1d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes/* 2d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * Check decoding of struct msghdr.msg_name* arguments of recvmsg syscall. 3d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * 4d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * Copyright (c) 2016 Dmitry V. Levin <ldv@altlinux.org> 539bac055674d23770b9a724221b728e443196ea7Elliott Hughes * Copyright (c) 2016-2017 The strace developers. 6d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * All rights reserved. 7d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * 8d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * Redistribution and use in source and binary forms, with or without 9d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * modification, are permitted provided that the following conditions 10d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * are met: 11d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * 1. Redistributions of source code must retain the above copyright 12d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * notice, this list of conditions and the following disclaimer. 13d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * 2. Redistributions in binary form must reproduce the above copyright 14d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * notice, this list of conditions and the following disclaimer in the 15d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * documentation and/or other materials provided with the distribution. 16d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * 3. The name of the author may not be used to endorse or promote products 17d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * derived from this software without specific prior written permission. 18d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * 19d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 20d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 21d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 22d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 23d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 24d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 25d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 26d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 27d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 28d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 29d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes */ 30d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 31d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include "tests.h" 32d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <stddef.h> 33d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <stdio.h> 34d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <string.h> 35d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <unistd.h> 36d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <sys/socket.h> 37d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <sys/un.h> 38d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 39d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughesstatic int 40d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughessend_recv(const int send_fd, const int recv_fd, 41d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes struct msghdr *const msg, const int flags) 42d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes{ 43d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes if (send(send_fd, "A", 1, 0) != 1) 44d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes perror_msg_and_skip("send"); 45d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes return recvmsg(recv_fd, msg, flags); 46d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes} 47d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 48d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughesstatic void 49d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughestest_msg_name(const int send_fd, const int recv_fd) 50d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes{ 5139bac055674d23770b9a724221b728e443196ea7Elliott Hughes TAIL_ALLOC_OBJECT_CONST_PTR(char, recv_buf); 5239bac055674d23770b9a724221b728e443196ea7Elliott Hughes TAIL_ALLOC_OBJECT_CONST_PTR(struct iovec, iov); 53d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes iov->iov_base = recv_buf; 54d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes iov->iov_len = sizeof(*recv_buf); 55d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 5639bac055674d23770b9a724221b728e443196ea7Elliott Hughes TAIL_ALLOC_OBJECT_CONST_PTR(struct sockaddr_un, addr); 5739bac055674d23770b9a724221b728e443196ea7Elliott Hughes TAIL_ALLOC_OBJECT_CONST_PTR(struct msghdr, msg); 58d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_name = addr; 59d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_namelen = sizeof(*addr); 60d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_iov = iov; 61d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_iovlen = 1; 62d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_control = 0; 63d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_controllen = 0; 64d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_flags = 0; 65d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 66d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes int rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT); 67d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes if (rc < 0) 68d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes perror_msg_and_skip("recvmsg"); 69d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX, sun_path=\"%s\"}" 70d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ", msg_namelen=%d->%d, msg_iov=[{iov_base=\"A\", iov_len=1}]" 71d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ", msg_iovlen=1, msg_controllen=0, msg_flags=0}, MSG_DONTWAIT)" 72d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes " = %d\n", 73d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes recv_fd, addr->sun_path, (int) sizeof(struct sockaddr_un), 74d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes (int) msg->msg_namelen, rc); 75d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 76d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes memset(addr, 0, sizeof(*addr)); 77d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT); 78d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX, sun_path=\"%s\"}" 79d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ", msg_namelen=%d, msg_iov=[{iov_base=\"A\", iov_len=1}]" 80d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ", msg_iovlen=1, msg_controllen=0, msg_flags=0}, MSG_DONTWAIT)" 81d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes " = %d\n", 82d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes recv_fd, addr->sun_path, (int) msg->msg_namelen, rc); 