[PATCH testsuite v2] tests/overlay: verify that execmem is not checked for the mounter

Ondrej Mosnacek <[email protected]>
Newsgroups org.kernel.vger.selinux
Message-ID <[email protected]>
Add a test that verifies that the execmem permission is checked only on
the process mapping/updating the memory region and not against the
mounter credentials.

Signed-off-by: Ondrej Mosnacek <[email protected]>
Acked-by: Stephen Smalley <[email protected]>
---

v2: apply tools/check-syntax formatting

 policy/test_overlayfs.te   |  4 ++++
 tests/overlay/map_access.c | 20 ++++++++++++--------
 tests/overlay/test         | 11 ++++++++++-
 3 files changed, 26 insertions(+), 9 deletions(-)

diff --git a/policy/test_overlayfs.te b/policy/test_overlayfs.te
index 787685c..e1e1ebb 100644
--- a/policy/test_overlayfs.te
+++ b/policy/test_overlayfs.te
@@ -122,6 +122,10 @@ can_exec(test_overlay_mounter_t, test_file_t)
 allow test_overlay_client_t self:dir list_dir_perms;
 allow test_overlay_client_t self:file read_file_perms;
 
+# For testing execmem checking (should be checked only on the client,
+# never on the mounter)
+allow test_overlay_client_t self:process execmem;
+
 mcs_constrained(test_overlay_client_t)
 
 kernel_read_system_state(test_overlay_client_t)
diff --git a/tests/overlay/map_access.c b/tests/overlay/map_access.c
index da1ae36..6160563 100644
--- a/tests/overlay/map_access.c
+++ b/tests/overlay/map_access.c
@@ -11,15 +11,20 @@ int main(int argc, const char **argv)
 {
 	const char *file;
 	void *ptr;
-	int rdonly, fd, ret;
+	int rdonly, execmem, flags, prot, fd, ret;
 
-	if (argc != 3 || (strcmp(argv[2], "R_OK") && strcmp(argv[2], "W_OK"))) {
-		fprintf(stderr, "Usage %s <file> R_OK|W_OK\n", argv[0]);
+	if (argc != 3 || (strcmp(argv[2], "R_OK") && strcmp(argv[2], "W_OK") &&
+			  strcmp(argv[2], "EXECMEM"))) {
+		fprintf(stderr, "Usage %s <file> R_OK|W_OK|EXECMEM\n", argv[0]);
 		return EINVAL;
 	}
 
 	file = argv[1];
-	rdonly = strcmp(argv[2], "R_OK") == 0;
+	rdonly = strcmp(argv[2], "W_OK") != 0;
+	execmem = strcmp(argv[2], "EXECMEM") == 0;
+	flags = execmem ? MAP_PRIVATE : MAP_SHARED;
+	prot = PROT_READ | (!rdonly ||
+			    execmem ? PROT_WRITE : 0) | (execmem ? PROT_EXEC : 0);
 
 	fd = open(file, rdonly ? O_RDONLY : O_RDWR);
 	if (fd == -1) {
@@ -28,8 +33,7 @@ int main(int argc, const char **argv)
 	}
 
 	/* try direct mmap */
-	ptr = mmap(NULL, 1, rdonly ? PROT_READ : PROT_READ | PROT_WRITE,
-		   MAP_SHARED, fd, 0);
+	ptr = mmap(NULL, 1, prot, flags, fd, 0);
 	if (ptr == MAP_FAILED) {
 		perror("mmap");
 		return 3;
@@ -37,13 +41,13 @@ int main(int argc, const char **argv)
 	munmap(ptr, 1);
 
 	/* try mmap with PROT_NONE followed by mprotect with full access */
-	ptr = mmap(NULL, 1, PROT_NONE, MAP_SHARED, fd, 0);
+	ptr = mmap(NULL, 1, PROT_NONE, flags, fd, 0);
 	if (ptr == MAP_FAILED) {
 		perror("mmap PROT_NONE");
 		return 4;
 	}
 
-	ret = mprotect(ptr, 1, rdonly ? PROT_READ : PROT_READ | PROT_WRITE);
+	ret = mprotect(ptr, 1, prot);
 	if (ret == -1) {
 		perror("mprotect");
 		return 5;
diff --git a/tests/overlay/test b/tests/overlay/test
index 2d0555a..ae8ec33 100755
--- a/tests/overlay/test
+++ b/tests/overlay/test
@@ -19,7 +19,7 @@ BEGIN {
         plan skip_all => "overlayfs upperdir not supported on NFS";
     }
     else {
-        plan tests => 135;
+        plan tests => 137;
     }
 }
 
@@ -641,6 +641,13 @@ sub test_68_8_ctx {
     return;
 }
 
+sub test_68_9 {
+    print "Check execmem map access on mapreadfile, should succeed\n";
+    $result = mmap( "$basedir/container1/merged/mapreadfile", "EXECMEM" );
+    ok( $result eq 0 );
+    return;
+}
+
 sub test_70 {
     print "Check unlink access on client_nounlinkfile, should fail.\n";
     $result = system(
@@ -891,6 +898,7 @@ sub nocontext_test {
     test_68_6();
     test_68_7();
     test_68_8();
+    test_68_9();
 
     print "=====================================================\n";
     print "unlink tests.\n";
@@ -1033,6 +1041,7 @@ sub context_test {
     test_68_6();
     test_68_7_ctx();
     test_68_8_ctx();
+    test_68_9();
 
     print "=====================================================\n";
     print "unlink tests.\n";
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.