, NULL
, CHASE_NONEXISTENT
, &result
, NULL
);
236 assert_se(path_equal(result
, p
));
237 result
= mfree(result
);
239 p
= strjoina(temp
, "/idontexist/meneither");
240 r
= chase_symlinks(p
, NULL
, 0, &result
, NULL
);
241 assert_se(r
== -ENOENT
);
243 r
= chase_symlinks(p
, NULL
, CHASE_NONEXISTENT
, &result
, NULL
);
245 assert_se(path_equal(result
, p
));
246 result
= mfree(result
);
248 /* Path which doesn't exist, but contains weird stuff */
250 p
= strjoina(temp
, "/idontexist/..");
251 r
= chase_symlinks(p
, NULL
, 0, &result
, NULL
);
252 assert_se(r
== -ENOENT
);
254 r
= chase_symlinks(p
, NULL
, CHASE_NONEXISTENT
, &result
, NULL
);
255 assert_se(r
== -ENOENT
);
257 p
= strjoina(temp
, "/target");
258 q
= strjoina(temp
, "/top");
259 assert_se(symlink(q
, p
) >= 0);
260 p
= strjoina(temp
, "/target/idontexist");
261 r
= chase_symlinks(p
, NULL
, 0, &result
, NULL
);
262 assert_se(r
== -ENOENT
);
264 if (geteuid() == 0) {
265 p
= strjoina(temp
, "/priv1");
266 assert_se(mkdir(p
, 0755) >= 0);
268 q
= strjoina(p
, "/priv2");
269 assert_se(mkdir(q
, 0755) >= 0);
271 assert_se(chase_symlinks(q
, NULL
, CHASE_SAFE
, NULL
, NULL
) >= 0);
273 assert_se(chown(q
, UID_NOBODY
, GID_NOBODY
) >= 0);
274 assert_se(chase_symlinks(q
, NULL
, CHASE_SAFE
, NULL
, NULL
) >= 0);
276 assert_se(chown(p
, UID_NOBODY
, GID_NOBODY
) >= 0);
277 assert_se(chase_symlinks(q
, NULL
, CHASE_SAFE
, NULL
, NULL
) >= 0);
279 assert_se(chown(q
, 0, 0) >= 0);
280 assert_se(chase_symlinks(q
, NULL
, CHASE_SAFE
, NULL
, NULL
) == -ENOLINK
);
282 assert_se(rmdir(q
) >= 0);
283 assert_se(symlink("/etc/passwd", q
) >= 0);
284 assert_se(chase_symlinks(q
, NULL
, CHASE_SAFE
, NULL
, NULL
) == -ENOLINK
);
286 assert_se(chown(p
, 0, 0) >= 0);
287 assert_se(chase_symlinks(q
, NULL
, CHASE_SAFE
, NULL
, NULL
) >= 0);
290 p
= strjoina(temp
, "/machine-id-test");
291 assert_se(symlink("/usr/../etc/./machine-id", p
) >= 0);
293 r
= chase_symlinks(p
, NULL
, 0, NULL
, &pfd
);
295 _cleanup_close_
int fd
= -1;
300 fd
= fd_reopen(pfd
, O_RDONLY
|O_CLOEXEC
);
304 assert_se(id128_read_fd(fd
, ID128_PLAIN
, &a
) >= 0);
305 assert_se(sd_id128_get_machine(&b
) >= 0);
306 assert_se(sd_id128_equal(a
, b
));
309 /* Test CHASE_NOFOLLOW */
311 p
= strjoina(temp
, "/target");
312 q
= strjoina(temp
, "/symlink");
313 assert_se(symlink(p
, q
) >= 0);
314 r
= chase_symlinks(q
, NULL
, CHASE_NOFOLLOW
, &result
, &pfd
);
317 assert_se(path_equal(result
, q
));
318 assert_se(fstat(pfd
, &st
) >= 0);
319 assert_se(S_ISLNK(st
.st_mode
));
320 result
= mfree(result
);
322 /* s1 -> s2 -> nonexistent */
323 q
= strjoina(temp
, "/s1");
324 assert_se(symlink("s2", q
) >= 0);
325 p
= strjoina(temp
, "/s2");
326 assert_se(symlink("nonexistent", p
) >= 0);
327 r
= chase_symlinks(q
, NULL
, CHASE_NOFOLLOW
, &result
, &pfd
);
330 assert_se(path_equal(result
, q
));
331 assert_se(fstat(pfd
