1 // https://github.com/llvm/llvm-project/issues/60678
4 // RUN: %clang_dfsan %s -o %t && DFSAN_OPTIONS="strict_data_dependencies=0" %run %t
5 // RUN: %clang_dfsan -DSTRICT_DATA_DEPENDENCIES %s -o %t && %run %t
6 // RUN: %clang_dfsan -DORIGIN_TRACKING -mllvm -dfsan-track-origins=1 -mllvm -dfsan-combine-pointer-labels-on-load=false -DSTRICT_DATA_DEPENDENCIES %s -o %t && %run %t
7 // RUN: %clang_dfsan -DORIGIN_TRACKING -mllvm -dfsan-track-origins=1 -mllvm -dfsan-combine-pointer-labels-on-load=false %s -o %t && DFSAN_OPTIONS="strict_data_dependencies=0" %run %t
9 // Tests custom implementations of various glibc functions.
11 #pragma clang diagnostic ignored "-Wformat-extra-args"
13 #include <sanitizer/dfsan_interface.h>
15 #include <arpa/inet.h>
29 #include <sys/epoll.h>
30 #include <sys/resource.h>
31 #include <sys/select.h>
32 #include <sys/socket.h>
35 #include <sys/types.h>
39 dfsan_label i_label
= 0;
40 dfsan_label j_label
= 0;
41 dfsan_label k_label
= 0;
42 dfsan_label m_label
= 0;
43 dfsan_label n_label
= 0;
44 dfsan_label i_j_label
= 0;
46 #define ASSERT_ZERO_LABEL(data) \
47 assert(0 == dfsan_get_label((long) (data)))
49 #define ASSERT_READ_ZERO_LABEL(ptr, size) \
50 assert(0 == dfsan_read_label(ptr, size))
52 #define ASSERT_LABEL(data, label) \
53 assert(label == dfsan_get_label((long) (data)))
55 #define ASSERT_READ_LABEL(ptr, size, label) \
56 assert(label == dfsan_read_label(ptr, size))
58 #ifdef ORIGIN_TRACKING
59 #define ASSERT_ZERO_ORIGIN(data) \
60 assert(0 == dfsan_get_origin((long)(data)))
62 #define ASSERT_ZERO_ORIGIN(data)
65 #ifdef ORIGIN_TRACKING
66 #define ASSERT_ZERO_ORIGINS(ptr, size) \
67 for (int i = 0; i < size; ++i) { \
68 assert(0 == dfsan_get_origin((long)(((char *)ptr)[i]))); \
71 #define ASSERT_ZERO_ORIGINS(ptr, size)
74 #ifdef ORIGIN_TRACKING
75 #define ASSERT_ORIGIN(data, origin) \
76 assert(origin == dfsan_get_origin((long)(data)))
78 #define ASSERT_ORIGIN(data, origin)
81 #ifdef ORIGIN_TRACKING
82 #define ASSERT_ORIGINS(ptr, size, origin) \
83 for (int i = 0; i < size; ++i) { \
84 assert(origin == dfsan_get_origin((long)(((char *)ptr)[i]))); \
87 #define ASSERT_ORIGINS(ptr, size, origin)
90 #ifdef ORIGIN_TRACKING
91 #define ASSERT_INIT_ORIGIN(ptr, origin) \
92 assert(origin == dfsan_get_init_origin(ptr))
94 #define ASSERT_INIT_ORIGIN(ptr, origin)
97 #ifdef ORIGIN_TRACKING
98 #define ASSERT_INIT_ORIGIN_EQ_ORIGIN(ptr, data) \
99 assert(dfsan_get_origin((long)(data)) == dfsan_get_init_origin(ptr))
101 #define ASSERT_INIT_ORIGIN_EQ_ORIGIN(ptr, data)
104 #ifdef ORIGIN_TRACKING
105 #define ASSERT_INIT_ORIGINS(ptr, size, origin) \
106 for (int i = 0; i < size; ++i) { \
107 assert(origin == dfsan_get_init_origin(&((char *)ptr)[i])); \
110 #define ASSERT_INIT_ORIGINS(ptr, size, origin)
