jbates@chromium.org | 0fc8736 | 2012-03-08 05:42:56 +0900 | [diff] [blame] | 1 | // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
| 5 | #include "build/build_config.h" |
| 6 | |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 7 | #if defined(OS_POSIX) |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 8 | #if defined(OS_MACOSX) |
| 9 | extern "C" { |
| 10 | #include <sandbox.h> |
kerrnel | f8e810e | 2016-04-13 01:39:06 +0900 | [diff] [blame] | 11 | }; |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 12 | #endif |
| 13 | #include <fcntl.h> |
avi | 42ebda4 | 2015-12-22 11:39:04 +0900 | [diff] [blame] | 14 | #include <stddef.h> |
hubbe@chromium.org | 683920d | 2013-10-15 09:07:00 +0900 | [diff] [blame] | 15 | #include <sys/socket.h> |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 16 | #include <sys/stat.h> |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 17 | #include <unistd.h> |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 18 | |
danakj | c3fb6c5 | 2016-04-23 13:21:09 +0900 | [diff] [blame] | 19 | #include <memory> |
hubbe@chromium.org | 683920d | 2013-10-15 09:07:00 +0900 | [diff] [blame] | 20 | #include <queue> |
| 21 | |
| 22 | #include "base/callback.h" |
erg@google.com | e6ffcb5 | 2010-08-18 03:38:24 +0900 | [diff] [blame] | 23 | #include "base/file_descriptor_posix.h" |
skyostil | e468e66 | 2015-05-12 20:29:21 +0900 | [diff] [blame] | 24 | #include "base/location.h" |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 25 | #include "base/pickle.h" |
| 26 | #include "base/posix/eintr_wrapper.h" |
fdoray | 284aae5 | 2016-06-23 04:56:16 +0900 | [diff] [blame] | 27 | #include "base/run_loop.h" |
skyostil | e468e66 | 2015-05-12 20:29:21 +0900 | [diff] [blame] | 28 | #include "base/single_thread_task_runner.h" |
hubbe@chromium.org | 683920d | 2013-10-15 09:07:00 +0900 | [diff] [blame] | 29 | #include "base/synchronization/waitable_event.h" |
gab | d3e68cf | 2016-09-27 06:00:45 +0900 | [diff] [blame] | 30 | #include "base/threading/thread.h" |
rockot | 37e7fa4 | 2016-07-20 13:28:32 +0900 | [diff] [blame] | 31 | #include "base/threading/thread_task_runner_handle.h" |
morrita | 33a3590 | 2015-01-15 06:17:06 +0900 | [diff] [blame] | 32 | #include "ipc/ipc_message_attachment_set.h" |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 33 | #include "ipc/ipc_message_utils.h" |
| 34 | #include "ipc/ipc_test_base.h" |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 35 | |
yusukes | f8a5011 | 2015-01-06 15:56:34 +0900 | [diff] [blame] | 36 | #if defined(OS_POSIX) |
| 37 | #include "base/macros.h" |
yusukes | f8a5011 | 2015-01-06 15:56:34 +0900 | [diff] [blame] | 38 | #endif |
| 39 | |
kerrnel | f8e810e | 2016-04-13 01:39:06 +0900 | [diff] [blame] | 40 | #if defined(OS_MACOSX) |
| 41 | #include "sandbox/mac/seatbelt.h" |
| 42 | #endif |
| 43 | |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 44 | namespace { |
| 45 | |
yusukes | df3387d | 2015-05-07 04:45:45 +0900 | [diff] [blame] | 46 | const unsigned kNumFDsToSend = 7; // per message |
| 47 | const unsigned kNumMessages = 20; |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 48 | const char* kDevZeroPath = "/dev/zero"; |
| 49 | |
yusukes | f8a5011 | 2015-01-06 15:56:34 +0900 | [diff] [blame] | 50 | #if defined(OS_POSIX) |
anujk.sharma | f56be5d | 2015-01-22 14:39:37 +0900 | [diff] [blame] | 51 | static_assert(kNumFDsToSend == |
| 52 | IPC::MessageAttachmentSet::kMaxDescriptorsPerMessage, |