, &st
) >= 0);
332 assert_se(S_ISLNK(st
.st_mode
));
333 result
= mfree(result
);
337 p
= strjoina(temp
, "/start");
338 r
= chase_symlinks(p
, NULL
, CHASE_STEP
, &result
, NULL
);
340 p
= strjoina(temp
, "/top/dot/dotdota");
341 assert_se(streq(p
, result
));
342 result
= mfree(result
);
344 r
= chase_symlinks(p
, NULL
, CHASE_STEP
, &result
, NULL
);
346 p
= strjoina(temp
, "/top/./dotdota");
347 assert_se(streq(p
, result
));
348 result
= mfree(result
);
350 r
= chase_symlinks(p
, NULL
, CHASE_STEP
, &result
, NULL
);
352 p
= strjoina(temp
, "/top/../a");
353 assert_se(streq(p
, result
));
354 result
= mfree(result
);
356 r
= chase_symlinks(p
, NULL
, CHASE_STEP
, &result
, NULL
);
358 p
= strjoina(temp
, "/a");
359 assert_se(streq(p
, result
));
360 result
= mfree(result
);
362 r
= chase_symlinks(p
, NULL
, CHASE_STEP
, &result
, NULL
);
364 p
= strjoina(temp
, "/b");
365 assert_se(streq(p
, result
));
366 result
= mfree(result
);
368 r
= chase_symlinks(p
, NULL
, CHASE_STEP
, &result
, NULL
);
370 assert_se(streq("/usr", result
));
371 result
= mfree(result
);
373 r
= chase_symlinks("/usr", NULL
, CHASE_STEP
, &result
, NULL
);
375 assert_se(streq("/usr", result
));
376 result
= mfree(result
);
378 /* Make sure that symlinks in the "root" path are not resolved, but those below are */
379 p
= strjoina("/etc/..", temp
, "/self");
380 assert_se(symlink(".", p
) >= 0);
381 q
= strjoina(p
, "/top/dot/dotdota");
382 r
= chase_symlinks(q
, p
, 0, &result
, NULL
);
384 assert_se(path_equal(path_startswith(result
, p
), "usr"));
385 result
= mfree(result
);
388 assert_se(rm_rf(temp
, REMOVE_ROOT
|REMOVE_PHYSICAL
) >= 0);
391 static void test_unlink_noerrno(void) {
395 log_info("/* %s */", __func__
);
397 name
= strjoina(arg_test_dir
?: "/tmp", "/test-close_nointr.XXXXXX");
398 fd
= mkostemp_safe(name
);
400 assert_se(close_nointr(fd
) >= 0);
405 assert_se(unlink_noerrno(name
) >= 0);
406 assert_se(errno
== 42);
407 assert_se(unlink_noerrno(name
) < 0);
408 assert_se(errno
== 42);
412 static void test_readlink_and_make_absolute(void) {
413 const char *tempdir
, *name
, *name2
, *name_alias
;
414 _cleanup_free_
char *r1
= NULL
, *r2
= NULL
, *pwd
= NULL
;
416 log_info("/* %s */", __func__
);
418 tempdir
= strjoina(arg_test_dir
?: "/tmp", "/test-readlink_and_make_absolute");
419 name
= strjoina(tempdir
, "/original");
420 name2
= "test-readlink_and_make_absolute/original";
421 name_alias
= strjoina(arg_test_dir
?: "/tmp", "/test-readlink_and_make_absolute-alias");
423 assert_se(mkdir_safe(tempdir
, 0755, getuid(), getgid(), MKDIR_WARN_MODE
) >= 0);
424 assert_se(touch(name
) >= 0);
426 if (symlink(name
, name_alias
) < 0) {
427 assert_se(IN_SET(errno
, EINVAL
, ENOSYS
, ENOTTY
, EPERM
));
428 log_tests_skipped_errno(errno
, "symlink() not possible");
430 assert_se(readlink_and_make_absolute(name_alias
, &r1
