jbates@chromium.org | ce208f87 | 2012-03-07 20:42:56 | [diff] [blame] | 1 | // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
Greg Thompson | bec327a7 | 2021-11-10 16:31:48 | [diff] [blame] | 5 | #include "build/os_buildflags.h" |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 6 | |
Greg Thompson | bec327a7 | 2021-11-10 16:31:48 | [diff] [blame] | 7 | #if BUILDFLAG(IS_MAC) |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 8 | extern "C" { |
| 9 | #include <sandbox.h> |
Nico Weber | e86ed9b3 | 2019-02-22 18:11:12 | [diff] [blame] | 10 | } |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 11 | #endif |
Greg Thompson | bec327a7 | 2021-11-10 16:31:48 | [diff] [blame] | 12 | |
patrick@chromium.org | d67c249 | 2009-03-20 17:26:02 | [diff] [blame] | 13 | #include <fcntl.h> |
avi | 246998d | 2015-12-22 02:39:04 | [diff] [blame] | 14 | #include <stddef.h> |
hubbe@chromium.org | dc875dc | 2013-10-15 00:07:00 | [diff] [blame] | 15 | #include <sys/socket.h> |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 16 | #include <sys/stat.h> |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 17 | #include <unistd.h> |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 18 | |
danakj | 03de39b | 2016-04-23 04:21:09 | [diff] [blame] | 19 | #include <memory> |
hubbe@chromium.org | dc875dc | 2013-10-15 00:07:00 | [diff] [blame] | 20 | #include <queue> |
| 21 | |
erg@google.com | 7a4de7a6 | 2010-08-17 18:38:24 | [diff] [blame] | 22 | #include "base/file_descriptor_posix.h" |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 23 | #include "base/pickle.h" |
| 24 | #include "base/posix/eintr_wrapper.h" |
fdoray | 8e3258685 | 2016-06-22 19:56:16 | [diff] [blame] | 25 | #include "base/run_loop.h" |
hubbe@chromium.org | dc875dc | 2013-10-15 00:07:00 | [diff] [blame] | 26 | #include "base/synchronization/waitable_event.h" |
Patrick Monette | 643cdf6 | 2021-10-15 19:13:42 | [diff] [blame] | 27 | #include "base/task/single_thread_task_runner.h" |
gab | 4d92485f | 2016-09-26 21:00:45 | [diff] [blame] | 28 | #include "base/threading/thread.h" |
rockot | a34707ca | 2016-07-20 04:28:32 | [diff] [blame] | 29 | #include "base/threading/thread_task_runner_handle.h" |
morrita | 4b5c28e2 | 2015-01-14 21:17:06 | [diff] [blame] | 30 | #include "ipc/ipc_message_attachment_set.h" |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 31 | #include "ipc/ipc_message_utils.h" |
| 32 | #include "ipc/ipc_test_base.h" |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 33 | |
Greg Thompson | bec327a7 | 2021-11-10 16:31:48 | [diff] [blame] | 34 | #if BUILDFLAG(IS_MAC) |
kerrnel | dc059fe | 2016-04-12 16:39:06 | [diff] [blame] | 35 | #include "sandbox/mac/seatbelt.h" |
Greg Thompson | 9360c5d4 | 2021-12-01 17:55:34 | [diff] [blame] | 36 | #elif BUILDFLAG(IS_FUCHSIA) |
| 37 | #include "base/memory/scoped_refptr.h" |
| 38 | #include "base/test/scoped_dev_zero_fuchsia.h" |
kerrnel | dc059fe | 2016-04-12 16:39:06 | [diff] [blame] | 39 | #endif |
| 40 | |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 41 | namespace { |
| 42 | |
yusukes | c986c543 | 2015-05-06 19:45:45 | [diff] [blame] | 43 | const unsigned kNumFDsToSend = 7; // per message |
| 44 | const unsigned kNumMessages = 20; |
agl@chromium.org | 92639446 | 2009-02-11 23:23:12 | [diff] [blame] | 45 | const char* kDevZeroPath = "/dev/zero"; |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 46 | |
anujk.sharma | 5a7ffe2f | 2015-01-22 05:39:37 | [diff] [blame] | 47 | static_assert(kNumFDsToSend == |
| 48 | IPC::MessageAttachmentSet::kMaxDescriptorsPerMessage, |
| 49 | "The number of FDs to send must be kMaxDescriptorsPerMessage."); |
