[PATCHv3] tst-pidfd.c: UNSUPPORTED if we get EPERM on pidfd_open or pidfd_getfd

Adhemerval Zanella adhemerval.zanella@linaro.org
Mon Jul 4 19:46:58 GMT 2022



> On 1 Jul 2022, at 08:25, Mark Wielaard <mark@klomp.org> wrote:
> 
> pidfd_open or pidfd_getfd can fail with errno EPERM for various reasons
> in a restricted environment. Use FAIL_UNSUPPORTED in that case.
> ---
> 
> v3: Also test for EPERM on pidfd_open, don't mention
>    PTRACE_MODE_ATTACH_REALCREDS since it is just one reason for
>    getting EPERM.
> v2: separate ENOSYS and EPERM checks and FAIL_UNSUPPORTED messages
> 
> https://code.wildebeest.org/git/user/mjw/glibc/commit/?h=container-perms&id=3e1211cb6e3f0dba98201c12610a6cb2cb106d2d
> 
> sysdeps/unix/sysv/linux/tst-pidfd.c | 12 +++++++++++-
> 1 file changed, 11 insertions(+), 1 deletion(-)
> 
> diff --git a/sysdeps/unix/sysv/linux/tst-pidfd.c b/sysdeps/unix/sysv/linux/tst-pidfd.c
> index d93b6faa6f..2655d94636 100644
> --- a/sysdeps/unix/sysv/linux/tst-pidfd.c
> +++ b/sysdeps/unix/sysv/linux/tst-pidfd.c
> @@ -92,11 +92,15 @@ do_test (void)
>   {
>     /* The pidfd_getfd syscall was the last in the set of pidfd related
>        syscalls added to the kernel.  Use pidfd_getfd to decide if this
> -       kernel has pidfd support that we can test.  */
> +       kernel has pidfd support that we can test.  And that we have
> +       permission to use pidfd_getfd.  */
>     int r = pidfd_getfd (0, 0, 1);
>     TEST_VERIFY_EXIT (r == -1);
>     if (errno == ENOSYS)
>       FAIL_UNSUPPORTED ("kernel does not support pidfd_getfd, skipping test");
> +    if (errno == EPERM)
> +      FAIL_UNSUPPORTED ("don't have permission to use pidfd_getfd, "
> +			"skipping test");

Sorry, but if this is really failing with EPERM for a valid call the
syscall filtering is broken: either kernel should return ENOSYS
or EINVAL (assuming 1 in an invalid flag, we might need to update
it once kernel starts to implement possible flags).

>   }
> 
>   ppid = getpid ();
> @@ -113,9 +117,15 @@ do_test (void)
>   xclose (sockets[1]);
> 
>   TEST_COMPARE (pidfd_open (-1, 0), -1);
> +  if (errno == EPERM)
> +    FAIL_UNSUPPORTED ("don't have permission to use pidfd_getfd, "
> +		      "skipping test");
>   TEST_COMPARE (errno, EINVAL);
> 
>   int pidfd = pidfd_open (pid, 0);
> +  if (pidfd == -1 && errno == EPERM)
> +    FAIL_UNSUPPORTED ("don't have permission to use pidfd_getfd, "
> +		      "skipping test");
>   TEST_VERIFY (pidfd != -1);
> 
>   /* Wait for first sigtimedwait.  */
> -- 
> 2.18.4
> 



More information about the Libc-alpha mailing list