) >= 0);
431 assert_se(streq(r1
, name
));
432 assert_se(unlink(name_alias
) >= 0);
434 assert_se(safe_getcwd(&pwd
) >= 0);
436 assert_se(chdir(tempdir
) >= 0);
437 assert_se(symlink(name2
, name_alias
) >= 0);
438 assert_se(readlink_and_make_absolute(name_alias
, &r2
) >= 0);
439 assert_se(streq(r2
, name
));
440 assert_se(unlink(name_alias
) >= 0);
442 assert_se(chdir(pwd
) >= 0);
445 assert_se(rm_rf(tempdir
, REMOVE_ROOT
|REMOVE_PHYSICAL
) >= 0);
448 static void test_get_files_in_directory(void) {
449 _cleanup_strv_free_
char **l
= NULL
, **t
= NULL
;
451 assert_se(get_files_in_directory(arg_test_dir
?: "/tmp", &l
) >= 0);
452 assert_se(get_files_in_directory(".", &t
) >= 0);
453 assert_se(get_files_in_directory(".", NULL
) >= 0);
456 static void test_var_tmp(void) {
457 _cleanup_free_
char *tmpdir_backup
= NULL
, *temp_backup
= NULL
, *tmp_backup
= NULL
;
458 const char *tmp_dir
= NULL
, *t
;
460 log_info("/* %s */", __func__
);
462 t
= getenv("TMPDIR");
464 tmpdir_backup
= strdup(t
);
465 assert_se(tmpdir_backup
);
470 temp_backup
= strdup(t
);
471 assert_se(temp_backup
);
476 tmp_backup
= strdup(t
);
477 assert_se(tmp_backup
);
480 assert_se(unsetenv("TMPDIR") >= 0);
481 assert_se(unsetenv("TEMP") >= 0);
482 assert_se(unsetenv("TMP") >= 0);
484 assert_se(var_tmp_dir(&tmp_dir
) >= 0);
485 assert_se(streq(tmp_dir
, "/var/tmp"));
487 assert_se(setenv("TMPDIR", "/tmp", true) >= 0);
488 assert_se(streq(getenv("TMPDIR"), "/tmp"));
490 assert_se(var_tmp_dir(&tmp_dir
) >= 0);
491 assert_se(streq(tmp_dir
, "/tmp"));
493 assert_se(setenv("TMPDIR", "/88_does_not_exist_88", true) >= 0);
494 assert_se(streq(getenv("TMPDIR"), "/88_does_not_exist_88"));
496 assert_se(var_tmp_dir(&tmp_dir
) >= 0);
497 assert_se(streq(tmp_dir
, "/var/tmp"));
500 assert_se(setenv("TMPDIR", tmpdir_backup
, true) >= 0);
501 assert_se(streq(getenv("TMPDIR"), tmpdir_backup
));
505 assert_se(setenv("TEMP", temp_backup
, true) >= 0);
506 assert_se(streq(getenv("TEMP"), temp_backup
));
510 assert_se(setenv("TMP", tmp_backup
, true) >= 0);
511 assert_se(streq(getenv("TMP"), tmp_backup
));
515 static void test_dot_or_dot_dot(void) {
516 log_info("/* %s */", __func__
);
518 assert_se(!dot_or_dot_dot(NULL
));
519 assert_se(!dot_or_dot_dot(""));
520 assert_se(!dot_or_dot_dot("xxx"));
521 assert_se(dot_or_dot_dot("."));
522 assert_se(dot_or_dot_dot(".."));
523 assert_se(!dot_or_dot_dot(".foo"));
524 assert_se(!dot_or_dot_dot("..foo"));
527 static void test_access_fd(void) {
528 _cleanup_(rmdir_and_freep
) char *p
= NULL
;
529 _cleanup_close_
int fd
= -1;
532 log_info("/* %s */", __func__
);
534 a
= strjoina(arg_test_dir
?: "/tmp", "/access-fd.XXXXXX");
535 assert_se(mkdtemp_malloc(a
, &p
) >= 0);
537 fd
= open(p
, O_RDONLY
|O_DIRECTORY
|O_CLOEXEC
);
540 assert_se(access_fd(fd
, R_OK
) >= 0);
541 assert_se(access_fd(fd
, F_OK
) >= 0);
542 assert_se(access_fd(fd
