1*8d741a5dSApple OSS Distributions #include <darwintest.h>
2*8d741a5dSApple OSS Distributions #include <darwintest_utils.h>
3*8d741a5dSApple OSS Distributions
4*8d741a5dSApple OSS Distributions #include <errno.h>
5*8d741a5dSApple OSS Distributions #include <fcntl.h>
6*8d741a5dSApple OSS Distributions #include <signal.h>
7*8d741a5dSApple OSS Distributions #include <spawn.h>
8*8d741a5dSApple OSS Distributions #include <spawn_filtering_private.h>
9*8d741a5dSApple OSS Distributions #include <spawn_private.h>
10*8d741a5dSApple OSS Distributions #include <stdbool.h>
11*8d741a5dSApple OSS Distributions #include <stdint.h>
12*8d741a5dSApple OSS Distributions #include <stdio.h>
13*8d741a5dSApple OSS Distributions #include <stdlib.h>
14*8d741a5dSApple OSS Distributions #include <string.h>
15*8d741a5dSApple OSS Distributions #include <sys/spawn_internal.h>
16*8d741a5dSApple OSS Distributions #include <sys/stat.h>
17*8d741a5dSApple OSS Distributions #include <sys/sysctl.h>
18*8d741a5dSApple OSS Distributions #include <sys/syslimits.h>
19*8d741a5dSApple OSS Distributions #include <sysexits.h>
20*8d741a5dSApple OSS Distributions #include <unistd.h>
21*8d741a5dSApple OSS Distributions
22*8d741a5dSApple OSS Distributions static char tmp_path_filter_rules[PATH_MAX] = "";
23*8d741a5dSApple OSS Distributions static char tmp_path_env_output[PATH_MAX] = "";
24*8d741a5dSApple OSS Distributions
25*8d741a5dSApple OSS Distributions static void
cleanup_tmpfiles(void)26*8d741a5dSApple OSS Distributions cleanup_tmpfiles(void)
27*8d741a5dSApple OSS Distributions {
28*8d741a5dSApple OSS Distributions if (tmp_path_filter_rules[0] != '\0') {
29*8d741a5dSApple OSS Distributions unlink(tmp_path_filter_rules);
30*8d741a5dSApple OSS Distributions }
31*8d741a5dSApple OSS Distributions if (tmp_path_env_output[0] != '\0') {
32*8d741a5dSApple OSS Distributions unlink(tmp_path_env_output);
33*8d741a5dSApple OSS Distributions }
34*8d741a5dSApple OSS Distributions }
35*8d741a5dSApple OSS Distributions
36*8d741a5dSApple OSS Distributions /*
37*8d741a5dSApple OSS Distributions * Creates a filtering rules file that says "when launching sh, add this env
38*8d741a5dSApple OSS Distributions * var". The we launch "sh -c env", redirect the output to a file, read the file
39*8d741a5dSApple OSS Distributions * and check that the added env var is present.
40*8d741a5dSApple OSS Distributions */
41*8d741a5dSApple OSS Distributions T_DECL(posix_spawn_filtering,
42*8d741a5dSApple OSS Distributions "Check posix_spawn_filtering",
43*8d741a5dSApple OSS Distributions T_META_ENVVAR("FEATUREFLAGS_ENABLED=Libsystem/posix_spawn_filtering"))
44*8d741a5dSApple OSS Distributions {
45*8d741a5dSApple OSS Distributions #if POSIX_SPAWN_FILTERING_ENABLED
46*8d741a5dSApple OSS Distributions const char *tmpdir = dt_tmpdir();
47*8d741a5dSApple OSS Distributions T_LOG("tmpdir: %s\n", tmpdir);
48*8d741a5dSApple OSS Distributions
49*8d741a5dSApple OSS Distributions strlcat(tmp_path_filter_rules, tmpdir ? tmpdir : "/tmp", sizeof(tmp_path_filter_rules));
50*8d741a5dSApple OSS Distributions strlcat(tmp_path_filter_rules, "/filter.rules.XXXXX", sizeof(tmp_path_filter_rules));
51*8d741a5dSApple OSS Distributions int filter_rules_fd = mkstemp(tmp_path_filter_rules);
52*8d741a5dSApple OSS Distributions T_ASSERT_POSIX_SUCCESS(filter_rules_fd, "create temporary file 1");
53*8d741a5dSApple OSS Distributions
54*8d741a5dSApple OSS Distributions const char *filter_rules_contents =
55*8d741a5dSApple OSS Distributions "binary_name:sh\n"
56*8d741a5dSApple OSS Distributions "add_env:ADDED_VAR=VIA_RULES\n";
57*8d741a5dSApple OSS Distributions ssize_t bytes_written = write(filter_rules_fd, filter_rules_contents, strlen(filter_rules_contents));
58*8d741a5dSApple OSS Distributions T_ASSERT_EQ(bytes_written, (long)strlen(filter_rules_contents), "write should write all contents");
59*8d741a5dSApple OSS Distributions close(filter_rules_fd);
60*8d741a5dSApple OSS Distributions
61*8d741a5dSApple OSS Distributions strlcat(tmp_path_env_output, tmpdir ? tmpdir : "/tmp", sizeof(tmp_path_env_output));
62*8d741a5dSApple OSS Distributions strlcat(tmp_path_env_output, "/env.output.XXXXX", sizeof(tmp_path_env_output));
63*8d741a5dSApple OSS Distributions int env_output_fd = mkstemp(tmp_path_env_output);
