#include <errno.h>
#include <fcntl.h>
#include <pthread.h>
#include <sched.h>
#include <signal.h>
#include <stddef.h>
#include <stdint.h>
#include <sys/prctl.h>
#include <sys/ptrace.h>
#include <sys/socket.h>
#include <sys/syscall.h>
#include <sys/time.h>
#include <sys/types.h>
#include <sys/utsname.h>
#include <unistd.h>
#include <array>
#include <memory>
#include <vector>
#include "base/compiler_specific.h"
#include "base/containers/adapters.h"
#include "base/containers/contains.h"
#include "base/containers/span.h"
#if defined(ANDROID)
#define __user
#endif
#include <linux/futex.h>
#include "base/check.h"
#include "base/functional/bind.h"
#include "base/memory/raw_ptr.h"
#include "base/posix/eintr_wrapper.h"
#include "base/synchronization/waitable_event.h"
#include "base/system/sys_info.h"
#include "base/threading/thread.h"
#include "build/build_config.h"
#include "sandbox/linux/bpf_dsl/bpf_dsl.h"
#include "sandbox/linux/bpf_dsl/errorcode.h"
#include "sandbox/linux/bpf_dsl/linux_syscall_ranges.h"
#include "sandbox/linux/bpf_dsl/policy.h"
#include "sandbox/linux/bpf_dsl/seccomp_macros.h"
#include "sandbox/linux/seccomp-bpf/bpf_tests.h"
#include "sandbox/linux/seccomp-bpf/die.h"
#include "sandbox/linux/seccomp-bpf/sandbox_bpf.h"
#include "sandbox/linux/seccomp-bpf/syscall.h"
#include "sandbox/linux/seccomp-bpf/trap.h"
#include "sandbox/linux/services/syscall_wrappers.h"
#include "sandbox/linux/services/thread_helpers.h"
#include "sandbox/linux/system_headers/linux_syscalls.h"
#include "sandbox/linux/tests/scoped_temporary_file.h"
#include "sandbox/linux/tests/unit_tests.h"
#include "testing/gtest/include/gtest/gtest.h"
#ifndef PR_GET_ENDIAN
#define PR_GET_ENDIAN 19
#endif
#ifndef PR_CAPBSET_READ
#define PR_CAPBSET_READ 23
#define PR_CAPBSET_DROP 24
#endif
namespace sandbox {
namespace bpf_dsl {
namespace {
const int kExpectedReturnValue = 42;
const char kSandboxDebuggingEnv[] = "CHROME_SANDBOX_DEBUGGING";
void EnableUnsafeTraps() {
setenv(kSandboxDebuggingEnv, "t", 0);
Die::SuppressInfoMessages(true);
}
intptr_t IncreaseCounter(const struct arch_seccomp_data& args, void* aux) {
BPF_ASSERT(aux);
int* counter = static_cast<int*>(aux);
return (*counter)++;
}
class VerboseAPITestingPolicy : public Policy {
public:
explicit VerboseAPITestingPolicy(int* counter_ptr)
: counter_ptr_(counter_ptr) {}
VerboseAPITestingPolicy(const VerboseAPITestingPolicy&) = delete;
VerboseAPITestingPolicy& operator=(const VerboseAPITestingPolicy&) = delete;
~VerboseAPITestingPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (sysno == __NR_uname) {
return Trap(IncreaseCounter, counter_ptr_);
}
return Allow();
}
private:
const raw_ptr<int> counter_ptr_;
};
SANDBOX_TEST(SandboxBPF, DISABLE_ON_TSAN(VerboseAPITesting)) {
if (SandboxBPF::SupportsSeccompSandbox(
SandboxBPF::SeccompLevel::SINGLE_THREADED)) {
static int counter = 0;
SandboxBPF sandbox(std::make_unique<VerboseAPITestingPolicy>(&counter));
BPF_ASSERT(sandbox.StartSandbox(SandboxBPF::SeccompLevel::SINGLE_THREADED));
BPF_ASSERT_EQ(0, counter);
BPF_ASSERT_EQ(0, syscall(__NR_uname, 0));
BPF_ASSERT_EQ(1, counter);
BPF_ASSERT_EQ(1, syscall(__NR_uname, 0));
BPF_ASSERT_EQ(2, counter);
}
}
class DenylistNanosleepPolicy : public Policy {
public:
DenylistNanosleepPolicy() = default;
DenylistNanosleepPolicy(const DenylistNanosleepPolicy&) = delete;
DenylistNanosleepPolicy& operator=(const DenylistNanosleepPolicy&) = delete;
~DenylistNanosleepPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
switch (sysno) {
case __NR_nanosleep:
return Error(EACCES);
default:
return Allow();
}
}
static void AssertNanosleepFails() {
const struct timespec ts = {0, 0};
errno = 0;
BPF_ASSERT_EQ(-1, HANDLE_EINTR(syscall(__NR_nanosleep, &ts, NULL)));
BPF_ASSERT_EQ(EACCES, errno);
}
};
BPF_TEST_C(SandboxBPF, ApplyBasicDenylistPolicy, DenylistNanosleepPolicy) {
DenylistNanosleepPolicy::AssertNanosleepFails();
}
BPF_TEST_C(SandboxBPF, UseVsyscall, DenylistNanosleepPolicy) {
time_t current_time;
BPF_ASSERT_NE(static_cast<time_t>(-1), time(¤t_time));
}
bool IsSyscallForTestHarness(int sysno) {
if (sysno == __NR_exit_group || sysno == __NR_write) {
return true;
}
#if defined(ADDRESS_SANITIZER) || defined(MEMORY_SANITIZER) || \
defined(UNDEFINED_SANITIZER)
if (sysno == kMMapNr || sysno == __NR_munmap ||
#if !defined(__aarch64__)
sysno == __NR_pipe ||
#endif
sysno == __NR_pipe2 || sysno == __NR_sigaltstack) {
return true;
}
#endif
return false;
}
class AllowlistGetpidPolicy : public Policy {
public:
AllowlistGetpidPolicy() = default;
AllowlistGetpidPolicy(const AllowlistGetpidPolicy&) = delete;
AllowlistGetpidPolicy& operator=(const AllowlistGetpidPolicy&) = delete;
~AllowlistGetpidPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (IsSyscallForTestHarness(sysno) || sysno == __NR_getpid) {
return Allow();
}
return Error(ENOMEM);
}
};
BPF_TEST_C(SandboxBPF, ApplyBasicAllowlistPolicy, AllowlistGetpidPolicy) {
errno = 0;
BPF_ASSERT(sys_getpid() > 0);
BPF_ASSERT(errno == 0);
BPF_ASSERT(getpgid(0) == -1);
BPF_ASSERT(errno == ENOMEM);
}
intptr_t EnomemHandler(const struct arch_seccomp_data& args, void* aux) {
SANDBOX_ASSERT(aux);
*(static_cast<int*>(aux)) = kExpectedReturnValue;
return -ENOMEM;
}
class DenylistNanosleepTrapPolicy : public Policy {
public:
explicit DenylistNanosleepTrapPolicy(int* aux) : aux_(aux) {}
DenylistNanosleepTrapPolicy(const DenylistNanosleepTrapPolicy&) = delete;
DenylistNanosleepTrapPolicy& operator=(const DenylistNanosleepTrapPolicy&) =
delete;
~DenylistNanosleepTrapPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
switch (sysno) {
case __NR_nanosleep:
return Trap(EnomemHandler, aux_);
default:
return Allow();
}
}
private:
const raw_ptr<int> aux_;
};
BPF_TEST(SandboxBPF,
BasicDenylistWithSigsys,
DenylistNanosleepTrapPolicy,
int ) {
errno = 0;
BPF_ASSERT(sys_getpid() > 0);
BPF_ASSERT(errno == 0);
*BPF_AUX = -1;
const struct timespec ts = {0, 0};
BPF_ASSERT(syscall(__NR_nanosleep, &ts, NULL) == -1);
BPF_ASSERT(errno == ENOMEM);
BPF_ASSERT(*BPF_AUX == kExpectedReturnValue);
}
class ErrnoTestPolicy : public Policy {
public:
ErrnoTestPolicy() = default;
ErrnoTestPolicy(const ErrnoTestPolicy&) = delete;
ErrnoTestPolicy& operator=(const ErrnoTestPolicy&) = delete;
~ErrnoTestPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override;
};
ResultExpr ErrnoTestPolicy::EvaluateSyscall(int sysno) const {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
switch (sysno) {
case __NR_dup3:
#if defined(__NR_dup2)
case __NR_dup2:
#endif
return Error(0);
case __NR_setuid:
#if defined(__NR_setuid32)
case __NR_setuid32:
#endif
return Error(1);
case __NR_setgid:
#if defined(__NR_setgid32)
case __NR_setgid32:
#endif
return Error(ErrorCode::ERR_MAX_ERRNO);
case __NR_uname:
return Error(42);
default:
return Allow();
}
}
BPF_TEST_C(SandboxBPF, ErrnoTest, ErrnoTestPolicy) {
std::array<int, 4> fds;
BPF_ASSERT(pipe(fds.data()) == 0);