113 #ifdef ORIGIN_TRACKING
114 #define ASSERT_EQ_ORIGIN(data1, data2) \
115 assert(dfsan_get_origin((long)(data1)) == dfsan_get_origin((long)(data2)))
117 #define ASSERT_EQ_ORIGIN(data1, data2)
120 #ifdef ORIGIN_TRACKING
121 #define DEFINE_AND_SAVE_ORIGINS(val) \
122 dfsan_origin val##_o[sizeof(val)]; \
123 for (int i = 0; i < sizeof(val); ++i) \
124 val##_o[i] = dfsan_get_origin((long)(((char *)(&val))[i]));
126 #define DEFINE_AND_SAVE_ORIGINS(val)
129 #ifdef ORIGIN_TRACKING
130 #define SAVE_ORIGINS(val) \
131 for (int i = 0; i < sizeof(val); ++i) \
132 val##_o[i] = dfsan_get_origin((long)(((char *)(&val))[i]));
134 #define SAVE_ORIGINS(val)
137 #ifdef ORIGIN_TRACKING
138 #define ASSERT_SAVED_ORIGINS(val) \
139 for (int i = 0; i < sizeof(val); ++i) \
140 ASSERT_ORIGIN(((char *)(&val))[i], val##_o[i]);
142 #define ASSERT_SAVED_ORIGINS(val)
145 #ifdef ORIGIN_TRACKING
146 #define DEFINE_AND_SAVE_N_ORIGINS(val, n) \
147 dfsan_origin val##_o[n]; \
148 for (int i = 0; i < n; ++i) \
149 val##_o[i] = dfsan_get_origin((long)(val[i]));
151 #define DEFINE_AND_SAVE_N_ORIGINS(val, n)
154 #ifdef ORIGIN_TRACKING
155 #define ASSERT_SAVED_N_ORIGINS(val, n) \
156 for (int i = 0; i < n; ++i) \
157 ASSERT_ORIGIN(val[i], val##_o[i]);
159 #define ASSERT_SAVED_N_ORIGINS(val, n)
162 #if !defined(__GLIBC_PREREQ)
163 # define __GLIBC_PREREQ(a, b) 0
168 dfsan_set_label(i_label
, &i
, sizeof(i
));
172 DEFINE_AND_SAVE_ORIGINS(s
)
173 int ret
= stat("/", &s
);
175 ASSERT_ZERO_LABEL(ret
);
176 ASSERT_ZERO_LABEL(s
.st_dev
);
177 ASSERT_SAVED_ORIGINS(s
)
181 ret
= stat("/nonexistent", &s
);
183 ASSERT_ZERO_LABEL(ret
);
184 ASSERT_LABEL(s
.st_dev
, i_label
);
185 ASSERT_SAVED_ORIGINS(s
)
190 dfsan_set_label(i_label
, &i
, sizeof(i
));
193 int fd
= open("/dev/zero", O_RDONLY
);
195 DEFINE_AND_SAVE_ORIGINS(s
)
196 int rv
= fstat(fd
, &s
);
198 ASSERT_ZERO_LABEL(rv
);
199 ASSERT_ZERO_LABEL(s
.st_dev
);
200 ASSERT_SAVED_ORIGINS(s
)
204 char str1
[] = "str1", str2
[] = "str2";
205 dfsan_set_label(i_label
, &str1
[3], 1);
206 dfsan_set_label(j_label
, &str2
[3], 1);
208 int rv
= memcmp(str1
, str2
, sizeof(str1
));
210 #ifdef STRICT_DATA_DEPENDENCIES
211 ASSERT_ZERO_LABEL(rv
);
213 ASSERT_LABEL(rv
, i_j_label
);
214 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
217 rv
= memcmp(str1
, str2
, sizeof(str1
) - 2);
219 ASSERT_ZERO_LABEL(rv
);
223 char str1
[] = "str1", str2
[] = "str2";
224 dfsan_set_label(i_label
, &str1
[3], 1);
225 dfsan_set_label(j_label
, &str2
[3], 1);
227 int rv
= bcmp(str1
, str2
, sizeof(str1
));
229 #ifdef STRICT_DATA_DEPENDENCIES
230 ASSERT_ZERO_LABEL(rv
);
232 ASSERT_LABEL(rv
, i_j_label
);
233 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
236 rv
= bcmp(str1
, str2
, sizeof(str1
) - 2);
238 ASSERT_ZERO_LABEL(rv
);
242 char str1