, W_OK
) >= 0);
544 assert_se(fchmod(fd
, 0000) >= 0);
546 assert_se(access_fd(fd
, F_OK
) >= 0);
548 if (geteuid() == 0) {
549 assert_se(access_fd(fd
, R_OK
) >= 0);
550 assert_se(access_fd(fd
, W_OK
) >= 0);
552 assert_se(access_fd(fd
, R_OK
) == -EACCES
);
553 assert_se(access_fd(fd
, W_OK
) == -EACCES
);
557 static void test_touch_file(void) {
558 uid_t test_uid
, test_gid
;
559 _cleanup_(rm_rf_physical_and_freep
) char *p
= NULL
;
565 log_info("/* %s */", __func__
);
567 test_uid
= geteuid() == 0 ? 65534 : getuid();
568 test_gid
= geteuid() == 0 ? 65534 : getgid();
570 test_mtime
= usec_sub_unsigned(now(CLOCK_REALTIME
), USEC_PER_WEEK
);
572 a
= strjoina(arg_test_dir
?: "/dev/shm", "/touch-file-XXXXXX");
573 assert_se(mkdtemp_malloc(a
, &p
) >= 0);
575 a
= strjoina(p
, "/regular");
576 r
= touch_file(a
, false, test_mtime
, test_uid
, test_gid
, 0640);
578 assert_se(IN_SET(r
, -EINVAL
, -ENOSYS
, -ENOTTY
, -EPERM
));
579 log_tests_skipped_errno(errno
, "touch_file() not possible");
583 assert_se(lstat(a
, &st
) >= 0);
584 assert_se(st
.st_uid
== test_uid
);
585 assert_se(st
.st_gid
== test_gid
);
586 assert_se(S_ISREG(st
.st_mode
));
587 assert_se((st
.st_mode
& 0777) == 0640);
588 assert_se(timespec_load(&st
.st_mtim
) == test_mtime
);
590 a
= strjoina(p
, "/dir");
591 assert_se(mkdir(a
, 0775) >= 0);
592 assert_se(touch_file(a
, false, test_mtime
, test_uid
, test_gid
, 0640) >= 0);
593 assert_se(lstat(a
, &st
) >= 0);
594 assert_se(st
.st_uid
== test_uid
);
595 assert_se(st
.st_gid
== test_gid
);
596 assert_se(S_ISDIR(st
.st_mode
));
597 assert_se((st
.st_mode
& 0777) == 0640);
598 assert_se(timespec_load(&st
.st_mtim
) == test_mtime
);
600 a
= strjoina(p
, "/fifo");
601 assert_se(mkfifo(a
, 0775) >= 0);
602 assert_se(touch_file(a
, false, test_mtime
, test_uid
, test_gid
, 0640) >= 0);
603 assert_se(lstat(a
, &st
) >= 0);
604 assert_se(st
.st_uid
== test_uid
);
605 assert_se(st
.st_gid
== test_gid
);
606 assert_se(S_ISFIFO(st
.st_mode
));
607 assert_se((st
.st_mode
& 0777) == 0640);
608 assert_se(timespec_load(&st
.st_mtim
) == test_mtime
);
610 a
= strjoina(p
, "/sock");
611 assert_se(mknod(a
, 0775 | S_IFSOCK
, 0) >= 0);
612 assert_se(touch_file(a
, false, test_mtime
, test_uid
, test_gid
, 0640) >= 0);
613 assert_se(lstat(a
, &st
) >= 0);
614 assert_se(st
.st_uid
== test_uid
);
615 assert_se(st
.st_gid
== test_gid
);
616 assert_se(S_ISSOCK(st
.st_mode
));
617 assert_se((st
.st_mode
& 0777) == 0640);
618 assert_se(timespec_load(&st
.st_mtim
) == test_mtime
);
620 if (geteuid() == 0) {
621 a
= strjoina(p
, "/bdev");
622 r
= mknod(a
, 0775 | S_IFBLK
, makedev(0, 0));
623 if (r
< 0 && errno
== EPERM
&& detect_container() > 0) {
624 log_notice("Running in unprivileged container? Skipping remaining tests in %s", __func__
);
628 assert_se(touch_file(a
, false, test_mtime
, test_uid
, test_gid