BPF_ASSERT(pipe(base::span(fds).subspan(2u).data()) == 0);
BPF_ASSERT(dup2(fds[2], fds[0]) == 0);
char buf[1] = {};
BPF_ASSERT(write(fds[1], "\x55", 1) == 1);
BPF_ASSERT(write(fds[3], "\xAA", 1) == 1);
BPF_ASSERT(read(fds[0], buf, 1) == 1);
BPF_ASSERT(buf[0] == '\x55');
errno = 0;
BPF_ASSERT(setuid(0) == -1);
BPF_ASSERT(errno == 1);
if (sandbox::IsAndroid() && setgid(0) != -1) {
errno = 0;
BPF_ASSERT(setgid(0) == -ErrorCode::ERR_MAX_ERRNO);
BPF_ASSERT(errno == 0);
} else {
errno = 0;
BPF_ASSERT(setgid(0) == -1);
BPF_ASSERT(errno == ErrorCode::ERR_MAX_ERRNO);
}
errno = 0;
struct utsname uts_buf;
BPF_ASSERT(uname(&uts_buf) == -1);
BPF_ASSERT(errno == 42);
}
class StackingPolicyPartOne : public Policy {
public:
StackingPolicyPartOne() = default;
StackingPolicyPartOne(const StackingPolicyPartOne&) = delete;
StackingPolicyPartOne& operator=(const StackingPolicyPartOne&) = delete;
~StackingPolicyPartOne() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
switch (sysno) {
case __NR_getppid: {
const Arg<int> arg(0);
return If(arg == 0, Allow()).Else(Error(EPERM));
}
default:
return Allow();
}
}
};
class StackingPolicyPartTwo : public Policy {
public:
StackingPolicyPartTwo() = default;
StackingPolicyPartTwo(const StackingPolicyPartTwo&) = delete;
StackingPolicyPartTwo& operator=(const StackingPolicyPartTwo&) = delete;
~StackingPolicyPartTwo() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
switch (sysno) {
case __NR_getppid: {
const Arg<int> arg(0);
return If(arg == 0, Error(EINVAL)).Else(Allow());
}
default:
return Allow();
}
}
};
BPF_DEATH_TEST_C(SandboxBPF,
StackingPolicy,
DEATH_SUCCESS_ALLOW_NOISE(),
StackingPolicyPartOne) {
errno = 0;
BPF_ASSERT(syscall(__NR_getppid, 0) > 0);
BPF_ASSERT(errno == 0);
BPF_ASSERT(syscall(__NR_getppid, 1) == -1);
BPF_ASSERT(errno == EPERM);
SandboxBPF sandbox(std::make_unique<StackingPolicyPartTwo>());
BPF_ASSERT(sandbox.StartSandbox(SandboxBPF::SeccompLevel::SINGLE_THREADED));
errno = 0;
BPF_ASSERT(syscall(__NR_getppid, 0) == -1);
BPF_ASSERT(errno == EINVAL);
BPF_ASSERT(syscall(__NR_getppid, 1) == -1);
BPF_ASSERT(errno == EPERM);
}
int SysnoToRandomErrno(int sysno) {
return ((sysno & ~3) >> 2) % 29 + 1;
}
class SyntheticPolicy : public Policy {
public:
SyntheticPolicy() = default;
SyntheticPolicy(const SyntheticPolicy&) = delete;
SyntheticPolicy& operator=(const SyntheticPolicy&) = delete;
~SyntheticPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (IsSyscallForTestHarness(sysno)) {
return Allow();
}
return Error(SysnoToRandomErrno(sysno));
}
};
BPF_TEST_C(SandboxBPF, SyntheticPolicy, SyntheticPolicy) {
BPF_ASSERT(std::numeric_limits<int>::max() - kExpectedReturnValue - 1 >=
static_cast<int>(MAX_PUBLIC_SYSCALL));
for (int syscall_number = static_cast<int>(MIN_SYSCALL);
syscall_number <= static_cast<int>(MAX_PUBLIC_SYSCALL);
++syscall_number) {
if (IsSyscallForTestHarness(syscall_number)) {
continue;
}
errno = 0;
BPF_ASSERT(syscall(syscall_number) == -1);
BPF_ASSERT(errno == SysnoToRandomErrno(syscall_number));
}
}
#if defined(__arm__)
int ArmPrivateSysnoToErrno(int sysno) {
if (sysno >= static_cast<int>(MIN_PRIVATE_SYSCALL) &&
sysno <= static_cast<int>(MAX_PRIVATE_SYSCALL)) {
return (sysno - MIN_PRIVATE_SYSCALL) + 1;
}
return ENOSYS;
}
class ArmPrivatePolicy : public Policy {
public:
ArmPrivatePolicy() = default;
ArmPrivatePolicy(const ArmPrivatePolicy&) = delete;
ArmPrivatePolicy& operator=(const ArmPrivatePolicy&) = delete;
~ArmPrivatePolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (sysno >= static_cast<int>(__ARM_NR_set_tls + 1) &&
sysno <= static_cast<int>(MAX_PRIVATE_SYSCALL)) {
return Error(ArmPrivateSysnoToErrno(sysno));
}
return Allow();
}
};
BPF_TEST_C(SandboxBPF, ArmPrivatePolicy, ArmPrivatePolicy) {
for (int syscall_number = static_cast<int>(__ARM_NR_set_tls + 1);
syscall_number <= static_cast<int>(MAX_PRIVATE_SYSCALL);
++syscall_number) {
errno = 0;
BPF_ASSERT(syscall(syscall_number) == -1);
BPF_ASSERT(errno == ArmPrivateSysnoToErrno(syscall_number));
}
}
#endif
intptr_t CountSyscalls(const struct arch_seccomp_data& args, void* aux) {
++*reinterpret_cast<int*>(aux);
BPF_ASSERT(sys_getpid() > 1);
return SandboxBPF::ForwardSyscall(args);
}
class GreyListedPolicy : public Policy {
public:
explicit GreyListedPolicy(int* aux) : aux_(aux) {
EnableUnsafeTraps();
}
GreyListedPolicy(const GreyListedPolicy&) = delete;
GreyListedPolicy& operator=(const GreyListedPolicy&) = delete;
~GreyListedPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (SandboxBPF::IsRequiredForUnsafeTrap(sysno)) {
return Allow();
}
if (sysno == __NR_getpid) {
return Error(EPERM);
}
return UnsafeTrap(CountSyscalls, aux_);
}
private:
const raw_ptr<int> aux_;
};
BPF_TEST(SandboxBPF, GreyListedPolicy, GreyListedPolicy, int ) {
BPF_ASSERT(sys_getpid() == -1);
BPF_ASSERT(errno == EPERM);
BPF_ASSERT(*BPF_AUX == 0);
BPF_ASSERT(syscall(__NR_geteuid) == syscall(__NR_getuid));
BPF_ASSERT(*BPF_AUX == 2);
char name[17] = {};
BPF_ASSERT(!syscall(__NR_prctl,
PR_GET_NAME,
name,
(void*)NULL,
(void*)NULL,
(void*)NULL));
BPF_ASSERT(*BPF_AUX == 3);
BPF_ASSERT(*name);
}
SANDBOX_TEST(SandboxBPF, EnableUnsafeTrapsInSigSysHandler) {
setenv(kSandboxDebuggingEnv, "t", 0);
Die::SuppressInfoMessages(true);
unsetenv(kSandboxDebuggingEnv);
SANDBOX_ASSERT(Trap::Registry()->EnableUnsafeTraps() == false);
setenv(kSandboxDebuggingEnv, "", 1);
SANDBOX_ASSERT(Trap::Registry()->EnableUnsafeTraps() == false);
setenv(kSandboxDebuggingEnv, "t", 1);
SANDBOX_ASSERT(Trap::Registry()->EnableUnsafeTraps() == true);
}
intptr_t PrctlHandler(const struct arch_seccomp_data& args, void*) {
if (args.args[0] == PR_CAPBSET_DROP && static_cast<int>(args.args[1]) == -1) {
return 0;
}
return SandboxBPF::ForwardSyscall(args);
}
class PrctlPolicy : public Policy {
public:
PrctlPolicy() = default;
PrctlPolicy(const PrctlPolicy&) = delete;
PrctlPolicy& operator=(const PrctlPolicy&) = delete;
~PrctlPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
setenv(kSandboxDebuggingEnv, "t", 0);
Die::SuppressInfoMessages(true);
if (sysno == __NR_prctl) {
return UnsafeTrap(PrctlHandler, nullptr);
}
return Allow();
}
};
BPF_TEST_C(SandboxBPF, ForwardSyscall, PrctlPolicy) {
BPF_ASSERT(
!prctl(PR_CAPBSET_DROP, -1, (void*)NULL, (void*)NULL, (void*)NULL));
BPF_ASSERT(
prctl(PR_CAPBSET_DROP, -2, (void*)NULL, (void*)NULL, (void*)NULL) == -1);
char name[17] = {};
BPF_ASSERT(!syscall(__NR_prctl,
PR_GET_NAME,
name,
(void*)NULL,
(void*)NULL,
(void*)NULL));
BPF_ASSERT(*name);
struct utsname uts = {};
BPF_ASSERT(!uname(&uts));
UNSAFE_TODO(BPF_ASSERT(!strcmp(uts.sysname, "Linux")));
}
intptr_t AllowRedirectedSyscall(const struct arch_seccomp_data& args, void*) {
return SandboxBPF::ForwardSyscall(args);
}
class RedirectAllSyscallsPolicy : public Policy {
public:
RedirectAllSyscallsPolicy() = default;
RedirectAllSyscallsPolicy(const RedirectAllSyscallsPolicy&) = delete;