[] = "str1";
243 char str2
[sizeof(str1
)];
244 dfsan_set_label(i_label
, &str1
[3], 1);
246 DEFINE_AND_SAVE_ORIGINS(str1
)
249 dfsan_set_label(j_label
, &ptr2
, sizeof(ptr2
));
251 void *r
= memcpy(ptr2
, str1
, sizeof(str1
));
252 ASSERT_LABEL(r
, j_label
);
253 ASSERT_EQ_ORIGIN(r
, ptr2
);
254 assert(0 == memcmp(str2
, str1
, sizeof(str1
)));
255 ASSERT_ZERO_LABEL(str2
[0]);
256 ASSERT_LABEL(str2
[3], i_label
);
258 for (int i
= 0; i
< sizeof(str2
); ++i
) {
259 if (!dfsan_get_label(str2
[i
]))
261 ASSERT_INIT_ORIGIN(&(str2
[i
]), str1_o
[i
]);
265 void test_memmove() {
266 char str
[] = "str1xx";
267 dfsan_set_label(i_label
, &str
[3], 1);
269 DEFINE_AND_SAVE_ORIGINS(str
)
272 dfsan_set_label(j_label
, &ptr
, sizeof(ptr
));
274 void *r
= memmove(ptr
, str
, 4);
275 ASSERT_LABEL(r
, j_label
);
276 ASSERT_EQ_ORIGIN(r
, ptr
);
277 assert(0 == memcmp(str
+ 2, "str1", 4));
278 ASSERT_ZERO_LABEL(str
[4]);
279 ASSERT_LABEL(str
[5], i_label
);
281 for (int i
= 0; i
< 4; ++i
) {
282 if (!dfsan_get_label(ptr
[i
]))
284 ASSERT_INIT_ORIGIN(&(ptr
[i
]), str_o
[i
]);
292 dfsan_set_label(j_label
, &j
, sizeof(j
));
293 dfsan_set_label(k_label
, &ptr
, sizeof(ptr
));
294 void *ret
= memset(ptr
, j
, sizeof(buf
));
295 ASSERT_LABEL(ret
, k_label
);
296 ASSERT_EQ_ORIGIN(ret
, ptr
);
297 for (int i
= 0; i
< 8; ++i
) {
298 ASSERT_LABEL(buf
[i
], j_label
);
299 ASSERT_EQ_ORIGIN(buf
[i
], j
);
300 assert(buf
[i
] == 'a');
305 char str1
[] = "str1", str2
[] = "str2";
306 dfsan_set_label(i_label
, &str1
[3], 1);
307 dfsan_set_label(j_label
, &str2
[3], 1);
309 int rv
= strcmp(str1
, str2
);
311 #ifdef STRICT_DATA_DEPENDENCIES
312 ASSERT_ZERO_LABEL(rv
);
314 ASSERT_LABEL(rv
, i_j_label
);
315 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
318 rv
= strcmp(str1
, str1
);
320 #ifdef STRICT_DATA_DEPENDENCIES
321 ASSERT_ZERO_LABEL(rv
);
322 ASSERT_ZERO_ORIGIN(rv
);
324 ASSERT_LABEL(rv
, i_label
);
325 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
330 char src
[] = "world";
331 int volatile x
= 0; // buffer to ensure src and dst do not share origins
333 char dst
[] = "hello \0 ";
334 int volatile y
= 0; // buffer to ensure dst and p do not share origins
337 dfsan_set_label(k_label
, &p
, sizeof(p
));
338 dfsan_set_label(i_label
, src
, sizeof(src
));
339 dfsan_set_label(j_label
, dst
, sizeof(dst
));
340 dfsan_origin dst_o
= dfsan_get_origin((long)dst
[0]);
342 char *ret
= strcat(p
, src
);
344 ASSERT_LABEL(ret
, k_label
);
345 ASSERT_EQ_ORIGIN(ret
, p
);
347 assert(strcmp(src
, dst
+ 6) == 0);
348 // Origins are assigned for every 4 contiguous 4-aligned bytes. After
349 // appending src to dst, origins of src can overwrite origins of dst if their
350 // application adddresses are within [start_aligned_down, end_aligned_up).