, 0640) >= 0);
629 assert_se(lstat(a
, &st
) >= 0);
630 assert_se(st
.st_uid
== test_uid
);
631 assert_se(st
.st_gid
== test_gid
);
632 assert_se(S_ISBLK(st
.st_mode
));
633 assert_se((st
.st_mode
& 0777) == 0640);
634 assert_se(timespec_load(&st
.st_mtim
) == test_mtime
);
636 a
= strjoina(p
, "/cdev");
637 assert_se(mknod(a
, 0775 | S_IFCHR
, makedev(0, 0)) >= 0);
638 assert_se(touch_file(a
, false, test_mtime
, test_uid
, test_gid
, 0640) >= 0);
639 assert_se(lstat(a
, &st
) >= 0);
640 assert_se(st
.st_uid
== test_uid
);
641 assert_se(st
.st_gid
== test_gid
);
642 assert_se(S_ISCHR(st
.st_mode
));
643 assert_se((st
.st_mode
& 0777) == 0640);
644 assert_se(timespec_load(&st
.st_mtim
) == test_mtime
);
647 a
= strjoina(p
, "/lnk");
648 assert_se(symlink("target", a
) >= 0);
649 assert_se(touch_file(a
, false, test_mtime
, test_uid
, test_gid
, 0640) >= 0);
650 assert_se(lstat(a
, &st
) >= 0);
651 assert_se(st
.st_uid
== test_uid
);
652 assert_se(st
.st_gid
== test_gid
);
653 assert_se(S_ISLNK(st
.st_mode
));
654 assert_se(timespec_load(&st
.st_mtim
) == test_mtime
);
657 static void test_unlinkat_deallocate(void) {
658 _cleanup_free_
char *p
= NULL
;
659 _cleanup_close_
int fd
= -1;
662 log_info("/* %s */", __func__
);
664 assert_se(tempfn_random_child(arg_test_dir
, "unlink-deallocation", &p
) >= 0);
666 fd
= open(p
, O_WRONLY
|O_CLOEXEC
|O_CREAT
|O_EXCL
, 0600);
669 assert_se(write(fd
, "hallo\n", 6) == 6);
671 assert_se(fstat(fd
, &st
) >= 0);
672 assert_se(st
.st_size
== 6);
673 assert_se(st
.st_blocks
> 0);
674 assert_se(st
.st_nlink
== 1);
676 assert_se(unlinkat_deallocate(AT_FDCWD
, p
, UNLINK_ERASE
) >= 0);
678 assert_se(fstat(fd
, &st
) >= 0);
679 assert_se(IN_SET(st
.st_size
, 0, 6)); /* depending on whether hole punching worked the size will be 6
680 (it worked) or 0 (we had to resort to truncation) */
681 assert_se(st
.st_blocks
== 0);
682 assert_se(st
.st_nlink
== 0);
685 static void test_fsync_directory_of_file(void) {
686 _cleanup_close_
int fd
= -1;
688 log_info("/* %s */", __func__
);
690 fd
= open_tmpfile_unlinkable(arg_test_dir
, O_RDWR
);
693 assert_se(fsync_directory_of_file(fd
) >= 0);
696 static void test_rename_noreplace(void) {
697 static const char* const table
[] = {
706 _cleanup_(rm_rf_physical_and_freep
) char *z
= NULL
;
707 const char *j
= NULL
;
710 log_info("/* %s */", __func__
);
713 j
= strjoina(arg_test_dir
, "/testXXXXXX");
714 assert_se(mkdtemp_malloc(j
, &z
) >= 0);
716 j
= strjoina(z
, table
[0]);
717 assert_se(touch(j
) >= 0);
719 j
= strjoina(z
, table
[1]);
720 assert_se(mkdir(j
, 0777) >= 0);
722 j
= strjoina(z
, table
[2]);
723 (void) mkfifo(j
, 0777);
725 j
= strjoina(z
, table
[3]);
726 (void) mknod(j
, S_IFSOCK
| 0777, 0);
728 j
= strjoina(z
, table
[4]);
729 (void) symlink("foobar", j
);
731 STRV_FOREACH(a
, (char**) table
) {
732 _cleanup_free_
char *x
= NULL
, *y