RedirectAllSyscallsPolicy& operator=(const RedirectAllSyscallsPolicy&) =
delete;
~RedirectAllSyscallsPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override;
};
ResultExpr RedirectAllSyscallsPolicy::EvaluateSyscall(int sysno) const {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
setenv(kSandboxDebuggingEnv, "t", 0);
Die::SuppressInfoMessages(true);
if (SandboxBPF::IsRequiredForUnsafeTrap(sysno))
return Allow();
return UnsafeTrap(AllowRedirectedSyscall, nullptr);
}
#if !defined(ADDRESS_SANITIZER)
int bus_handler_fd_ = -1;
void SigBusHandler(int, siginfo_t* info, void* void_context) {
BPF_ASSERT(write(bus_handler_fd_, "\x55", 1) == 1);
}
BPF_TEST_C(SandboxBPF, SigBus, RedirectAllSyscallsPolicy) {
int fds[2];
BPF_ASSERT(socketpair(AF_UNIX, SOCK_STREAM, 0, fds) == 0);
bus_handler_fd_ = fds[1];
struct sigaction sa = {};
sa.sa_sigaction = SigBusHandler;
sa.sa_flags = SA_SIGINFO;
BPF_ASSERT(sigaction(SIGBUS, &sa, nullptr) == 0);
kill(getpid(), SIGBUS);
char c = '\000';
BPF_ASSERT(read(fds[0], &c, 1) == 1);
BPF_ASSERT(close(fds[0]) == 0);
BPF_ASSERT(close(fds[1]) == 0);
BPF_ASSERT(c == 0x55);
}
#endif
BPF_TEST_C(SandboxBPF, SigMask, RedirectAllSyscallsPolicy) {
sigset_t mask0, mask1, mask2;
sigemptyset(&mask0);
BPF_ASSERT(!sigprocmask(SIG_BLOCK, &mask0, &mask1));
BPF_ASSERT(!sigismember(&mask1, SIGUSR2));
sigaddset(&mask0, SIGUSR2);
BPF_ASSERT(!sigprocmask(SIG_BLOCK, &mask0, nullptr));
BPF_ASSERT(!sigprocmask(SIG_BLOCK, nullptr, &mask2));
BPF_ASSERT(sigismember(&mask2, SIGUSR2));
}
BPF_TEST_C(SandboxBPF, UnsafeTrapWithErrno, RedirectAllSyscallsPolicy) {
errno = 0;
BPF_ASSERT(close(-1) == -1);
BPF_ASSERT(errno == EBADF);
errno = 0;
struct arch_seccomp_data args = {};
args.nr = __NR_close;
args.args[0] = -1;
BPF_ASSERT(SandboxBPF::ForwardSyscall(args) == -EBADF);
BPF_ASSERT(errno == 0);
}
class SimpleCondTestPolicy : public Policy {
public:
SimpleCondTestPolicy() = default;
SimpleCondTestPolicy(const SimpleCondTestPolicy&) = delete;
SimpleCondTestPolicy& operator=(const SimpleCondTestPolicy&) = delete;
~SimpleCondTestPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override;
};
ResultExpr SimpleCondTestPolicy::EvaluateSyscall(int sysno) const {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
int flags_argument_position = -1;
switch (sysno) {
#if defined(__NR_open)
case __NR_open:
flags_argument_position = 1;
[[fallthrough]];
#endif
case __NR_openat: {
if (sysno == __NR_openat)
flags_argument_position = 2;
static_assert(O_RDONLY == 0, "O_RDONLY must be all zero bits");
const Arg<int> flags(flags_argument_position);
return If((flags & O_ACCMODE) != 0, Error(EROFS)).Else(Allow());
}
case __NR_prctl: {
const Arg<int> option(0);
return Switch(option)
.Cases({PR_SET_DUMPABLE, PR_GET_DUMPABLE}, Allow())
.Default(Error(ENOMEM));
}
default:
return Allow();
}
}
BPF_TEST_C(SandboxBPF, SimpleCondTest, SimpleCondTestPolicy) {
int fd;
BPF_ASSERT((fd = open("/proc/self/comm", O_RDWR)) == -1);
BPF_ASSERT(errno == EROFS);
BPF_ASSERT((fd = open("/proc/self/comm", O_RDONLY)) >= 0);
close(fd);
int ret;
BPF_ASSERT((ret = prctl(PR_GET_DUMPABLE)) >= 0);
BPF_ASSERT(prctl(PR_SET_DUMPABLE, 1 - ret) == 0);
BPF_ASSERT(prctl(PR_GET_ENDIAN, &ret) == -1);
BPF_ASSERT(errno == ENOMEM);
}
class EqualityStressTest {
public:
EqualityStressTest() {
srand(0);
static_assert(
kNumTestCases < (int)(MAX_PUBLIC_SYSCALL - MIN_SYSCALL - 10),
"kNumTestCases must be significantly smaller than the number "
"of system calls");
for (int sysno = MIN_SYSCALL, end = kNumTestCases; sysno < end; ++sysno) {
if (IsReservedSyscall(sysno)) {
++end;
arg_values_.push_back(nullptr);
} else {
arg_values_.push_back(
RandomArgValue(rand() % kMaxArgs, 0, rand() % kMaxArgs));
}
}
}
~EqualityStressTest() = default;
ResultExpr Policy(int sysno) {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (sysno < 0 || sysno >= (int)arg_values_.size() ||
IsReservedSyscall(sysno)) {
return Allow();
}
return ToErrorCode(arg_values_[sysno].get());
}
void VerifyFilter() {
for (int sysno = 0; sysno < (int)arg_values_.size(); ++sysno) {
if (!arg_values_[sysno]) {
continue;
}
intptr_t args[6] = {};
Verify(sysno, args, *arg_values_[sysno]);
}
}
private:
struct Tests;
struct ArgValue {
int argno;
int err;
std::vector<Tests> tests;
std::unique_ptr<ArgValue> next;
};
struct Tests {
uint32_t k_value;
int err;
std::unique_ptr<ArgValue> arg_value;
};
bool IsReservedSyscall(int sysno) {
return sysno == __NR_read || sysno == __NR_write || sysno == __NR_exit ||
sysno == __NR_exit_group || sysno == __NR_restart_syscall;
}
std::unique_ptr<ArgValue> RandomArgValue(int argno,
int args_mask,
int remaining_args) {
auto arg_value = std::make_unique<ArgValue>();
args_mask |= 1 << argno;
arg_value->argno = argno;
int fan_out = kMaxFanOut;
if (remaining_args > 3) {
fan_out = 1;
} else if (remaining_args > 2) {
fan_out = 2;
}
arg_value->tests.resize(rand() % fan_out + 1);
uint32_t k_value = rand();
for (auto& test : arg_value->tests) {
k_value += rand() % (RAND_MAX / (kMaxFanOut + 1)) + 1;
test.k_value = k_value;
if (!remaining_args || (rand() & 1)) {
test.err = 1 + (rand() % 1000);
test.arg_value = nullptr;
} else {
test.err = 0;
test.arg_value =
RandomArgValue(RandomArg(args_mask), args_mask, remaining_args - 1);
}
}
if (!remaining_args || (rand() & 1)) {
arg_value->err = (rand() % 1000) + 1;
arg_value->next = nullptr;
} else {
arg_value->err = 0;
arg_value->next =
RandomArgValue(RandomArg(args_mask), args_mask, remaining_args - 1);
}
return arg_value;
}
int RandomArg(int args_mask) {
int argno = rand() % kMaxArgs;
while (args_mask & (1 << argno)) {
argno = (argno + 1) % kMaxArgs;
}
return argno;
}
ResultExpr ToErrorCode(ArgValue* arg_value) {
ResultExpr err = arg_value->err ? Error(arg_value->err)
: ToErrorCode(arg_value->next.get());
for (auto& test : base::Reversed(arg_value->tests)) {
ResultExpr matched =
test.err ? Error(test.err) : ToErrorCode(test.arg_value.get());
const Arg<uint32_t> arg(arg_value->argno);
err = If(arg == test.k_value, matched).Else(err);
}
return err;
}
void Verify(int sysno, base::span<intptr_t> args, const ArgValue& arg_value) {
uint32_t mismatched = 0;
for (auto& test : base::Reversed(arg_value.tests)) {
mismatched += test.k_value;
args[arg_value.argno] = test.k_value;
if (test.err) {
VerifyErrno(sysno, args, test.err);
} else {
Verify(sysno, args, *test.arg_value);
}
}
while (base::Contains(arg_value.tests, mismatched, &Tests::k_value)) {
++mismatched;
}
args[arg_value.argno] = mismatched;
if (arg_value.err) {
VerifyErrno(sysno, args, arg_value.err);
} else {
Verify(sysno, args, *arg_value.next);
}
args[arg_value.argno] = 0;
}
void VerifyErrno(int sysno, base::span<intptr_t> args, int err) {
BPF_ASSERT(
Syscall::Call(
sysno, args[0], args[1], args[2], args[3], args[4], args[5]) ==
-err);
}
std::vector<std::unique_ptr<ArgValue>> arg_values_;
#if defined(__aarch64__)
static const int kNumTestCases = 30;
#else