| 53 | "The number of FDs to send must be kMaxDescriptorsPerMessage."); |
yusukes | f8a5011 | 2015-01-06 15:56:34 +0900 | [diff] [blame] | 54 | #endif |
| 55 | |
hubbe@chromium.org | 683920d | 2013-10-15 09:07:00 +0900 | [diff] [blame] | 56 | class MyChannelDescriptorListenerBase : public IPC::Listener { |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 57 | public: |
dcheng | ef7721a | 2014-10-22 11:29:52 +0900 | [diff] [blame] | 58 | bool OnMessageReceived(const IPC::Message& message) override { |
brettw | f314620 | 2015-06-03 13:29:25 +0900 | [diff] [blame] | 59 | base::PickleIterator iter(message); |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 60 | base::FileDescriptor descriptor; |
yusukes | f8a5011 | 2015-01-06 15:56:34 +0900 | [diff] [blame] | 61 | while (IPC::ParamTraits<base::FileDescriptor>::Read( |
| 62 | &message, &iter, &descriptor)) { |
| 63 | HandleFD(descriptor.fd); |
| 64 | } |
jam@chromium.org | 8a2c784 | 2010-12-24 15:19:28 +0900 | [diff] [blame] | 65 | return true; |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 66 | } |
| 67 | |
hubbe@chromium.org | 683920d | 2013-10-15 09:07:00 +0900 | [diff] [blame] | 68 | protected: |
| 69 | virtual void HandleFD(int fd) = 0; |
| 70 | }; |
| 71 | |
| 72 | class MyChannelDescriptorListener : public MyChannelDescriptorListenerBase { |
| 73 | public: |
| 74 | explicit MyChannelDescriptorListener(ino_t expected_inode_num) |
| 75 | : MyChannelDescriptorListenerBase(), |
| 76 | expected_inode_num_(expected_inode_num), |
| 77 | num_fds_received_(0) { |
hubbe@chromium.org | 1b503fc | 2013-10-11 06:12:14 +0900 | [diff] [blame] | 78 | } |
| 79 | |
benwells@chromium.org | 6ecd712 | 2013-10-11 13:22:34 +0900 | [diff] [blame] | 80 | bool GotExpectedNumberOfDescriptors() const { |
yusukes | f8a5011 | 2015-01-06 15:56:34 +0900 | [diff] [blame] | 81 | return num_fds_received_ == kNumFDsToSend * kNumMessages; |
hubbe@chromium.org | 1b503fc | 2013-10-11 06:12:14 +0900 | [diff] [blame] | 82 | } |
| 83 | |
dcheng | ef7721a | 2014-10-22 11:29:52 +0900 | [diff] [blame] | 84 | void OnChannelError() override { |
ki.stfu | ad02964 | 2015-10-13 02:26:00 +0900 | [diff] [blame] | 85 | base::MessageLoop::current()->QuitWhenIdle(); |
dcheng | 9b01d24 | 2014-10-22 03:02:42 +0900 | [diff] [blame] | 86 | } |
hubbe@chromium.org | 683920d | 2013-10-15 09:07:00 +0900 | [diff] [blame] | 87 | |
| 88 | protected: |
dcheng | ef7721a | 2014-10-22 11:29:52 +0900 | [diff] [blame] | 89 | void HandleFD(int fd) override { |
yusukes | f8a5011 | 2015-01-06 15:56:34 +0900 | [diff] [blame] | 90 | ASSERT_GE(fd, 0); |
hubbe@chromium.org | 683920d | 2013-10-15 09:07:00 +0900 | [diff] [blame] | 91 | // Check that we can read from the FD. |
| 92 | char buf; |
| 93 | ssize_t amt_read = read(fd, &buf, 1); |
| 94 | ASSERT_EQ(amt_read, 1); |
| 95 | ASSERT_EQ(buf, 0); // /dev/zero always reads 0 bytes. |
| 96 | |
| 97 | struct stat st; |
| 98 | ASSERT_EQ(fstat(fd, &st), 0); |
| 99 | |
| 100 | ASSERT_EQ(close(fd), 0); |
| 101 | |
| 102 | // Compare inode numbers to check that the file sent over the wire is |
| 103 | // actually the one expected. |
| 104 | ASSERT_EQ(expected_inode_num_, st.st_ino); |
| 105 | |
| 106 | ++num_fds_received_; |
yusukes | f8a5011 | 2015-01-06 15:56:34 +0900 | [diff] [blame] | 107 | if (num_fds_received_ == kNumFDsToSend * kNumMessages) |
ki.stfu | ad02964 | 2015-10-13 02:26:00 +0900 | [diff] [blame] | 108 | base::MessageLoop::current()->QuitWhenIdle(); |