= NULL
;
737 if (access(x
, F_OK
) < 0) {
738 assert_se(errno
== ENOENT
);
742 STRV_FOREACH(b
, (char**) table
) {
743 _cleanup_free_
char *w
= NULL
;
748 if (access(w
, F_OK
) < 0) {
749 assert_se(errno
== ENOENT
);
753 assert_se(rename_noreplace(AT_FDCWD
, x
, AT_FDCWD
, w
) == -EEXIST
);
756 y
= strjoin(z
, "/somethingelse");
759 assert_se(rename_noreplace(AT_FDCWD
, x
, AT_FDCWD
, y
) >= 0);
760 assert_se(rename_noreplace(AT_FDCWD
, y
, AT_FDCWD
, x
) >= 0);
764 static void test_chmod_and_chown(void) {
765 _cleanup_(rm_rf_physical_and_freep
) char *d
= NULL
;
766 _unused_ _cleanup_umask_ mode_t u
= umask(0000);
773 log_info("/* %s */", __func__
);
775 assert_se(mkdtemp_malloc(NULL
, &d
) >= 0);
777 p
= strjoina(d
, "/reg");
778 assert_se(mknod(p
, S_IFREG
| 0123, 0) >= 0);
780 assert_se(chmod_and_chown(p
, S_IFREG
| 0321, 1, 2) >= 0);
781 assert_se(chmod_and_chown(p
, S_IFDIR
| 0555, 3, 4) == -EINVAL
);
783 assert_se(lstat(p
, &st
) >= 0);
784 assert_se(S_ISREG(st
.st_mode
));
785 assert_se((st
.st_mode
& 07777) == 0321);
787 p
= strjoina(d
, "/dir");
788 assert_se(mkdir(p
, 0123) >= 0);
790 assert_se(chmod_and_chown(p
, S_IFDIR
| 0321, 1, 2) >= 0);
791 assert_se(chmod_and_chown(p
, S_IFREG
| 0555, 3, 4) == -EINVAL
);
793 assert_se(lstat(p
, &st
) >= 0);
794 assert_se(S_ISDIR(st
.st_mode
));
795 assert_se((st
.st_mode
& 07777) == 0321);
797 p
= strjoina(d
, "/lnk");
798 assert_se(symlink("idontexist", p
) >= 0);
800 assert_se(chmod_and_chown(p
, S_IFLNK
| 0321, 1, 2) >= 0);
801 assert_se(chmod_and_chown(p
, S_IFREG
| 0555, 3, 4) == -EINVAL
);
802 assert_se(chmod_and_chown(p
, S_IFDIR
| 0555, 3, 4) == -EINVAL
);
804 assert_se(lstat(p
, &st
) >= 0);
805 assert_se(S_ISLNK(st
.st_mode
));
808 static void test_path_is_encrypted_one(const char *p
, int expect
) {
811 r
= path_is_encrypted(p
);
812 if (r
== -ENOENT
|| ERRNO_IS_PRIVILEGE(r
)) /* This might fail, if btrfs is used and we run in a
813 * container. In that case we cannot resolve the device node paths that
814 * BTRFS_IOC_DEV_INFO returns, because the device nodes are unlikely to exist in
815 * the container. But if we can't stat() them we cannot determine the dev_t of
816 * them, and thus cannot figure out if they are enrypted. Hence let's just ignore
817 * ENOENT here. Also skip the test if we lack privileges. */
821 log_info("%s encrypted: %s", p
, yes_no(r
));
823 assert_se(expect
< 0 || ((r
> 0) == (expect
> 0)));
826 static void test_path_is_encrypted(void) {
827 int booted
= sd_booted(); /* If this is run in build environments such as koji, /dev might be a
828 * reguar fs. Don't assume too much if not running under systemd. */
830 log_info("/* %s (sd_booted=%d)*/", __func__
, booted
);
832 test_path_is_encrypted_one("/home", -1);
833 test_path_is_encrypted_one("/var", -1);
834 test_path_is_encrypted_one("/", -1);
835 test_path_is_encrypted_one("/proc", false);