static const int kNumTestCases = 40;
#endif
static const int kMaxFanOut = 3;
static const int kMaxArgs = 6;
};
class EqualityStressTestPolicy : public Policy {
public:
explicit EqualityStressTestPolicy(EqualityStressTest* aux) : aux_(aux) {}
EqualityStressTestPolicy(const EqualityStressTestPolicy&) = delete;
EqualityStressTestPolicy& operator=(const EqualityStressTestPolicy&) = delete;
~EqualityStressTestPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
return aux_->Policy(sysno);
}
private:
const raw_ptr<EqualityStressTest> aux_;
};
BPF_TEST(SandboxBPF,
EqualityTests,
EqualityStressTestPolicy,
EqualityStressTest ) {
BPF_AUX->VerifyFilter();
}
class EqualityArgumentWidthPolicy : public Policy {
public:
EqualityArgumentWidthPolicy() = default;
EqualityArgumentWidthPolicy(const EqualityArgumentWidthPolicy&) = delete;
EqualityArgumentWidthPolicy& operator=(const EqualityArgumentWidthPolicy&) =
delete;
~EqualityArgumentWidthPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override;
};
ResultExpr EqualityArgumentWidthPolicy::EvaluateSyscall(int sysno) const {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (sysno == __NR_uname) {
const Arg<int> option(0);
const Arg<uint32_t> arg32(1);
const Arg<uint64_t> arg64(1);
return Switch(option)
.Case(0, If(arg32 == 0x55555555, Error(1)).Else(Error(2)))
#if __SIZEOF_POINTER__ > 4
.Case(1, If(arg64 == 0x55555555AAAAAAAAULL, Error(1)).Else(Error(2)))
#endif
.Default(Error(3));
}
return Allow();
}
BPF_TEST_C(SandboxBPF, EqualityArgumentWidth, EqualityArgumentWidthPolicy) {
BPF_ASSERT(Syscall::Call(__NR_uname, 0, 0x55555555) == -1);
BPF_ASSERT(Syscall::Call(__NR_uname, 0, 0xAAAAAAAA) == -2);
#if __SIZEOF_POINTER__ > 4
BPF_ASSERT(Syscall::Call(__NR_uname, 1, 0x55555555AAAAAAAAULL) == -1);
BPF_ASSERT(Syscall::Call(__NR_uname, 1, 0x5555555500000000ULL) == -2);
BPF_ASSERT(Syscall::Call(__NR_uname, 1, 0x5555555511111111ULL) == -2);
BPF_ASSERT(Syscall::Call(__NR_uname, 1, 0x11111111AAAAAAAAULL) == -2);
#endif
}
#if __SIZEOF_POINTER__ > 4
BPF_DEATH_TEST_C(SandboxBPF,
EqualityArgumentUnallowed64bit,
DEATH_MESSAGE("Unexpected 64bit argument detected"),
EqualityArgumentWidthPolicy) {
Syscall::Call(__NR_uname, 0, 0x5555555555555555ULL);
}
#endif
class EqualityWithNegativeArgumentsPolicy : public Policy {
public:
EqualityWithNegativeArgumentsPolicy() = default;
EqualityWithNegativeArgumentsPolicy(
const EqualityWithNegativeArgumentsPolicy&) = delete;
EqualityWithNegativeArgumentsPolicy& operator=(
const EqualityWithNegativeArgumentsPolicy&) = delete;
~EqualityWithNegativeArgumentsPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (sysno == __NR_uname) {
const Arg<unsigned> arg(0);
return If(arg == 0xFFFFFFFF, Error(1)).Else(Error(2));
}
return Allow();
}
};
BPF_TEST_C(SandboxBPF,
EqualityWithNegativeArguments,
EqualityWithNegativeArgumentsPolicy) {
BPF_ASSERT(Syscall::Call(__NR_uname, 0xFFFFFFFF) == -1);
BPF_ASSERT(Syscall::Call(__NR_uname, -1) == -1);
BPF_ASSERT(Syscall::Call(__NR_uname, -1LL) == -1);
}
#if __SIZEOF_POINTER__ > 4
BPF_DEATH_TEST_C(SandboxBPF,
EqualityWithNegative64bitArguments,
DEATH_MESSAGE("Unexpected 64bit argument detected"),
EqualityWithNegativeArgumentsPolicy) {
BPF_ASSERT(Syscall::Call(__NR_uname, 0xFFFFFFFF00000000LL) == -1);
}
#endif
class AllBitTestPolicy : public Policy {
public:
AllBitTestPolicy() = default;
AllBitTestPolicy(const AllBitTestPolicy&) = delete;
AllBitTestPolicy& operator=(const AllBitTestPolicy&) = delete;
~AllBitTestPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override;
private:
static ResultExpr HasAllBits32(uint32_t bits);
static ResultExpr HasAllBits64(uint64_t bits);
};
ResultExpr AllBitTestPolicy::HasAllBits32(uint32_t bits) {
if (bits == 0) {
return Error(1);
}
const Arg<uint32_t> arg(1);
return If((arg & bits) == bits, Error(1)).Else(Error(0));
}
ResultExpr AllBitTestPolicy::HasAllBits64(uint64_t bits) {
if (bits == 0) {
return Error(1);
}
const Arg<uint64_t> arg(1);
return If((arg & bits) == bits, Error(1)).Else(Error(0));
}
ResultExpr AllBitTestPolicy::EvaluateSyscall(int sysno) const {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (sysno == __NR_uname) {
const Arg<int> option(0);
return Switch(option)
.Case(0, HasAllBits32(0x0))
.Case(1, HasAllBits32(0x1))
.Case(2, HasAllBits32(0x3))
.Case(3, HasAllBits32(0x80000000))
#if __SIZEOF_POINTER__ > 4
.Case(4, HasAllBits64(0x0))
.Case(5, HasAllBits64(0x1))
.Case(6, HasAllBits64(0x3))
.Case(7, HasAllBits64(0x80000000))
.Case(8, HasAllBits64(0x100000000ULL))
.Case(9, HasAllBits64(0x300000000ULL))
.Case(10, HasAllBits64(0x100000001ULL))
#endif
.Default(Kill());
}
return Allow();
}
#define BITMASK_TEST(testcase, arg, op, mask, expected_value) \
BPF_ASSERT(Syscall::Call(__NR_uname, (testcase), (arg)) == (expected_value))
#define EXPECT_FAILURE 0
#define EXPECT_SUCCESS -1
#define EXPT64_SUCCESS (sizeof(void*) > 4 ? EXPECT_SUCCESS : EXPECT_FAILURE)
BPF_TEST_C(SandboxBPF, AllBitTests, AllBitTestPolicy) {
BITMASK_TEST( 0, 0, ALLBITS32, 0, EXPECT_SUCCESS);
BITMASK_TEST( 0, 1, ALLBITS32, 0, EXPECT_SUCCESS);
BITMASK_TEST( 0, 3, ALLBITS32, 0, EXPECT_SUCCESS);
BITMASK_TEST( 0, 0xFFFFFFFFU, ALLBITS32, 0, EXPECT_SUCCESS);
BITMASK_TEST( 0, -1LL, ALLBITS32, 0, EXPECT_SUCCESS);
BITMASK_TEST( 1, 0, ALLBITS32, 0x1, EXPECT_FAILURE);
BITMASK_TEST( 1, 1, ALLBITS32, 0x1, EXPECT_SUCCESS);
BITMASK_TEST( 1, 2, ALLBITS32, 0x1, EXPECT_FAILURE);
BITMASK_TEST( 1, 3, ALLBITS32, 0x1, EXPECT_SUCCESS);
BITMASK_TEST( 2, 0, ALLBITS32, 0x3, EXPECT_FAILURE);
BITMASK_TEST( 2, 1, ALLBITS32, 0x3, EXPECT_FAILURE);
BITMASK_TEST( 2, 2, ALLBITS32, 0x3, EXPECT_FAILURE);
BITMASK_TEST( 2, 3, ALLBITS32, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 2, 7, ALLBITS32, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 3, 0, ALLBITS32, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 3, 0x40000000U, ALLBITS32, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 3, 0x80000000U, ALLBITS32, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 3, 0xC0000000U, ALLBITS32, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 3, -0x80000000LL, ALLBITS32, 0x80000000, EXPECT_SUCCESS);
#if __SIZEOF_POINTER__ > 4
BITMASK_TEST( 4, 0, ALLBITS64, 0, EXPECT_SUCCESS);
BITMASK_TEST( 4, 1, ALLBITS64, 0, EXPECT_SUCCESS);
BITMASK_TEST( 4, 3, ALLBITS64, 0, EXPECT_SUCCESS);
BITMASK_TEST( 4, 0xFFFFFFFFU, ALLBITS64, 0, EXPECT_SUCCESS);
BITMASK_TEST( 4, 0x100000000LL, ALLBITS64, 0, EXPECT_SUCCESS);
BITMASK_TEST( 4, 0x300000000LL, ALLBITS64, 0, EXPECT_SUCCESS);
BITMASK_TEST( 4,0x8000000000000000LL, ALLBITS64, 0, EXPECT_SUCCESS);
BITMASK_TEST( 4, -1LL, ALLBITS64, 0, EXPECT_SUCCESS);
BITMASK_TEST( 5, 0, ALLBITS64, 1, EXPECT_FAILURE);
BITMASK_TEST( 5, 1, ALLBITS64, 1, EXPECT_SUCCESS);
BITMASK_TEST( 5, 2, ALLBITS64, 1, EXPECT_FAILURE);
BITMASK_TEST( 5, 3, ALLBITS64, 1, EXPECT_SUCCESS);
BITMASK_TEST( 5, 0x100000000LL, ALLBITS64, 1, EXPECT_FAILURE);
