1*a1e26a70SApple OSS Distributions #pragma clang diagnostic ignored "-Wdeprecated-declarations" 2*a1e26a70SApple OSS Distributions 3*a1e26a70SApple OSS Distributions #include <bsm/audit.h> 4*a1e26a70SApple OSS Distributions #include <bsm/audit_session.h> 5*a1e26a70SApple OSS Distributions #include <err.h> 6*a1e26a70SApple OSS Distributions #include <sysexits.h> 7*a1e26a70SApple OSS Distributions #include <unistd.h> 8*a1e26a70SApple OSS Distributions #include <errno.h> 9*a1e26a70SApple OSS Distributions #include <string.h> 10*a1e26a70SApple OSS Distributions 11*a1e26a70SApple OSS Distributions #include <darwintest.h> 12*a1e26a70SApple OSS Distributions #include <darwintest_utils.h> 13*a1e26a70SApple OSS Distributions 14*a1e26a70SApple OSS Distributions T_GLOBAL_META(T_META_RUN_CONCURRENTLY(true)); 15*a1e26a70SApple OSS Distributions 16*a1e26a70SApple OSS Distributions T_DECL(invalid_setaudit_57414044, 17*a1e26a70SApple OSS Distributions "Verify that auditing a setaudit_addr syscall which has an invalid " 18*a1e26a70SApple OSS Distributions "at_type field does not panic", 19*a1e26a70SApple OSS Distributions T_META_CHECK_LEAKS(false), T_META_TAG_VM_PREFERRED) 20*a1e26a70SApple OSS Distributions { 21*a1e26a70SApple OSS Distributions T_SETUPBEGIN; 22*a1e26a70SApple OSS Distributions 23*a1e26a70SApple OSS Distributions int cond, ret = auditon(A_GETCOND, &cond, sizeof(cond)); 24*a1e26a70SApple OSS Distributions if (ret == -1 && errno == ENOSYS) { 25*a1e26a70SApple OSS Distributions T_SKIP("no kernel support for auditing; can't test"); 26*a1e26a70SApple OSS Distributions } 27*a1e26a70SApple OSS Distributions T_ASSERT_POSIX_SUCCESS(ret, "auditon A_GETCOND"); 28*a1e26a70SApple OSS Distributions if (cond != AUC_AUDITING) { 29*a1e26a70SApple OSS Distributions T_SKIP("auditing is not enabled; can't test"); 30*a1e26a70SApple OSS Distributions } 31*a1e26a70SApple OSS Distributions 32*a1e26a70SApple OSS Distributions /* set up auditing to audit `setaudit_addr` */ 33*a1e26a70SApple OSS Distributions auditpinfo_addr_t pinfo_addr = {.ap_pid = getpid()}; 34*a1e26a70SApple OSS Distributions T_ASSERT_POSIX_SUCCESS(auditon(A_GETPINFO_ADDR, &pinfo_addr, sizeof(pinfo_addr)), NULL); 35*a1e26a70SApple OSS Distributions auditpinfo_t pinfo = {.ap_pid = getpid(), .ap_mask = pinfo_addr.ap_mask}; 36*a1e26a70SApple OSS Distributions pinfo.ap_mask.am_failure |= 0x800; /* man 5 audit_class */ 37*a1e26a70SApple OSS Distributions T_ASSERT_POSIX_SUCCESS(auditon(A_SETPMASK, &pinfo, sizeof(pinfo)), NULL); 38*a1e26a70SApple OSS Distributions 39*a1e26a70SApple OSS Distributions T_SETUPEND; 40*a1e26a70SApple OSS Distributions 41*a1e26a70SApple OSS Distributions struct auditinfo_addr a; 42*a1e26a70SApple OSS Distributions memset(&a, 0, sizeof(a)); 43*a1e26a70SApple OSS Distributions a.ai_termid.at_type = 999; 44*a1e26a70SApple OSS Distributions T_ASSERT_POSIX_FAILURE(setaudit_addr(&a, sizeof(a)), EINVAL, 45*a1e26a70SApple OSS Distributions "setaudit_addr should fail due to invalid at_type"); 46*a1e26a70SApple OSS Distributions } 47