351 // Other origins are not changed.
352 char *start_aligned_down
= (char *)(((size_t)(dst
+ 6)) & ~3UL);
353 char *end_aligned_up
= (char *)(((size_t)(dst
+ 11 + 4)) & ~3UL);
354 for (int i
= 0; i
< 12; ++i
) {
355 if (dst
+ i
< start_aligned_down
|| dst
+ i
>= end_aligned_up
) {
356 ASSERT_INIT_ORIGIN(&dst
[i
], dst_o
);
358 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&dst
[i
], src
[0]);
361 for (int i
= 0; i
< 6; ++i
) {
362 ASSERT_LABEL(dst
[i
], j_label
);
364 for (int i
= 6; i
< strlen(dst
); ++i
) {
365 ASSERT_LABEL(dst
[i
], i_label
);
366 assert(dfsan_get_label(dst
[i
]) == dfsan_get_label(src
[i
- 6]));
368 ASSERT_LABEL(dst
[11], j_label
);
371 void test_strncat(int n
) {
372 char src
[] = "world";
373 int volatile x
= 0; // buffer to ensure src and dst do not share origins
375 char dst
[] = "hello \0 ";
376 int volatile y
= 0; // buffer to ensure dst and p do not share origins
379 dfsan_set_label(k_label
, &p
, sizeof(p
));
380 dfsan_set_label(i_label
, src
, sizeof(src
));
381 dfsan_set_label(j_label
, dst
, sizeof(dst
));
382 dfsan_origin dst_o
= dfsan_get_origin((long)dst
[0]);
384 char *ret
= strncat(p
, src
, n
);
386 ASSERT_LABEL(ret
, k_label
);
387 ASSERT_EQ_ORIGIN(ret
, p
);
389 assert(strncmp(src
, dst
+ 6, n
) == 0);
390 // Origins are assigned for every 4 contiguous 4-aligned bytes. After
391 // appending src to dst, origins of src can overwrite origins of dst if their
392 // application adddresses are within [start_aligned_down, end_aligned_up).
393 // Other origins are not changed.