BITMASK_TEST( 5, 0x100000001LL, ALLBITS64, 1, EXPECT_SUCCESS);
BITMASK_TEST( 5, 0x100000002LL, ALLBITS64, 1, EXPECT_FAILURE);
BITMASK_TEST( 5, 0x100000003LL, ALLBITS64, 1, EXPECT_SUCCESS);
BITMASK_TEST( 6, 0, ALLBITS64, 3, EXPECT_FAILURE);
BITMASK_TEST( 6, 1, ALLBITS64, 3, EXPECT_FAILURE);
BITMASK_TEST( 6, 2, ALLBITS64, 3, EXPECT_FAILURE);
BITMASK_TEST( 6, 3, ALLBITS64, 3, EXPECT_SUCCESS);
BITMASK_TEST( 6, 7, ALLBITS64, 3, EXPECT_SUCCESS);
BITMASK_TEST( 6, 0x100000000LL, ALLBITS64, 3, EXPECT_FAILURE);
BITMASK_TEST( 6, 0x100000001LL, ALLBITS64, 3, EXPECT_FAILURE);
BITMASK_TEST( 6, 0x100000002LL, ALLBITS64, 3, EXPECT_FAILURE);
BITMASK_TEST( 6, 0x100000003LL, ALLBITS64, 3, EXPECT_SUCCESS);
BITMASK_TEST( 6, 0x100000007LL, ALLBITS64, 3, EXPECT_SUCCESS);
BITMASK_TEST( 7, 0, ALLBITS64, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 7, 0x40000000U, ALLBITS64, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 7, 0x80000000U, ALLBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 7, 0xC0000000U, ALLBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 7, -0x80000000LL, ALLBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 7, 0x100000000LL, ALLBITS64, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 7, 0x140000000LL, ALLBITS64, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 7, 0x180000000LL, ALLBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 7, 0x1C0000000LL, ALLBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 7, -0x180000000LL, ALLBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 8, 0x000000000LL, ALLBITS64,0x100000000, EXPECT_FAILURE);
BITMASK_TEST( 8, 0x100000000LL, ALLBITS64,0x100000000, EXPT64_SUCCESS);
BITMASK_TEST( 8, 0x200000000LL, ALLBITS64,0x100000000, EXPECT_FAILURE);
BITMASK_TEST( 8, 0x300000000LL, ALLBITS64,0x100000000, EXPT64_SUCCESS);
BITMASK_TEST( 8, 0x000000001LL, ALLBITS64,0x100000000, EXPECT_FAILURE);
BITMASK_TEST( 8, 0x100000001LL, ALLBITS64,0x100000000, EXPT64_SUCCESS);
BITMASK_TEST( 8, 0x200000001LL, ALLBITS64,0x100000000, EXPECT_FAILURE);
BITMASK_TEST( 8, 0x300000001LL, ALLBITS64,0x100000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x000000000LL, ALLBITS64,0x300000000, EXPECT_FAILURE);
BITMASK_TEST( 9, 0x100000000LL, ALLBITS64,0x300000000, EXPECT_FAILURE);
BITMASK_TEST( 9, 0x200000000LL, ALLBITS64,0x300000000, EXPECT_FAILURE);
BITMASK_TEST( 9, 0x300000000LL, ALLBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x700000000LL, ALLBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x000000001LL, ALLBITS64,0x300000000, EXPECT_FAILURE);
BITMASK_TEST( 9, 0x100000001LL, ALLBITS64,0x300000000, EXPECT_FAILURE);
BITMASK_TEST( 9, 0x200000001LL, ALLBITS64,0x300000000, EXPECT_FAILURE);
BITMASK_TEST( 9, 0x300000001LL, ALLBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x700000001LL, ALLBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST(10, 0x000000000LL, ALLBITS64,0x100000001, EXPECT_FAILURE);
BITMASK_TEST(10, 0x000000001LL, ALLBITS64,0x100000001, EXPECT_FAILURE);
BITMASK_TEST(10, 0x100000000LL, ALLBITS64,0x100000001, EXPECT_FAILURE);
BITMASK_TEST(10, 0x100000001LL, ALLBITS64,0x100000001, EXPT64_SUCCESS);
BITMASK_TEST(10, 0xFFFFFFFFU, ALLBITS64,0x100000001, EXPECT_FAILURE);
BITMASK_TEST(10, -1L, ALLBITS64,0x100000001, EXPT64_SUCCESS);
#endif
}
class AnyBitTestPolicy : public Policy {
public:
AnyBitTestPolicy() = default;
AnyBitTestPolicy(const AnyBitTestPolicy&) = delete;
AnyBitTestPolicy& operator=(const AnyBitTestPolicy&) = delete;
~AnyBitTestPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override;
private:
static ResultExpr HasAnyBits32(uint32_t);
static ResultExpr HasAnyBits64(uint64_t);
};
ResultExpr AnyBitTestPolicy::HasAnyBits32(uint32_t bits) {
if (bits == 0) {
return Error(0);
}
const Arg<uint32_t> arg(1);
return If((arg & bits) != 0, Error(1)).Else(Error(0));
}
ResultExpr AnyBitTestPolicy::HasAnyBits64(uint64_t bits) {
if (bits == 0) {
return Error(0);
}
const Arg<uint64_t> arg(1);
return If((arg & bits) != 0, Error(1)).Else(Error(0));
}
ResultExpr AnyBitTestPolicy::EvaluateSyscall(int sysno) const {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (sysno == __NR_uname) {
const Arg<int> option(0);
return Switch(option)
.Case(0, HasAnyBits32(0x0))
.Case(1, HasAnyBits32(0x1))
.Case(2, HasAnyBits32(0x3))
.Case(3, HasAnyBits32(0x80000000))
#if __SIZEOF_POINTER__ > 4
.Case(4, HasAnyBits64(0x0))
.Case(5, HasAnyBits64(0x1))
.Case(6, HasAnyBits64(0x3))
.Case(7, HasAnyBits64(0x80000000))
.Case(8, HasAnyBits64(0x100000000ULL))
.Case(9, HasAnyBits64(0x300000000ULL))
.Case(10, HasAnyBits64(0x100000001ULL))
#endif
.Default(Kill());
}
return Allow();
}
BPF_TEST_C(SandboxBPF, AnyBitTests, AnyBitTestPolicy) {
BITMASK_TEST( 0, 0, ANYBITS32, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 0, 1, ANYBITS32, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 0, 3, ANYBITS32, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 0, 0xFFFFFFFFU, ANYBITS32, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 0, -1LL, ANYBITS32, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 1, 0, ANYBITS32, 0x1, EXPECT_FAILURE);
BITMASK_TEST( 1, 1, ANYBITS32, 0x1, EXPECT_SUCCESS);
BITMASK_TEST( 1, 2, ANYBITS32, 0x1, EXPECT_FAILURE);
BITMASK_TEST( 1, 3, ANYBITS32, 0x1, EXPECT_SUCCESS);
BITMASK_TEST( 2, 0, ANYBITS32, 0x3, EXPECT_FAILURE);
BITMASK_TEST( 2, 1, ANYBITS32, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 2, 2, ANYBITS32, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 2, 3, ANYBITS32, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 2, 7, ANYBITS32, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 3, 0, ANYBITS32, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 3, 0x40000000U, ANYBITS32, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 3, 0x80000000U, ANYBITS32, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 3, 0xC0000000U, ANYBITS32, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 3, -0x80000000LL, ANYBITS32, 0x80000000, EXPECT_SUCCESS);
#if __SIZEOF_POINTER__ > 4
BITMASK_TEST( 4, 0, ANYBITS64, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 4, 1, ANYBITS64, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 4, 3, ANYBITS64, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 4, 0xFFFFFFFFU, ANYBITS64, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 4, 0x100000000LL, ANYBITS64, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 4, 0x300000000LL, ANYBITS64, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 4,0x8000000000000000LL, ANYBITS64, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 4, -1LL, ANYBITS64, 0x0, EXPECT_FAILURE);
BITMASK_TEST( 5, 0, ANYBITS64, 0x1, EXPECT_FAILURE);
BITMASK_TEST( 5, 1, ANYBITS64, 0x1, EXPECT_SUCCESS);
BITMASK_TEST( 5, 2, ANYBITS64, 0x1, EXPECT_FAILURE);
BITMASK_TEST( 5, 3, ANYBITS64, 0x1, EXPECT_SUCCESS);
BITMASK_TEST( 5, 0x100000001LL, ANYBITS64, 0x1, EXPECT_SUCCESS);