yusukes | d0329fc | 2015-01-06 06:56:34 | [diff] [blame] | 50 | |
hubbe@chromium.org | dc875dc | 2013-10-15 00:07:00 | [diff] [blame] | 51 | class MyChannelDescriptorListenerBase : public IPC::Listener { |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 52 | public: |
dcheng | fe61fca | 2014-10-22 02:29:52 | [diff] [blame] | 53 | bool OnMessageReceived(const IPC::Message& message) override { |
brettw | bd4d711 | 2015-06-03 04:29:25 | [diff] [blame] | 54 | base::PickleIterator iter(message); |
agl@chromium.org | 5fe733de | 2009-02-11 18:59:20 | [diff] [blame] | 55 | base::FileDescriptor descriptor; |
yusukes | d0329fc | 2015-01-06 06:56:34 | [diff] [blame] | 56 | while (IPC::ParamTraits<base::FileDescriptor>::Read( |
| 57 | &message, &iter, &descriptor)) { |
| 58 | HandleFD(descriptor.fd); |
| 59 | } |
jam@chromium.org | a95986a | 2010-12-24 06:19:28 | [diff] [blame] | 60 | return true; |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 61 | } |
| 62 | |
hubbe@chromium.org | dc875dc | 2013-10-15 00:07:00 | [diff] [blame] | 63 | protected: |
| 64 | virtual void HandleFD(int fd) = 0; |
| 65 | }; |
| 66 | |
| 67 | class MyChannelDescriptorListener : public MyChannelDescriptorListenerBase { |
| 68 | public: |
| 69 | explicit MyChannelDescriptorListener(ino_t expected_inode_num) |
| 70 | : MyChannelDescriptorListenerBase(), |
| 71 | expected_inode_num_(expected_inode_num), |
| 72 | num_fds_received_(0) { |
hubbe@chromium.org | 6b47b4d | 2013-10-10 21:12:14 | [diff] [blame] | 73 | } |
| 74 | |
sammc | 6ed3efb | 2016-11-23 03:17:35 | [diff] [blame] | 75 | unsigned num_fds_received() const { |
| 76 | return num_fds_received_; |
hubbe@chromium.org | 6b47b4d | 2013-10-10 21:12:14 | [diff] [blame] | 77 | } |
| 78 | |
dcheng | fe61fca | 2014-10-22 02:29:52 | [diff] [blame] | 79 | void OnChannelError() override { |
Gabriel Charette | 53a9ef81 | 2017-07-26 12:36:23 | [diff] [blame] | 80 | base::RunLoop::QuitCurrentWhenIdleDeprecated(); |
dcheng | f3076af | 2014-10-21 18:02:42 | [diff] [blame] | 81 | } |
hubbe@chromium.org | dc875dc | 2013-10-15 00:07:00 | [diff] [blame] | 82 | |
| 83 | protected: |
dcheng | fe61fca | 2014-10-22 02:29:52 | [diff] [blame] | 84 | void HandleFD(int fd) override { |
yusukes | d0329fc | 2015-01-06 06:56:34 | [diff] [blame] | 85 | ASSERT_GE(fd, 0); |
hubbe@chromium.org | dc875dc | 2013-10-15 00:07:00 | [diff] [blame] | 86 | // Check that we can read from the FD. |
| 87 | char buf; |
| 88 | ssize_t amt_read = read(fd, &buf, 1); |
| 89 | ASSERT_EQ(amt_read, 1); |
| 90 | ASSERT_EQ(buf, 0); // /dev/zero always reads 0 bytes. |
| 91 | |
| 92 | struct stat st; |
| 93 | ASSERT_EQ(fstat(fd, &st), 0); |
| 94 | |
| 95 | ASSERT_EQ(close(fd), 0); |
| 96 | |
| 97 | // Compare inode numbers to check that the file sent over the wire is |
| 98 | // actually the one expected. |
| 99 | ASSERT_EQ(expected_inode_num_, st.st_ino); |
| 100 | |
| 101 | ++num_fds_received_; |
yusukes | d0329fc | 2015-01-06 06:56:34 | [diff] [blame] | 102 | if (num_fds_received_ == kNumFDsToSend * kNumMessages) |
Gabriel Charette | 53a9ef81 | 2017-07-26 12:36:23 | [diff] [blame] | 103 | base::RunLoop::QuitCurrentWhenIdleDeprecated(); |
hubbe@chromium.org | dc875dc | 2013-10-15 00:07:00 | [diff] [blame] | 104 | } |
| 105 | |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 106 | private: |
| 107 | ino_t expected_inode_num_; |
agl@chromium.org | 92639446 | 2009-02-11 23:23:12 | [diff] [blame] | 108 | unsigned num_fds_received_; |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 109 | }; |
| 110 | |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 111 | class IPCSendFdsTest : public IPCChannelMojoTestBase { |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 112 | protected: |