398 char *start_aligned_down
= (char *)(((size_t)(dst
+ 6)) & ~3UL);
399 char *end_aligned_up
= (char *)(((size_t)(dst
+ 6 + n
+ pad
)) & ~3UL);
401 for (int i
= 0; i
< 12; ++i
) {
402 if (dst
+ i
< start_aligned_down
|| dst
+ i
>= end_aligned_up
) {
403 ASSERT_INIT_ORIGIN(&dst
[i
], dst_o
);
405 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&dst
[i
], src
[0]);
408 for (int i
= 0; i
< 6; ++i
) {
409 ASSERT_LABEL(dst
[i
], j_label
);
411 for (int i
= 6; i
< 6 + n
; ++i
) {
412 ASSERT_LABEL(dst
[i
], i_label
);
413 assert(dfsan_get_label(dst
[i
]) == dfsan_get_label(src
[i
- 6]));
415 for (int i
= 6 + n
; i
< strlen(dst
); ++i
) {
416 ASSERT_LABEL(dst
[i
], j_label
);
418 ASSERT_LABEL(dst
[11], j_label
);
422 char str1
[] = "str1";
423 dfsan_set_label(i_label
, &str1
[3], 1);
425 int rv
= strlen(str1
);
427 #ifdef STRICT_DATA_DEPENDENCIES
428 ASSERT_ZERO_LABEL(rv
);
430 ASSERT_LABEL(rv
, i_label
);
431 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
435 void test_strnlen() {
436 char str1
[] = "str1";
437 dfsan_set_label(i_label
, &str1
[3], 1);
440 dfsan_set_label(j_label
, &maxlen
, sizeof(maxlen
));
442 int rv
= strnlen(str1
, maxlen
);
444 #ifdef STRICT_DATA_DEPENDENCIES
445 ASSERT_ZERO_LABEL(rv
);
447 ASSERT_LABEL(rv
, dfsan_union(i_label
, j_label
));
448 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
452 dfsan_set_label(j_label
, &maxlen
, sizeof(maxlen
));
453 rv
= strnlen(str1
, maxlen
);
455 #ifdef STRICT_DATA_DEPENDENCIES
456 ASSERT_ZERO_LABEL(rv
);
458 ASSERT_LABEL(rv
, j_label
);
459 ASSERT_EQ_ORIGIN(rv
, maxlen
);
464 char str1
[] = "str1";
465 dfsan_set_label(i_label
, &str1
[3], 1);
466 DEFINE_AND_SAVE_ORIGINS(str1
)
468 char *strd
= strdup(str1
);
469 ASSERT_ZERO_LABEL(strd
);
470 ASSERT_ZERO_LABEL(strd
[0]);
471 ASSERT_LABEL(strd
[3], i_label
);
473 for (int i
= 0; i
< strlen(strd
); ++i
) {
474 if (!dfsan_get_label(strd
[i
]))
476 ASSERT_INIT_ORIGIN(&(strd
[i
]), str1_o
[i
]);
482 void test_strncpy() {
483 char str1
[] = "str1";
484 char str2
[sizeof(str1
)];
485 dfsan_set_label(i_label
, &str1
[3], 1);
487 char *strd
= strncpy(str2
, str1
, 5);
488 assert(strd
== str2
);
489 assert(strcmp(str1
, str2
) == 0);
490 ASSERT_ZERO_LABEL(strd
);
491 ASSERT_ZERO_LABEL(strd
[0]);
492 ASSERT_ZERO_LABEL(strd
[1]);
493 ASSERT_ZERO_LABEL(strd
[2]);
494 ASSERT_LABEL(strd
[3], i_label
);
495 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&(strd
[3]), str1
[3]);
498 dfsan_set_label(j_label
, &p2
, sizeof(p2
));
499 strd
= strncpy(p2
, str1
, 3);
500 assert(strd
== str2
);
501 assert(strncmp(str1
, str2
, 3) == 0);
502 ASSERT_LABEL(strd
, j_label
);
503 ASSERT_EQ_ORIGIN(strd
, p2
);
504 // When -dfsan-combine-pointer-labels-on-load is on, strd's label propagates
505 // to strd[i]'s label. When ORIGIN_TRACKING is defined,