BITMASK_TEST( 5, 0x100000000LL, ANYBITS64, 0x1, EXPECT_FAILURE);
BITMASK_TEST( 5, 0x100000002LL, ANYBITS64, 0x1, EXPECT_FAILURE);
BITMASK_TEST( 5, 0x100000003LL, ANYBITS64, 0x1, EXPECT_SUCCESS);
BITMASK_TEST( 6, 0, ANYBITS64, 0x3, EXPECT_FAILURE);
BITMASK_TEST( 6, 1, ANYBITS64, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 6, 2, ANYBITS64, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 6, 3, ANYBITS64, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 6, 7, ANYBITS64, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 6, 0x100000000LL, ANYBITS64, 0x3, EXPECT_FAILURE);
BITMASK_TEST( 6, 0x100000001LL, ANYBITS64, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 6, 0x100000002LL, ANYBITS64, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 6, 0x100000003LL, ANYBITS64, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 6, 0x100000007LL, ANYBITS64, 0x3, EXPECT_SUCCESS);
BITMASK_TEST( 7, 0, ANYBITS64, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 7, 0x40000000U, ANYBITS64, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 7, 0x80000000U, ANYBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 7, 0xC0000000U, ANYBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 7, -0x80000000LL, ANYBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 7, 0x100000000LL, ANYBITS64, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 7, 0x140000000LL, ANYBITS64, 0x80000000, EXPECT_FAILURE);
BITMASK_TEST( 7, 0x180000000LL, ANYBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 7, 0x1C0000000LL, ANYBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 7, -0x180000000LL, ANYBITS64, 0x80000000, EXPECT_SUCCESS);
BITMASK_TEST( 8, 0x000000000LL, ANYBITS64,0x100000000, EXPECT_FAILURE);
BITMASK_TEST( 8, 0x100000000LL, ANYBITS64,0x100000000, EXPT64_SUCCESS);
BITMASK_TEST( 8, 0x200000000LL, ANYBITS64,0x100000000, EXPECT_FAILURE);
BITMASK_TEST( 8, 0x300000000LL, ANYBITS64,0x100000000, EXPT64_SUCCESS);
BITMASK_TEST( 8, 0x000000001LL, ANYBITS64,0x100000000, EXPECT_FAILURE);
BITMASK_TEST( 8, 0x100000001LL, ANYBITS64,0x100000000, EXPT64_SUCCESS);
BITMASK_TEST( 8, 0x200000001LL, ANYBITS64,0x100000000, EXPECT_FAILURE);
BITMASK_TEST( 8, 0x300000001LL, ANYBITS64,0x100000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x000000000LL, ANYBITS64,0x300000000, EXPECT_FAILURE);
BITMASK_TEST( 9, 0x100000000LL, ANYBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x200000000LL, ANYBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x300000000LL, ANYBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x700000000LL, ANYBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x000000001LL, ANYBITS64,0x300000000, EXPECT_FAILURE);
BITMASK_TEST( 9, 0x100000001LL, ANYBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x200000001LL, ANYBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x300000001LL, ANYBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 9, 0x700000001LL, ANYBITS64,0x300000000, EXPT64_SUCCESS);
BITMASK_TEST( 10, 0x000000000LL, ANYBITS64,0x100000001, EXPECT_FAILURE);
BITMASK_TEST( 10, 0x000000001LL, ANYBITS64,0x100000001, EXPECT_SUCCESS);
BITMASK_TEST( 10, 0x100000000LL, ANYBITS64,0x100000001, EXPT64_SUCCESS);
BITMASK_TEST( 10, 0x100000001LL, ANYBITS64,0x100000001, EXPECT_SUCCESS);
BITMASK_TEST( 10, 0xFFFFFFFFU, ANYBITS64,0x100000001, EXPECT_SUCCESS);
BITMASK_TEST( 10, -1L, ANYBITS64,0x100000001, EXPECT_SUCCESS);
#endif
}
class MaskedEqualTestPolicy : public Policy {
public:
MaskedEqualTestPolicy() = default;
MaskedEqualTestPolicy(const MaskedEqualTestPolicy&) = delete;
MaskedEqualTestPolicy& operator=(const MaskedEqualTestPolicy&) = delete;
~MaskedEqualTestPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override;
private:
static ResultExpr MaskedEqual32(uint32_t mask, uint32_t value);
static ResultExpr MaskedEqual64(uint64_t mask, uint64_t value);
};
ResultExpr MaskedEqualTestPolicy::MaskedEqual32(uint32_t mask, uint32_t value) {
const Arg<uint32_t> arg(1);
return If((arg & mask) == value, Error(1)).Else(Error(0));
}
ResultExpr MaskedEqualTestPolicy::MaskedEqual64(uint64_t mask, uint64_t value) {
const Arg<uint64_t> arg(1);
return If((arg & mask) == value, Error(1)).Else(Error(0));
}
ResultExpr MaskedEqualTestPolicy::EvaluateSyscall(int sysno) const {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (sysno == __NR_uname) {
const Arg<int> option(0);
return Switch(option)
.Case(0, MaskedEqual32(0x00ff00ff, 0x005500aa))
#if __SIZEOF_POINTER__ > 4
.Case(1, MaskedEqual64(0x00ff00ff00000000, 0x005500aa00000000))
.Case(2, MaskedEqual64(0x00ff00ff00ff00ff, 0x005500aa005500aa))
#endif
.Default(Kill());
}
return Allow();
}
#define MASKEQ_TEST(rulenum, arg, expected_result) \
BPF_ASSERT(Syscall::Call(__NR_uname, (rulenum), (arg)) == (expected_result))
BPF_TEST_C(SandboxBPF, MaskedEqualTests, MaskedEqualTestPolicy) {
MASKEQ_TEST(0, 0x00000000, EXPECT_FAILURE);
MASKEQ_TEST(0, 0x00000001, EXPECT_FAILURE);
MASKEQ_TEST(0, 0x00000003, EXPECT_FAILURE);
MASKEQ_TEST(0, 0x00000100, EXPECT_FAILURE);
MASKEQ_TEST(0, 0x00000300, EXPECT_FAILURE);
MASKEQ_TEST(0, 0x005500aa, EXPECT_SUCCESS);
MASKEQ_TEST(0, 0x005500ab, EXPECT_FAILURE);
MASKEQ_TEST(0, 0x005600aa, EXPECT_FAILURE);
MASKEQ_TEST(0, 0x005501aa, EXPECT_SUCCESS);
MASKEQ_TEST(0, 0x005503aa, EXPECT_SUCCESS);
MASKEQ_TEST(0, 0x555500aa, EXPECT_SUCCESS);
MASKEQ_TEST(0, 0xaa5500aa, EXPECT_SUCCESS);
#if __SIZEOF_POINTER__ > 4
MASKEQ_TEST(1, 0x0000000000000000, EXPECT_FAILURE);
MASKEQ_TEST(1, 0x0000000000000010, EXPECT_FAILURE);
MASKEQ_TEST(1, 0x0000000000000050, EXPECT_FAILURE);
MASKEQ_TEST(1, 0x0000000100000000, EXPECT_FAILURE);
MASKEQ_TEST(1, 0x0000000300000000, EXPECT_FAILURE);
MASKEQ_TEST(1, 0x0000010000000000, EXPECT_FAILURE);
MASKEQ_TEST(1, 0x0000030000000000, EXPECT_FAILURE);
MASKEQ_TEST(1, 0x005500aa00000000, EXPECT_SUCCESS);
MASKEQ_TEST(1, 0x005500ab00000000, EXPECT_FAILURE);
MASKEQ_TEST(1, 0x005600aa00000000, EXPECT_FAILURE);
MASKEQ_TEST(1, 0x005501aa00000000, EXPECT_SUCCESS);
MASKEQ_TEST(1, 0x005503aa00000000, EXPECT_SUCCESS);
MASKEQ_TEST(1, 0x555500aa00000000, EXPECT_SUCCESS);
MASKEQ_TEST(1, 0xaa5500aa00000000, EXPECT_SUCCESS);
MASKEQ_TEST(1, 0xaa5500aa00000000, EXPECT_SUCCESS);
MASKEQ_TEST(1, 0xaa5500aa0000cafe, EXPECT_SUCCESS);
MASKEQ_TEST(2, 0x0000000000000000, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x0000000000000010, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x0000000000000050, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x0000000100000000, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x0000000300000000, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x0000010000000000, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x0000030000000000, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x00000000005500aa, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x005500aa00000000, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x005500aa005500aa, EXPECT_SUCCESS);
