/* * Copyright (c) 2020, the SerenityOS developers. * All rights reserved. * * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions are met: * * 1. Redistributions of source code must retain the above copyright notice, this * list of conditions and the following disclaimer. * * 2. Redistributions in binary form must reproduce the above copyright notice, * this list of conditions and the following disclaimer in the documentation * and/or other materials provided with the distribution. * * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE * DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. */ #include #include int main() { int res = unveil("/etc", "r"); if (res < 0) { fprintf(stderr, "FAIL, unveil read only failed\n"); return 1; } res = unveil("/etc", "w"); if (res >= 0) { fprintf(stderr, "FAIL, unveil write permitted after unveil read only\n"); return 1; } res = unveil("/etc", "x"); if (res >= 0) { fprintf(stderr, "FAIL, unveil execute permitted after unveil read only\n"); return 1; } res = unveil("/etc", "c"); if (res >= 0) { fprintf(stderr, "FAIL, unveil create permitted after unveil read only\n"); return 1; } res = unveil("/tmp/doesnotexist", "c"); if (res < 0) { fprintf(stderr, "FAIL, unveil create on non-existent path failed\n"); return 1; } res = unveil("/home", "b"); if (res < 0) { fprintf(stderr, "FAIL, unveil browse failed\n"); return 1; } res = unveil("/home", "w"); if (res >= 0) { fprintf(stderr, "FAIL, unveil write permitted after unveil browse only\n"); return 1; } res = unveil("/home", "x"); if (res >= 0) { fprintf(stderr, "FAIL, unveil execute permitted after unveil browse only\n"); return 1; } res = unveil("/home", "c"); if (res >= 0) { fprintf(stderr, "FAIL, unveil create permitted after unveil browse only\n"); return 1; } res = unveil(nullptr, nullptr); if (res < 0) { fprintf(stderr, "FAIL, unveil state lock failed\n"); return 1; } res = unveil("/bin", "w"); if (res >= 0) { fprintf(stderr, "FAIL, unveil permitted after unveil state locked\n"); return 1; } printf("PASS\n"); return 0; }