Greg Thompson | 9360c5d4 | 2021-12-01 17:55:34 | [diff] [blame] | 113 | void SetUp() override { |
| 114 | #if BUILDFLAG(IS_FUCHSIA) |
| 115 | ASSERT_TRUE(dev_zero_); |
| 116 | #endif |
| 117 | } |
| 118 | |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 119 | void RunServer() { |
| 120 | // Set up IPC channel and start client. |
| 121 | MyChannelDescriptorListener listener(-1); |
| 122 | CreateChannel(&listener); |
| 123 | ASSERT_TRUE(ConnectChannel()); |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 124 | |
yusukes | d0329fc | 2015-01-06 06:56:34 | [diff] [blame] | 125 | for (unsigned i = 0; i < kNumMessages; ++i) { |
bbudge@chromium.org | 753bb25 | 2013-11-04 22:28:12 | [diff] [blame] | 126 | IPC::Message* message = |
| 127 | new IPC::Message(0, 3, IPC::Message::PRIORITY_NORMAL); |
yusukes | d0329fc | 2015-01-06 06:56:34 | [diff] [blame] | 128 | for (unsigned j = 0; j < kNumFDsToSend; ++j) { |
| 129 | const int fd = open(kDevZeroPath, O_RDONLY); |
| 130 | ASSERT_GE(fd, 0); |
| 131 | base::FileDescriptor descriptor(fd, true); |
| 132 | IPC::ParamTraits<base::FileDescriptor>::Write(message, descriptor); |
| 133 | } |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 134 | ASSERT_TRUE(sender()->Send(message)); |
| 135 | } |
| 136 | |
| 137 | // Run message loop. |
fdoray | 8e3258685 | 2016-06-22 19:56:16 | [diff] [blame] | 138 | base::RunLoop().Run(); |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 139 | |
| 140 | // Close the channel so the client's OnChannelError() gets fired. |
| 141 | channel()->Close(); |
| 142 | |
| 143 | EXPECT_TRUE(WaitForClientShutdown()); |
| 144 | DestroyChannel(); |
agl@chromium.org | 92639446 | 2009-02-11 23:23:12 | [diff] [blame] | 145 | } |
Greg Thompson | 9360c5d4 | 2021-12-01 17:55:34 | [diff] [blame] | 146 | |
| 147 | private: |
| 148 | #if BUILDFLAG(IS_FUCHSIA) |
| 149 | scoped_refptr<base::ScopedDevZero> dev_zero_ = base::ScopedDevZero::Get(); |
| 150 | #endif |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 151 | }; |
| 152 | |
Greg Thompson | 9360c5d4 | 2021-12-01 17:55:34 | [diff] [blame] | 153 | // Disabled on Fuchsia due to failures; see https://crbug.com/1272424. |
| 154 | #if BUILDFLAG(IS_FUCHSIA) |
| 155 | #define MAYBE_DescriptorTest DISABLED_DescriptorTest |
| 156 | #else |
| 157 | #define MAYBE_DescriptorTest DescriptorTest |
| 158 | #endif |
| 159 | TEST_F(IPCSendFdsTest, MAYBE_DescriptorTest) { |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 160 | Init("SendFdsClient"); |
| 161 | RunServer(); |
| 162 | } |
| 163 | |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 164 | class SendFdsTestClientFixture : public IpcChannelMojoTestClient { |
| 165 | protected: |
| 166 | void SendFdsClientCommon(const std::string& test_client_name, |
| 167 | ino_t expected_inode_num) { |
| 168 | MyChannelDescriptorListener listener(expected_inode_num); |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 169 | |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 170 | // Set up IPC channel. |
| 171 | Connect(&listener); |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 172 | |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 173 | // Run message loop. |
| 174 | base::RunLoop().Run(); |
jeremy@chromium.org | c2f10ed | 2009-02-10 00:52:57 | [diff] [blame] | 175 | |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 176 | // Verify that the message loop was exited due to getting the correct number |
| 177 | // of descriptors, and not because of the channel closing unexpectedly. |
sammc | 6ed3efb | 2016-11-23 03:17:35 | [diff] [blame] | 178 | EXPECT_EQ(kNumFDsToSend * kNumMessages, listener.num_fds_received()); |