hubbe@chromium.org | 683920d | 2013-10-15 09:07:00 +0900 | [diff] [blame] | 109 | } |
| 110 | |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 111 | private: |
| 112 | ino_t expected_inode_num_; |
| 113 | unsigned num_fds_received_; |
| 114 | }; |
| 115 | |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 116 | class IPCSendFdsTest : public IPCChannelMojoTestBase { |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 117 | protected: |
| 118 | void RunServer() { |
| 119 | // Set up IPC channel and start client. |
| 120 | MyChannelDescriptorListener listener(-1); |
| 121 | CreateChannel(&listener); |
| 122 | ASSERT_TRUE(ConnectChannel()); |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 123 | |
yusukes | f8a5011 | 2015-01-06 15:56:34 +0900 | [diff] [blame] | 124 | for (unsigned i = 0; i < kNumMessages; ++i) { |
bbudge@chromium.org | ab4c6bc | 2013-11-05 07:28:12 +0900 | [diff] [blame] | 125 | IPC::Message* message = |
| 126 | new IPC::Message(0, 3, IPC::Message::PRIORITY_NORMAL); |
yusukes | f8a5011 | 2015-01-06 15:56:34 +0900 | [diff] [blame] | 127 | for (unsigned j = 0; j < kNumFDsToSend; ++j) { |
| 128 | const int fd = open(kDevZeroPath, O_RDONLY); |
| 129 | ASSERT_GE(fd, 0); |
| 130 | base::FileDescriptor descriptor(fd, true); |
| 131 | IPC::ParamTraits<base::FileDescriptor>::Write(message, descriptor); |
| 132 | } |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 133 | ASSERT_TRUE(sender()->Send(message)); |
| 134 | } |
| 135 | |
| 136 | // Run message loop. |
fdoray | 284aae5 | 2016-06-23 04:56:16 +0900 | [diff] [blame] | 137 | base::RunLoop().Run(); |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 138 | |
| 139 | // Close the channel so the client's OnChannelError() gets fired. |
| 140 | channel()->Close(); |
| 141 | |
| 142 | EXPECT_TRUE(WaitForClientShutdown()); |
| 143 | DestroyChannel(); |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 144 | } |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 145 | }; |
| 146 | |
amistry | 87fc78f | 2016-05-05 14:12:09 +0900 | [diff] [blame] | 147 | TEST_F(IPCSendFdsTest, DescriptorTest) { |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 148 | Init("SendFdsClient"); |
| 149 | RunServer(); |
| 150 | } |
| 151 | |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 152 | class SendFdsTestClientFixture : public IpcChannelMojoTestClient { |
| 153 | protected: |
| 154 | void SendFdsClientCommon(const std::string& test_client_name, |
| 155 | ino_t expected_inode_num) { |
| 156 | MyChannelDescriptorListener listener(expected_inode_num); |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 157 | |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 158 | // Set up IPC channel. |
| 159 | Connect(&listener); |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 160 | |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 161 | // Run message loop. |
| 162 | base::RunLoop().Run(); |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 163 | |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 164 | // Verify that the message loop was exited due to getting the correct number |
| 165 | // of descriptors, and not because of the channel closing unexpectedly. |
| 166 | EXPECT_TRUE(listener.GotExpectedNumberOfDescriptors()); |
dmaclach@chromium.org | 63b5df7 | 2010-12-09 10:12:20 +0900 | [diff] [blame] | 167 | |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 168 | Close(); |