MASKEQ_TEST(2, 0x005500aa005700aa, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x005700aa005500aa, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x005500aa004500aa, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x004500aa005500aa, EXPECT_FAILURE);
MASKEQ_TEST(2, 0x005512aa005500aa, EXPECT_SUCCESS);
MASKEQ_TEST(2, 0x005500aa005534aa, EXPECT_SUCCESS);
MASKEQ_TEST(2, 0xff5500aa0055ffaa, EXPECT_SUCCESS);
#endif
}
intptr_t PthreadTrapHandler(const struct arch_seccomp_data& args, void* aux) {
if (args.args[0] != (CLONE_CHILD_CLEARTID | CLONE_CHILD_SETTID | SIGCHLD)) {
const char* msg = (const char*)aux;
UNSAFE_TODO(
printf("Clone() was called with unexpected arguments\n"
" nr: %d\n"
" 1: 0x%llX\n"
" 2: 0x%llX\n"
" 3: 0x%llX\n"
" 4: 0x%llX\n"
" 5: 0x%llX\n"
" 6: 0x%llX\n"
"%s\n",
args.nr, (long long)args.args[0], (long long)args.args[1],
(long long)args.args[2], (long long)args.args[3],
(long long)args.args[4], (long long)args.args[5], msg));
}
return -EPERM;
}
class PthreadPolicyEquality : public Policy {
public:
PthreadPolicyEquality() = default;
PthreadPolicyEquality(const PthreadPolicyEquality&) = delete;
PthreadPolicyEquality& operator=(const PthreadPolicyEquality&) = delete;
~PthreadPolicyEquality() override = default;
ResultExpr EvaluateSyscall(int sysno) const override;
};
ResultExpr PthreadPolicyEquality::EvaluateSyscall(int sysno) const {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (sysno == __NR_clone) {
const uint64_t kGlibcCloneMask = CLONE_VM | CLONE_FS | CLONE_FILES |
CLONE_SIGHAND | CLONE_THREAD |
CLONE_SYSVSEM | CLONE_SETTLS |
CLONE_PARENT_SETTID | CLONE_CHILD_CLEARTID;
const uint64_t kBaseAndroidCloneMask = CLONE_VM | CLONE_FS | CLONE_FILES |
CLONE_SIGHAND | CLONE_THREAD |
CLONE_SYSVSEM;
const Arg<unsigned long> flags(0);
return Switch(flags)
.Cases({kGlibcCloneMask, (kBaseAndroidCloneMask | CLONE_DETACHED),
kBaseAndroidCloneMask},
Allow())
.Default(Trap(PthreadTrapHandler, "Unknown mask"));
}
return Allow();
}
class PthreadPolicyBitMask : public Policy {
public:
PthreadPolicyBitMask() = default;
PthreadPolicyBitMask(const PthreadPolicyBitMask&) = delete;
PthreadPolicyBitMask& operator=(const PthreadPolicyBitMask&) = delete;
~PthreadPolicyBitMask() override = default;
ResultExpr EvaluateSyscall(int sysno) const override;
private:
static BoolExpr HasAnyBits(const Arg<unsigned long>& arg, unsigned long bits);
static BoolExpr HasAllBits(const Arg<unsigned long>& arg, unsigned long bits);
};
BoolExpr PthreadPolicyBitMask::HasAnyBits(const Arg<unsigned long>& arg,
unsigned long bits) {
return (arg & bits) != 0;
}
BoolExpr PthreadPolicyBitMask::HasAllBits(const Arg<unsigned long>& arg,
unsigned long bits) {
return (arg & bits) == bits;
}
ResultExpr PthreadPolicyBitMask::EvaluateSyscall(int sysno) const {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
if (sysno == __NR_clone) {
const unsigned long kMandatoryFlags = CLONE_VM | CLONE_FS | CLONE_FILES |
CLONE_SIGHAND | CLONE_THREAD |
CLONE_SYSVSEM;
const unsigned long kFutexFlags =
CLONE_SETTLS | CLONE_PARENT_SETTID | CLONE_CHILD_CLEARTID;
const unsigned long kNoopFlags = CLONE_DETACHED;
const unsigned long kKnownFlags =
kMandatoryFlags | kFutexFlags | kNoopFlags;
const Arg<unsigned long> flags(0);
return If(HasAnyBits(flags, ~kKnownFlags),
Trap(PthreadTrapHandler, "Unexpected CLONE_XXX flag found"))
.ElseIf(Not(HasAllBits(flags, kMandatoryFlags)),
Trap(PthreadTrapHandler,
"Missing mandatory CLONE_XXX flags "
"when creating new thread"))
.ElseIf(AllOf(Not(HasAllBits(flags, kFutexFlags)),
HasAnyBits(flags, kFutexFlags)),
Trap(PthreadTrapHandler,
"Must set either all or none of the TLS and futex bits in "
"call to clone()"))
.Else(Allow());
}
return Allow();
}
static void* ThreadFnc(void* arg) {
++*reinterpret_cast<int*>(arg);
Syscall::Call(__NR_futex, arg, FUTEX_WAKE, 1, 0, 0, 0);
return nullptr;
}
static void PthreadTest() {
pthread_t thread;
int thread_ran = 0;
BPF_ASSERT(!pthread_create(&thread, nullptr, ThreadFnc, &thread_ran));
BPF_ASSERT(!pthread_join(thread, nullptr));
BPF_ASSERT(thread_ran);
thread_ran = 0;
pthread_attr_t attr;
BPF_ASSERT(!pthread_attr_init(&attr));
BPF_ASSERT(!pthread_attr_setdetachstate(&attr, PTHREAD_CREATE_DETACHED));
BPF_ASSERT(!pthread_create(&thread, &attr, ThreadFnc, &thread_ran));
BPF_ASSERT(!pthread_attr_destroy(&attr));
while (Syscall::Call(__NR_futex, &thread_ran, FUTEX_WAIT, 0, 0, 0, 0) ==
-EINTR) {
}
BPF_ASSERT(thread_ran);
int pid;
BPF_ASSERT(Syscall::Call(__NR_clone,
CLONE_CHILD_CLEARTID | CLONE_CHILD_SETTID | SIGCHLD,
0,
0,
&pid) == -EPERM);
}
BPF_TEST_C(SandboxBPF, PthreadEquality, PthreadPolicyEquality) {
PthreadTest();
}
BPF_TEST_C(SandboxBPF, PthreadBitMask, PthreadPolicyBitMask) {
PthreadTest();
}
#ifndef PTRACE_O_TRACESECCOMP
#define PTRACE_O_TRACESECCOMP 0x00000080
#endif
#ifdef PTRACE_EVENT_SECCOMP
#define IS_SECCOMP_EVENT(status) ((status >> 16) == PTRACE_EVENT_SECCOMP)
#else
#define IS_SECCOMP_EVENT(status) ((status >> 16) == 7 || (status >> 16) == 8)
#endif
#if defined(__arm__)
#ifndef PTRACE_SET_SYSCALL
#define PTRACE_SET_SYSCALL 23
#endif
#endif
#if defined(__aarch64__)
#ifndef PTRACE_GETREGS
#if defined(__GLIBC__)
#define PTRACE_GETREGS static_cast<enum __ptrace_request>(12)
#else
#define PTRACE_GETREGS 12
#endif
#endif
#endif
#if defined(__aarch64__)
#ifndef PTRACE_SETREGS
#if defined(__GLIBC__)
#define PTRACE_SETREGS static_cast<enum __ptrace_request>(13)
#else
#define PTRACE_SETREGS 13
#endif
#endif
#endif
#if !defined(__arm__) && !defined(__aarch64__) && !defined(__mips__)
long SetSyscall(pid_t pid, regs_struct* regs, int syscall_number) {
#if defined(__arm__)
return syscall(__NR_ptrace, PTRACE_SET_SYSCALL, pid, NULL, syscall_number);
#else
SECCOMP_PT_SYSCALL(*regs) = syscall_number;
return 0;
#endif
}
#endif
const uint16_t kTraceData = 0xcc;
class TraceAllPolicy : public Policy {
public:
TraceAllPolicy() = default;
TraceAllPolicy(const TraceAllPolicy&) = delete;
TraceAllPolicy& operator=(const TraceAllPolicy&) = delete;
~TraceAllPolicy() override = default;
ResultExpr EvaluateSyscall(int system_call_number) const override {
return Trace(kTraceData);
}
};
SANDBOX_TEST(SandboxBPF, DISABLE_ON_TSAN(SeccompRetTrace)) {
if (!SandboxBPF::SupportsSeccompSandbox(
SandboxBPF::SeccompLevel::SINGLE_THREADED)) {
return;
}
#if defined(__arm__) || defined(__aarch64__)
printf("This test is currently disabled on ARM32/64 due to a kernel bug.");
#elif defined(__mips__)
printf("This test is currently disabled on MIPS.");
#else
pid_t pid = fork();
BPF_ASSERT_NE(-1, pid);
if (pid == 0) {
pid_t my_pid = getpid();
BPF_ASSERT_NE(-1, ptrace(PTRACE_TRACEME, -1, NULL, NULL));
BPF_ASSERT_EQ(0, raise(SIGSTOP));
SandboxBPF sandbox(std::make_unique<TraceAllPolicy>());
BPF_ASSERT(sandbox.StartSandbox(SandboxBPF::SeccompLevel::SINGLE_THREADED));
BPF_ASSERT_EQ(my_pid, sys_getpid());