83d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 84d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_name = 0; 85d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT); 86d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes printf("recvmsg(%d, {msg_name=NULL, msg_namelen=%d" 87d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ", msg_iov=[{iov_base=\"A\", iov_len=1}], msg_iovlen=1" 88d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ", msg_controllen=0, msg_flags=0}, MSG_DONTWAIT) = %d\n", 89d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes recv_fd, (int) msg->msg_namelen, rc); 90d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 91d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes const size_t offsetof_sun_path = offsetof(struct sockaddr_un, sun_path); 92d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_name = addr; 93d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_namelen = offsetof_sun_path; 94d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes memset(addr->sun_path, 'A', sizeof(addr->sun_path)); 95d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 96d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT); 97d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX}, msg_namelen=%d->%d" 98d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ", msg_iov=[{iov_base=\"A\", iov_len=1}], msg_iovlen=1" 99d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ", msg_controllen=0, msg_flags=0}, MSG_DONTWAIT) = %d\n", 100d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes recv_fd, (int) offsetof_sun_path, (int) msg->msg_namelen, rc); 101d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 102d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_namelen = sizeof(struct sockaddr); 103d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg->msg_name = ((void *) (addr + 1)) - msg->msg_namelen; 104d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT); 105d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX, sun_path=\"%.*s\"}" 106d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ", msg_namelen=%d->%d, msg_iov=[{iov_base=\"A\", iov_len=1}]" 107d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ", msg_iovlen=1, msg_controllen=0, msg_flags=0}, MSG_DONTWAIT)" 108d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes " = %d\n", 109d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes recv_fd, (int) (sizeof(struct sockaddr) - offsetof_sun_path), 110d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes ((struct sockaddr_un *) msg->msg_name)->sun_path, 111d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes (int) sizeof(struct sockaddr), (int) msg->msg_namelen, rc); 112d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 113d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT); 114d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes printf("recvmsg(%d, {msg_namelen=%d}, MSG_DONTWAIT) = %d %s (%m)\n", 115d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes recv_fd, (int) msg->msg_namelen, rc, errno2name()); 116d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 117d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes /* 118d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * When recvmsg is called with a valid descriptor 119d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * but inaccessible memory, it causes segfaults on some architectures. 120d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * As in these cases we test decoding of failed recvmsg calls, 121d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * it's ok to fail recvmsg with any reason as long as 122d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * it doesn't read that inaccessible memory. 123d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes */ 124d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 125d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes /* 126d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * Sadly, musl recvmsg wrapper blindly dereferences 2nd argument, 127d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * so limit this test to glibc that doesn't. 128d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes */ 129d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#ifdef __GLIBC__ 130d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes rc = send_recv(send_fd, -1, msg + 1, 0); 131d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes printf("recvmsg(-1, %p, 0) = %d %s (%m)\n", 132d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes msg + 1, rc, errno2name()); 133d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#endif 134d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 135d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes rc = send_recv(send_fd, -1, 0, 0); 136d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes printf("recvmsg(-1, NULL, 0) = %d %s (%m)\n", 137d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes rc, errno2name()); 138d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes} 139d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 140d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughesint 141d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughesmain(void) 142d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes{ 143d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes int fds[2]; 144d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes if (socketpair(AF_UNIX, SOCK_STREAM, 0, fds)) 145d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes perror_msg_and_skip("socketpair"); 146d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 147d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes const struct sockaddr_un un = { 148d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes .sun_family = AF_UNIX, 149d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes .sun_path = "msg_name-recvmsg.test.send.socket" 150d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes }; 151d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 152d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes (void) unlink(un.sun_path); 153d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes if (bind(fds[1], (const void *) &un, sizeof(un))) 154d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes perror_msg_and_skip("bind"); 155d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes (void) unlink(un.sun_path); 156d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 157d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes test_msg_name(fds[1], fds[0]); 158d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes 159d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes puts("+++ exited with 0 +++"); 160d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes return 0; 161d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes} 162