64*8d741a5dSApple OSS Distributions T_ASSERT_POSIX_SUCCESS(env_output_fd, "create temporary file 2");
65*8d741a5dSApple OSS Distributions
66*8d741a5dSApple OSS Distributions T_ATEND(cleanup_tmpfiles);
67*8d741a5dSApple OSS Distributions
68*8d741a5dSApple OSS Distributions char * const prog = "/bin/sh";
69*8d741a5dSApple OSS Distributions char * const argv_child[] = { prog,
70*8d741a5dSApple OSS Distributions "-c",
71*8d741a5dSApple OSS Distributions "/usr/bin/env",
72*8d741a5dSApple OSS Distributions NULL, };
73*8d741a5dSApple OSS Distributions
74*8d741a5dSApple OSS Distributions char rules_path_env[PATH_MAX + 100] = {0};
75*8d741a5dSApple OSS Distributions sprintf(rules_path_env, "POSIX_SPAWN_FILTERING_RULES_PATH=%s", tmp_path_filter_rules);
76*8d741a5dSApple OSS Distributions char * const envp_child[] = {
77*8d741a5dSApple OSS Distributions "HELLO=WORLD",
78*8d741a5dSApple OSS Distributions rules_path_env,
79*8d741a5dSApple OSS Distributions NULL,
80*8d741a5dSApple OSS Distributions };
81*8d741a5dSApple OSS Distributions
82*8d741a5dSApple OSS Distributions pid_t child_pid;
83*8d741a5dSApple OSS Distributions
84*8d741a5dSApple OSS Distributions posix_spawn_file_actions_t file_actions;
85*8d741a5dSApple OSS Distributions T_ASSERT_POSIX_SUCCESS(posix_spawn_file_actions_init(&file_actions), "posix_spawn_file_actions_init");
86*8d741a5dSApple OSS Distributions T_ASSERT_POSIX_SUCCESS(posix_spawn_file_actions_adddup2(&file_actions, env_output_fd, STDOUT_FILENO), "posix_spawn_file_actions_addup2");
87*8d741a5dSApple OSS Distributions
88*8d741a5dSApple OSS Distributions int ret;
89*8d741a5dSApple OSS Distributions ret = posix_spawn(&child_pid, prog, &file_actions, NULL, argv_child, envp_child);
90*8d741a5dSApple OSS Distributions T_ASSERT_POSIX_SUCCESS(ret, "posix_spawn");
91*8d741a5dSApple OSS Distributions T_LOG("parent: spawned child with pid %d, waiting for child to exit\n", child_pid);
92*8d741a5dSApple OSS Distributions
93*8d741a5dSApple OSS Distributions ret = posix_spawn_file_actions_destroy(&file_actions);
94*8d741a5dSApple OSS Distributions T_QUIET;
95*8d741a5dSApple OSS Distributions T_ASSERT_POSIX_SUCCESS(ret, "posix_spawn_file_actions_destroy");
96*8d741a5dSApple OSS Distributions
97*8d741a5dSApple OSS Distributions int status = 0;
98*8d741a5dSApple OSS Distributions int waitpid_result = waitpid(child_pid, &status, 0);
99*8d741a5dSApple OSS Distributions T_ASSERT_POSIX_SUCCESS(waitpid_result, "waitpid");
100*8d741a5dSApple OSS Distributions T_ASSERT_EQ(waitpid_result, child_pid, "waitpid should return child we spawned");
101*8d741a5dSApple OSS Distributions T_ASSERT_EQ(WIFEXITED(status), 1, "child should have exited normally");
102*8d741a5dSApple OSS Distributions T_ASSERT_EQ(WEXITSTATUS(status), EX_OK, "child should have exited with success");
103*8d741a5dSApple OSS Distributions
104*8d741a5dSApple OSS Distributions T_ASSERT_EQ(lseek(env_output_fd, 0, SEEK_SET), 0ull, "lseek should succeed");
105*8d741a5dSApple OSS Distributions struct stat s;
106*8d741a5dSApple OSS Distributions T_ASSERT_POSIX_SUCCESS(fstat(env_output_fd, &s), "fstat should succeed");
107*8d741a5dSApple OSS Distributions T_ASSERT_GT(s.st_size, 0ll, "s.st_size > 0");
108*8d741a5dSApple OSS Distributions char env_file_content[s.st_size + 1];
109*8d741a5dSApple OSS Distributions memset(env_file_content, 0, s.st_size + 1);
110*8d741a5dSApple OSS Distributions T_ASSERT_EQ((long)read(env_output_fd, env_file_content, (size_t)s.st_size), (long)s.st_size, "read should load the whole file");
111*8d741a5dSApple OSS Distributions
112*8d741a5dSApple OSS Distributions T_ASSERT_NOTNULL(strstr(env_file_content, "HELLO=WORLD\n"), "original env var present");
113*8d741a5dSApple OSS Distributions T_ASSERT_NOTNULL(strstr(env_file_content, "ADDED_VAR=VIA_RULES\n"), "added env var present");
114*8d741a5dSApple OSS Distributions
115*8d741a5dSApple OSS Distributions T_PASS("posix_spawn_filtering did succeed to set an env var");
116*8d741a5dSApple OSS Distributions
117*8d741a5dSApple OSS Distributions #else // POSIX_SPAWN_FILTERING_ENABLED
118*8d741a5dSApple OSS Distributions T_SKIP("posix_spawn_filtering only supported with POSIX_SPAWN_FILTERING_ENABLED");
119*8d741a5dSApple OSS Distributions #endif // POSIX_SPAWN_FILTERING_ENABLED
120*8d741a5dSApple OSS Distributions }
121