1d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes/*
2d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * Check decoding of struct msghdr.msg_name* arguments of recvmsg syscall.
3d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes *
4d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * Copyright (c) 2016 Dmitry V. Levin <ldv@altlinux.org>
539bac055674d23770b9a724221b728e443196ea7Elliott Hughes * Copyright (c) 2016-2017 The strace developers.
6d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * All rights reserved.
7d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes *
8d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * Redistribution and use in source and binary forms, with or without
9d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * modification, are permitted provided that the following conditions
10d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * are met:
11d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * 1. Redistributions of source code must retain the above copyright
12d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes *    notice, this list of conditions and the following disclaimer.
13d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * 2. Redistributions in binary form must reproduce the above copyright
14d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes *    notice, this list of conditions and the following disclaimer in the
15d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes *    documentation and/or other materials provided with the distribution.
16d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * 3. The name of the author may not be used to endorse or promote products
17d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes *    derived from this software without specific prior written permission.
18d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes *
19d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
20d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
21d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
22d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
23d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
24d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
25d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
26d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
27d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
28d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
29d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes */
30d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
31d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include "tests.h"
32d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <stddef.h>
33d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <stdio.h>
34d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <string.h>
35d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <unistd.h>
36d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <sys/socket.h>
37d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#include <sys/un.h>
38d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
39d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughesstatic int
40d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughessend_recv(const int send_fd, const int recv_fd,
41d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	 struct msghdr *const msg, const int flags)
42d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes{
43d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	if (send(send_fd, "A", 1, 0) != 1)
44d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes		perror_msg_and_skip("send");
45d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	return recvmsg(recv_fd, msg, flags);
46d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes}
47d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
48d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughesstatic void
49d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughestest_msg_name(const int send_fd, const int recv_fd)
50d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes{
5139bac055674d23770b9a724221b728e443196ea7Elliott Hughes	TAIL_ALLOC_OBJECT_CONST_PTR(char, recv_buf);
5239bac055674d23770b9a724221b728e443196ea7Elliott Hughes	TAIL_ALLOC_OBJECT_CONST_PTR(struct iovec, iov);
53d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	iov->iov_base = recv_buf;
54d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	iov->iov_len = sizeof(*recv_buf);
55d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
5639bac055674d23770b9a724221b728e443196ea7Elliott Hughes	TAIL_ALLOC_OBJECT_CONST_PTR(struct sockaddr_un, addr);
5739bac055674d23770b9a724221b728e443196ea7Elliott Hughes	TAIL_ALLOC_OBJECT_CONST_PTR(struct msghdr, msg);
58d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_name = addr;
59d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_namelen = sizeof(*addr);
60d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_iov = iov;
61d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_iovlen = 1;
62d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_control = 0;
63d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_controllen = 0;
64d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_flags = 0;
65d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
66d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	int rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
67d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	if (rc < 0)
68d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes		perror_msg_and_skip("recvmsg");
69d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX, sun_path=\"%s\"}"
70d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ", msg_namelen=%d->%d, msg_iov=[{iov_base=\"A\", iov_len=1}]"
71d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ", msg_iovlen=1, msg_controllen=0, msg_flags=0}, MSG_DONTWAIT)"
72d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       " = %d\n",
73d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       recv_fd, addr->sun_path, (int) sizeof(struct sockaddr_un),
74d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       (int) msg->msg_namelen, rc);
75d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
76d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	memset(addr, 0, sizeof(*addr));
77d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
78d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX, sun_path=\"%s\"}"
79d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ", msg_namelen=%d, msg_iov=[{iov_base=\"A\", iov_len=1}]"
80d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ", msg_iovlen=1, msg_controllen=0, msg_flags=0}, MSG_DONTWAIT)"
81d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       " = %d\n",
82d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       recv_fd, addr->sun_path, (int) msg->msg_namelen, rc);