| 169 | } |
| 170 | }; |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 171 | |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 172 | DEFINE_IPC_CHANNEL_MOJO_TEST_CLIENT_WITH_CUSTOM_FIXTURE( |
| 173 | SendFdsClient, |
| 174 | SendFdsTestClientFixture) { |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 175 | struct stat st; |
| 176 | int fd = open(kDevZeroPath, O_RDONLY); |
| 177 | fstat(fd, &st); |
mark@chromium.org | fa5a0f9 | 2013-12-03 23:10:59 +0900 | [diff] [blame] | 178 | EXPECT_GE(IGNORE_EINTR(close(fd)), 0); |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 179 | SendFdsClientCommon("SendFdsClient", st.st_ino); |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 180 | } |
viettrungluu@chromium.org | 7d86af2 | 2013-01-12 00:13:37 +0900 | [diff] [blame] | 181 | |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 182 | #if defined(OS_MACOSX) |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 183 | // Test that FDs are correctly sent to a sandboxed process. |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 184 | // TODO(port): Make this test cross-platform. |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 185 | TEST_F(IPCSendFdsTest, DescriptorTestSandboxed) { |
| 186 | Init("SendFdsSandboxedClient"); |
| 187 | RunServer(); |
| 188 | } |
| 189 | |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 190 | DEFINE_IPC_CHANNEL_MOJO_TEST_CLIENT_WITH_CUSTOM_FIXTURE( |
| 191 | SendFdsSandboxedClient, |
| 192 | SendFdsTestClientFixture) { |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 193 | struct stat st; |
| 194 | const int fd = open(kDevZeroPath, O_RDONLY); |
| 195 | fstat(fd, &st); |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 196 | ASSERT_LE(0, IGNORE_EINTR(close(fd))); |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 197 | |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 198 | // Enable the sandbox. |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 199 | char* error_buff = NULL; |
kerrnel | 342941a | 2016-09-24 09:39:26 +0900 | [diff] [blame] | 200 | int error = sandbox::Seatbelt::Init( |
| 201 | sandbox::Seatbelt::kProfilePureComputation, SANDBOX_NAMED, &error_buff); |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 202 | ASSERT_EQ(0, error); |
| 203 | ASSERT_FALSE(error_buff); |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 204 | |
kerrnel | f8e810e | 2016-04-13 01:39:06 +0900 | [diff] [blame] | 205 | sandbox::Seatbelt::FreeError(error_buff); |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 206 | |
viettrungluu@chromium.org | 0015594 | 2013-01-26 06:51:35 +0900 | [diff] [blame] | 207 | // Make sure sandbox is really enabled. |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 208 | ASSERT_EQ(-1, open(kDevZeroPath, O_RDONLY)) |
| 209 | << "Sandbox wasn't properly enabled"; |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 210 | |
| 211 | // See if we can receive a file descriptor. |
sammc | e3cae21 | 2016-10-27 19:13:59 +0900 | [diff] [blame] | 212 | SendFdsClientCommon("SendFdsSandboxedClient", st.st_ino); |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 213 | } |
| 214 | #endif // defined(OS_MACOSX) |
| 215 | |
viettrungluu@chromium.org | 7ca1913 | 2013-01-12 05:56:22 +0900 | [diff] [blame] | 216 | } // namespace |
| 217 | |
agl@chromium.org | 1c6dcf2 | 2009-07-23 08:57:21 +0900 | [diff] [blame] | 218 | #endif // defined(OS_POSIX) |