dmaclach@chromium.org | d484ab5 | 2010-12-09 01:12:20 | [diff] [blame] | 179 | |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 180 | Close(); |
| 181 | } |
| 182 | }; |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 183 | |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 184 | DEFINE_IPC_CHANNEL_MOJO_TEST_CLIENT_WITH_CUSTOM_FIXTURE( |
| 185 | SendFdsClient, |
| 186 | SendFdsTestClientFixture) { |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 187 | struct stat st; |
| 188 | int fd = open(kDevZeroPath, O_RDONLY); |
| 189 | fstat(fd, &st); |
mark@chromium.org | d89eec8 | 2013-12-03 14:10:59 | [diff] [blame] | 190 | EXPECT_GE(IGNORE_EINTR(close(fd)), 0); |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 191 | SendFdsClientCommon("SendFdsClient", st.st_ino); |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 192 | } |
viettrungluu@chromium.org | 0cb7d8c8 | 2013-01-11 15:13:37 | [diff] [blame] | 193 | |
Greg Thompson | bec327a7 | 2021-11-10 16:31:48 | [diff] [blame] | 194 | #if BUILDFLAG(IS_MAC) |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 195 | // Test that FDs are correctly sent to a sandboxed process. |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 196 | // TODO(port): Make this test cross-platform. |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 197 | TEST_F(IPCSendFdsTest, DescriptorTestSandboxed) { |
| 198 | Init("SendFdsSandboxedClient"); |
| 199 | RunServer(); |
| 200 | } |
| 201 | |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 202 | DEFINE_IPC_CHANNEL_MOJO_TEST_CLIENT_WITH_CUSTOM_FIXTURE( |
| 203 | SendFdsSandboxedClient, |
| 204 | SendFdsTestClientFixture) { |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 205 | struct stat st; |
agl@chromium.org | 92639446 | 2009-02-11 23:23:12 | [diff] [blame] | 206 | const int fd = open(kDevZeroPath, O_RDONLY); |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 207 | fstat(fd, &st); |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 208 | ASSERT_LE(0, IGNORE_EINTR(close(fd))); |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 209 | |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 210 | // Enable the sandbox. |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 211 | char* error_buff = NULL; |
kerrnel | df7ac746 | 2016-09-24 00:39:26 | [diff] [blame] | 212 | int error = sandbox::Seatbelt::Init( |
| 213 | sandbox::Seatbelt::kProfilePureComputation, SANDBOX_NAMED, &error_buff); |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 214 | ASSERT_EQ(0, error); |
| 215 | ASSERT_FALSE(error_buff); |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 216 | |
kerrnel | dc059fe | 2016-04-12 16:39:06 | [diff] [blame] | 217 | sandbox::Seatbelt::FreeError(error_buff); |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 218 | |
viettrungluu@chromium.org | 3c78858 | 2013-01-25 21:51:35 | [diff] [blame] | 219 | // Make sure sandbox is really enabled. |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 220 | ASSERT_EQ(-1, open(kDevZeroPath, O_RDONLY)) |
| 221 | << "Sandbox wasn't properly enabled"; |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 222 | |
| 223 | // See if we can receive a file descriptor. |
sammc | 4bcc4ed6 | 2016-10-27 10:13:59 | [diff] [blame] | 224 | SendFdsClientCommon("SendFdsSandboxedClient", st.st_ino); |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 225 | } |
Greg Thompson | bec327a7 | 2021-11-10 16:31:48 | [diff] [blame] | 226 | #endif // BUILDFLAG(IS_MAC) |
jeremy@chromium.org | e8351b7e | 2009-02-10 22:25:39 | [diff] [blame] | 227 | |
viettrungluu@chromium.org | 2a3aa7b5 | 2013-01-11 20:56:22 | [diff] [blame] | 228 | } // namespace |