836 test_path_is_encrypted_one("/sys", false);
837 test_path_is_encrypted_one("/dev", booted
> 0 ? false : -1);
840 static void create_binary_file(const char *p
, const void *data
, size_t l
) {
841 _cleanup_close_
int fd
= -1;
843 fd
= open(p
, O_CREAT
|O_WRONLY
|O_EXCL
|O_CLOEXEC
, 0600);
845 assert_se(write(fd
, data
, l
) == (ssize_t
) l
);
848 static void test_conservative_rename(void) {
849 _cleanup_(unlink_and_freep
) char *p
= NULL
;
850 _cleanup_free_
char *q
= NULL
;
851 size_t l
= 16*1024 + random_u64() % (32 * 1024); /* some randomly sized buffer 16k…48k */
854 random_bytes(buffer
, l
);
856 assert_se(tempfn_random_child(NULL
, NULL
, &p
) >= 0);
857 create_binary_file(p
, buffer
, l
);
859 assert_se(tempfn_random_child(NULL
, NULL
, &q
) >= 0);
861 /* Check that the hardlinked "copy" is detected */
862 assert_se(link(p
, q
) >= 0);
863 assert_se(conservative_renameat(AT_FDCWD
, q
, AT_FDCWD
, p
) == 0);
864 assert_se(access(q
, F_OK
) < 0 && errno
== ENOENT
);
866 /* Check that a manual copy is detected */
867 assert_se(copy_file(p
, q
, 0, (mode_t
) -1, 0, 0, COPY_REFLINK
) >= 0);
868 assert_se(conservative_renameat(AT_FDCWD
, q
, AT_FDCWD
, p
) == 0);
869 assert_se(access(q
, F_OK
) < 0 && errno
== ENOENT
);
871 /* Check that a manual new writeout is also detected */
872 create_binary_file(q
, buffer
, l
);
873 assert_se(conservative_renameat(AT_FDCWD
, q
, AT_FDCWD
, p
) == 0);
874 assert_se(access(q
, F_OK
) < 0 && errno
== ENOENT
);
876 /* Check that a minimally changed version is detected */
877 buffer
[47] = ~buffer
[47];
878 create_binary_file(q
, buffer
, l
);
879 assert_se(conservative_renameat(AT_FDCWD
, q
, AT_FDCWD
, p
) > 0);
880 assert_se(access(q
, F_OK
) < 0 && errno
== ENOENT
);
882 /* Check that this really is new updated version */
883 create_binary_file(q
, buffer
, l
);
884 assert_se(conservative_renameat(AT_FDCWD
, q
, AT_FDCWD
, p
) == 0);
885 assert_se(access(q
, F_OK
) < 0 && errno
== ENOENT
);
887 /* Make sure we detect extended files */
889 create_binary_file(q
, buffer
, l
);
890 assert_se(conservative_renameat(AT_FDCWD
, q
, AT_FDCWD
, p
) > 0);
891 assert_se(access(q
, F_OK
) < 0 && errno
== ENOENT
);
893 /* Make sure we detect truncated files */
895 create_binary_file(q
, buffer
, l
);
896 assert_se(conservative_renameat(AT_FDCWD
, q
, AT_FDCWD
, p
) > 0);
897 assert_se(access(q
, F_OK
) < 0 && errno
== ENOENT
);
900 int main(int argc
, char *argv
[]) {
901 test_setup_logging(LOG_INFO
);
903 arg_test_dir
= argv
[1];
905 test_chase_symlinks();
906 test_unlink_noerrno();
907 test_readlink_and_make_absolute();
908 test_get_files_in_directory();
910 test_dot_or_dot_dot();
913 test_unlinkat_deallocate();
914 test_fsync_directory_of_file();
915 test_rename_noreplace();
916 test_chmod_and_chown();
917 test_path_is_encrypted();
918 test_conservative_rename();