File: cap.c

package info (click to toggle)
llvm-toolchain-19 1%3A19.1.7-7
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 1,998,872 kB
  • sloc: cpp: 6,951,694; ansic: 1,486,157; asm: 913,598; python: 232,024; f90: 80,126; objc: 75,281; lisp: 37,276; pascal: 16,990; sh: 10,033; ml: 5,058; perl: 4,724; awk: 3,523; makefile: 3,177; javascript: 2,504; xml: 892; fortran: 664; cs: 573
file content (48 lines) | stat: -rw-r--r-- 1,393 bytes parent folder | download | duplicates (16)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
// RUN: %clang %s -o %t && %run %t
// capget() and capset() are not intercepted on Android.
// UNSUPPORTED: android

#include <assert.h>
#include <errno.h>
#include <linux/capability.h>
#include <stdio.h>
#include <stdlib.h>

#include "sanitizer_common/sanitizer_specific.h"

/* Use capget() and capset() from glibc. */
int capget(cap_user_header_t header, cap_user_data_t data);
int capset(cap_user_header_t header, const cap_user_data_t data);

static void test(int version, int u32s) {
  struct __user_cap_header_struct hdr = {
      .version = version,
      .pid = 0,
  };
  struct __user_cap_data_struct data[u32s];
  if (capget(&hdr, data)) {
    assert(errno == EINVAL);
    /* Check that memory is not touched. */
#if __has_feature(memory_sanitizer)
    assert(__msan_test_shadow(data, sizeof(data)) == 0);
#endif
    hdr.version = version;
    int err = capset(&hdr, data);
    assert(errno == EINVAL);
  } else {
    for (int i = 0; i < u32s; i++)
      printf("%x %x %x\n", data[i].effective, data[i].permitted,
             data[i].inheritable);
    int err = capset(&hdr, data);
    assert(!err);
  }
}

int main() {
  test(0, 1); /* Test an incorrect version. */
  test(_LINUX_CAPABILITY_VERSION_1, _LINUX_CAPABILITY_U32S_1);
  test(_LINUX_CAPABILITY_VERSION_2, _LINUX_CAPABILITY_U32S_2);
  test(_LINUX_CAPABILITY_VERSION_3, _LINUX_CAPABILITY_U32S_3);

  return EXIT_SUCCESS;
}