BPF_ASSERT_EQ(kExpectedReturnValue,
syscall(__NR_write, STDOUT_FILENO, "A", 1));
syscall(__NR_kill, my_pid, SIGKILL);
BPF_ASSERT(false);
}
int status;
BPF_ASSERT(HANDLE_EINTR(waitpid(pid, &status, WUNTRACED)) != -1);
BPF_ASSERT(WIFSTOPPED(status));
BPF_ASSERT_NE(-1,
ptrace(PTRACE_SETOPTIONS,
pid,
NULL,
reinterpret_cast<void*>(PTRACE_O_TRACESECCOMP)));
BPF_ASSERT_NE(-1, ptrace(PTRACE_CONT, pid, NULL, NULL));
while (true) {
BPF_ASSERT(HANDLE_EINTR(waitpid(pid, &status, 0)) != -1);
if (WIFEXITED(status) || WIFSIGNALED(status)) {
BPF_ASSERT(WIFEXITED(status));
BPF_ASSERT_EQ(kExpectedReturnValue, WEXITSTATUS(status));
break;
}
if (!WIFSTOPPED(status) || WSTOPSIG(status) != SIGTRAP ||
!IS_SECCOMP_EVENT(status)) {
BPF_ASSERT_NE(-1, ptrace(PTRACE_CONT, pid, NULL, NULL));
continue;
}
unsigned long data;
BPF_ASSERT_NE(-1, ptrace(PTRACE_GETEVENTMSG, pid, NULL, &data));
BPF_ASSERT_EQ(kTraceData, data);
regs_struct regs;
BPF_ASSERT_NE(-1, ptrace(PTRACE_GETREGS, pid, NULL, ®s));
switch (SECCOMP_PT_SYSCALL(regs)) {
case __NR_write:
if (SECCOMP_PT_PARM1(regs) == STDOUT_FILENO) {
BPF_ASSERT_NE(-1, SetSyscall(pid, ®s, -1));
SECCOMP_PT_RESULT(regs) = kExpectedReturnValue;
BPF_ASSERT_NE(-1, ptrace(PTRACE_SETREGS, pid, NULL, ®s));
}
break;
case __NR_kill:
BPF_ASSERT_NE(-1, SetSyscall(pid, ®s, __NR_exit));
SECCOMP_PT_PARM1(regs) = kExpectedReturnValue;
BPF_ASSERT_NE(-1, ptrace(PTRACE_SETREGS, pid, NULL, ®s));
break;
default:
break;
}
BPF_ASSERT_NE(-1, ptrace(PTRACE_CONT, pid, NULL, NULL));
}
#endif
}
#if !BUILDFLAG(IS_ANDROID)
bool FullPwrite64(int fd, const char* buffer, size_t count, off64_t offset) {
while (count > 0) {
const ssize_t transfered =
HANDLE_EINTR(pwrite64(fd, buffer, count, offset));
if (transfered <= 0 || static_cast<size_t>(transfered) > count) {
return false;
}
count -= transfered;
UNSAFE_TODO(buffer += transfered);
offset += transfered;
}
return true;
}
bool FullPread64(int fd, char* buffer, size_t count, off64_t offset) {
while (count > 0) {
const ssize_t transfered = HANDLE_EINTR(pread64(fd, buffer, count, offset));
if (transfered <= 0 || static_cast<size_t>(transfered) > count) {
return false;
}
count -= transfered;
UNSAFE_TODO(buffer += transfered);
offset += transfered;
}
return true;
}
bool pread_64_was_forwarded = false;
class TrapPread64Policy : public Policy {
public:
TrapPread64Policy() = default;
TrapPread64Policy(const TrapPread64Policy&) = delete;
TrapPread64Policy& operator=(const TrapPread64Policy&) = delete;
~TrapPread64Policy() override = default;
ResultExpr EvaluateSyscall(int system_call_number) const override {
if (system_call_number == MIN_SYSCALL) {
EnableUnsafeTraps();
}
if (system_call_number == __NR_pread64) {
return UnsafeTrap(ForwardPreadHandler, nullptr);
}
return Allow();
}
private:
static intptr_t ForwardPreadHandler(const struct arch_seccomp_data& args,
void* aux) {
BPF_ASSERT(args.nr == __NR_pread64);
pread_64_was_forwarded = true;
return SandboxBPF::ForwardSyscall(args);
}
};
BPF_TEST_C(SandboxBPF, Pread64, TrapPread64Policy) {
ScopedTemporaryFile temp_file;
const uint64_t kLargeOffset = (static_cast<uint64_t>(1) << 32) | 0xBEEF;
const char kTestString[] = "This is a test!";
BPF_ASSERT(FullPwrite64(
temp_file.fd(), kTestString, sizeof(kTestString), kLargeOffset));
char read_test_string[sizeof(kTestString)] = {};
BPF_ASSERT(FullPread64(temp_file.fd(),
read_test_string,
sizeof(read_test_string),
kLargeOffset));
UNSAFE_TODO(BPF_ASSERT_EQ(
0, memcmp(kTestString, read_test_string, sizeof(kTestString))));
BPF_ASSERT(pread_64_was_forwarded);
}
#endif
void* TsyncApplyToTwoThreadsFunc(void* cond_ptr) {
base::WaitableEvent* event = static_cast<base::WaitableEvent*>(cond_ptr);
if (!event->IsSignaled()) {
event->Wait();
}
BPF_ASSERT(event->IsSignaled());
DenylistNanosleepPolicy::AssertNanosleepFails();
return nullptr;
}
SANDBOX_TEST(SandboxBPF, Tsync) {
const bool supports_multi_threaded = SandboxBPF::SupportsSeccompSandbox(
SandboxBPF::SeccompLevel::MULTI_THREADED);
#if BUILDFLAG(IS_CHROMEOS)
if (base::SysInfo::IsRunningOnChromeOS()) {
BPF_ASSERT_EQ(true, supports_multi_threaded);
}
#endif
if (!supports_multi_threaded) {
return;
}
base::WaitableEvent event(base::WaitableEvent::ResetPolicy::MANUAL,
base::WaitableEvent::InitialState::NOT_SIGNALED);
pthread_t thread;
BPF_ASSERT_EQ(
0, pthread_create(&thread, nullptr, &TsyncApplyToTwoThreadsFunc, &event));
const struct timespec ts = {0, 0};
BPF_ASSERT_EQ(0, HANDLE_EINTR(syscall(__NR_nanosleep, &ts, NULL)));
SandboxBPF sandbox(std::make_unique<DenylistNanosleepPolicy>());
BPF_ASSERT(sandbox.StartSandbox(SandboxBPF::SeccompLevel::MULTI_THREADED));
DenylistNanosleepPolicy::AssertNanosleepFails();
event.Signal();
BPF_ASSERT_EQ(0, pthread_join(thread, nullptr));
}
class AllowAllPolicy : public Policy {
public:
AllowAllPolicy() = default;
AllowAllPolicy(const AllowAllPolicy&) = delete;
AllowAllPolicy& operator=(const AllowAllPolicy&) = delete;
~AllowAllPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override { return Allow(); }
};
SANDBOX_DEATH_TEST(
SandboxBPF,
StartMultiThreadedAsSingleThreaded,
DEATH_MESSAGE(
ThreadHelpers::GetAssertSingleThreadedErrorMessageForTests())) {
base::Thread thread("sandbox.linux.StartMultiThreadedAsSingleThreaded");
BPF_ASSERT(thread.Start());
SandboxBPF sandbox(std::make_unique<AllowAllPolicy>());
BPF_ASSERT(!sandbox.StartSandbox(SandboxBPF::SeccompLevel::SINGLE_THREADED));
}
intptr_t NoOpHandler(const struct arch_seccomp_data& args, void*) {
return -1;
}
class UnsafeTrapWithCondPolicy : public Policy {
public:
UnsafeTrapWithCondPolicy() = default;
UnsafeTrapWithCondPolicy(const UnsafeTrapWithCondPolicy&) = delete;
UnsafeTrapWithCondPolicy& operator=(const UnsafeTrapWithCondPolicy&) = delete;
~UnsafeTrapWithCondPolicy() override = default;
ResultExpr EvaluateSyscall(int sysno) const override {
DCHECK(SandboxBPF::IsValidSyscallNumber(sysno));
setenv(kSandboxDebuggingEnv, "t", 0);
Die::SuppressInfoMessages(true);
if (SandboxBPF::IsRequiredForUnsafeTrap(sysno))
return Allow();
if (IsSyscallForTestHarness(sysno))
return Allow();
switch (sysno) {
case __NR_uname: {
const Arg<uint32_t> arg(0);
return If(arg == 0, Allow()).Else(Error(EPERM));
}
case __NR_setgid: {
const Arg<uint32_t> arg(0);
return Switch(arg)
.Case(100, Error(ENOMEM))
.Case(200, Error(ENOSYS))
.Default(Error(EPERM));
}
case __NR_close:
return Allow();
case __NR_getppid:
return UnsafeTrap(NoOpHandler, nullptr);
default:
return Error(EPERM);
}
}
};
BPF_TEST_C(SandboxBPF, UnsafeTrapWithCond, UnsafeTrapWithCondPolicy) {
BPF_ASSERT_EQ(-1, syscall(__NR_uname, 0));
BPF_ASSERT_EQ(EFAULT, errno);
BPF_ASSERT_EQ(-1, syscall(__NR_uname, 1));
BPF_ASSERT_EQ(EPERM, errno);
BPF_ASSERT_EQ(-1, syscall(__NR_setgid, 100));
BPF_ASSERT_EQ(ENOMEM, errno);
BPF_ASSERT_EQ(-1, syscall(__NR_setgid, 200));
BPF_ASSERT_EQ(ENOSYS, errno);
BPF_ASSERT_EQ(-1, syscall(__NR_setgid, 300));
BPF_ASSERT_EQ(EPERM, errno);
}
}
}
}