83d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
84d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_name = 0;
85d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
86d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	printf("recvmsg(%d, {msg_name=NULL, msg_namelen=%d"
87d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ", msg_iov=[{iov_base=\"A\", iov_len=1}], msg_iovlen=1"
88d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ", msg_controllen=0, msg_flags=0}, MSG_DONTWAIT) = %d\n",
89d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       recv_fd, (int) msg->msg_namelen, rc);
90d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
91d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	const size_t offsetof_sun_path = offsetof(struct sockaddr_un, sun_path);
92d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_name = addr;
93d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_namelen = offsetof_sun_path;
94d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	memset(addr->sun_path, 'A', sizeof(addr->sun_path));
95d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
96d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
97d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX}, msg_namelen=%d->%d"
98d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ", msg_iov=[{iov_base=\"A\", iov_len=1}], msg_iovlen=1"
99d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ", msg_controllen=0, msg_flags=0}, MSG_DONTWAIT) = %d\n",
100d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       recv_fd, (int) offsetof_sun_path, (int) msg->msg_namelen, rc);
101d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
102d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_namelen = sizeof(struct sockaddr);
103d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	msg->msg_name = ((void *) (addr + 1)) - msg->msg_namelen;
104d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
105d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	printf("recvmsg(%d, {msg_name={sa_family=AF_UNIX, sun_path=\"%.*s\"}"
106d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ", msg_namelen=%d->%d, msg_iov=[{iov_base=\"A\", iov_len=1}]"
107d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ", msg_iovlen=1, msg_controllen=0, msg_flags=0}, MSG_DONTWAIT)"
108d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       " = %d\n",
109d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       recv_fd, (int) (sizeof(struct sockaddr) - offsetof_sun_path),
110d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       ((struct sockaddr_un *) msg->msg_name)->sun_path,
111d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       (int) sizeof(struct sockaddr), (int) msg->msg_namelen, rc);
112d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
113d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	rc = send_recv(send_fd, recv_fd, msg, MSG_DONTWAIT);
114d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	printf("recvmsg(%d, {msg_namelen=%d}, MSG_DONTWAIT) = %d %s (%m)\n",
115d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       recv_fd, (int) msg->msg_namelen, rc, errno2name());
116d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
117d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	/*
118d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	 * When recvmsg is called with a valid descriptor
119d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	 * but inaccessible memory, it causes segfaults on some architectures.
120d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	 * As in these cases we test decoding of failed recvmsg calls,
121d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	 * it's ok to fail recvmsg with any reason as long as
122d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	 * it doesn't read that inaccessible memory.
123d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	 */
124d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
125d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	/*
126d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	 * Sadly, musl recvmsg wrapper blindly dereferences 2nd argument,
127d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	 * so limit this test to glibc that doesn't.
128d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	 */
129d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#ifdef __GLIBC__
130d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	rc = send_recv(send_fd, -1, msg + 1, 0);
131d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	printf("recvmsg(-1, %p, 0) = %d %s (%m)\n",
132d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       msg + 1, rc, errno2name());
133d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes#endif
134d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
135d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	rc = send_recv(send_fd, -1, 0, 0);
136d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	printf("recvmsg(-1, NULL, 0) = %d %s (%m)\n",
137d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	       rc, errno2name());
138d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes}
139d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
140d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughesint
141d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughesmain(void)
142d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes{
143d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	int fds[2];
144d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	if (socketpair(AF_UNIX, SOCK_STREAM, 0, fds))
145d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes		perror_msg_and_skip("socketpair");
146d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
147d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	const struct sockaddr_un un = {
148d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes		.sun_family = AF_UNIX,
149d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes		.sun_path = "msg_name-recvmsg.test.send.socket"
150d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	};
151d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
152d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	(void) unlink(un.sun_path);
153d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	if (bind(fds[1], (const void *) &un, sizeof(un)))
154d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes		perror_msg_and_skip("bind");
155d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	(void) unlink(un.sun_path);
156d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
157d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	test_msg_name(fds[1], fds[0]);
158d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes
159d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	puts("+++ exited with 0 +++");
160d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes	return 0;
161d35df493b4e7684c50d2d2fa032ee3a7ac228009Elliott Hughes}
162