506 // -dfsan-combine-pointer-labels-on-load is always off, otherwise the flag
508 #if defined(ORIGIN_TRACKING)
509 ASSERT_ZERO_LABEL(strd
[0]);
510 ASSERT_ZERO_LABEL(strd
[1]);
511 ASSERT_ZERO_LABEL(strd
[2]);
513 ASSERT_LABEL(strd
[0], j_label
);
514 ASSERT_LABEL(strd
[1], j_label
);
515 ASSERT_LABEL(strd
[2], j_label
);
519 void test_strncmp() {
520 char str1
[] = "str1", str2
[] = "str2";
521 dfsan_set_label(i_label
, &str1
[3], 1);
522 dfsan_set_label(j_label
, &str2
[3], 1);
524 int rv
= strncmp(str1
, str2
, sizeof(str1
));
526 #ifdef STRICT_DATA_DEPENDENCIES
527 ASSERT_ZERO_LABEL(rv
);
529 ASSERT_LABEL(rv
, dfsan_union(i_label
, j_label
));
530 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
533 rv
= strncmp(str1
, str2
, 0);
535 ASSERT_ZERO_LABEL(rv
);
537 rv
= strncmp(str1
, str2
, 3);
539 ASSERT_ZERO_LABEL(rv
);
541 rv
= strncmp(str1
, str1
, 4);
543 #ifdef STRICT_DATA_DEPENDENCIES
544 ASSERT_ZERO_LABEL(rv
);
546 ASSERT_LABEL(rv
, i_label
);
547 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
551 void test_strcasecmp() {
552 char str1
[] = "str1", str2
[] = "str2", str3
[] = "Str1";
553 dfsan_set_label(i_label
, &str1
[3], 1);
554 dfsan_set_label(j_label
, &str2
[3], 1);
555 dfsan_set_label(j_label
, &str3
[2], 1);
557 int rv
= strcasecmp(str1
, str2
);
559 #ifdef STRICT_DATA_DEPENDENCIES
560 ASSERT_ZERO_LABEL(rv
);
562 ASSERT_LABEL(rv
, dfsan_union(i_label
, j_label
));
563 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
566 rv
= strcasecmp(str1
, str3
);
568 #ifdef STRICT_DATA_DEPENDENCIES
569 ASSERT_ZERO_LABEL(rv
);
571 ASSERT_LABEL(rv
, dfsan_union(i_label
, j_label
));
572 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
577 dfsan_set_label(i_label
, &s1
[2], 1);
578 dfsan_set_label(j_label
, &s2
[2], 1);
580 rv
= strcasecmp(s1
, s2
);
581 assert(rv
> 0); // 'Z' > 'y'
582 #ifdef STRICT_DATA_DEPENDENCIES
583 ASSERT_ZERO_LABEL(rv
);
585 ASSERT_LABEL(rv
, dfsan_union(i_label
, j_label
));
586 ASSERT_EQ_ORIGIN(rv
, s1
[2]);
590 void test_strncasecmp() {
591 char str1
[] = "Str1", str2
[] = "str2";
592 dfsan_set_label(i_label
, &str1
[3], 1);
593 dfsan_set_label(j_label
, &str2
[3], 1);
595 int rv
= strncasecmp(str1
, str2
, sizeof(str1
));
597 #ifdef STRICT_DATA_DEPENDENCIES
598 ASSERT_ZERO_LABEL(rv
);
600 ASSERT_LABEL(rv
, dfsan_union(i_label
, j_label
));
601 ASSERT_EQ_ORIGIN(rv
, str1
[3]);
604 rv
= strncasecmp(str1
, str2
, 3);
606 ASSERT_ZERO_LABEL(rv
);
610 dfsan_set_label(i_label
, &s1
[2], 1);
611 dfsan_set_label(j_label
, &s2
[2], 1);
613 rv
= strncasecmp(s1
, s2
, 0);
614 assert(rv
== 0); // Compare zero chars.
615 ASSERT_ZERO_LABEL(rv
);
617 rv
= strncasecmp(s1
, s2
, 1);
618 assert(rv
== 0); // 'A' == 'a'
619 ASSERT_ZERO_LABEL(rv
);
621 rv
= strncasecmp(s1
, s2
, 2);
622 assert(rv
== 0); // 'b' == 'B'
623 ASSERT_ZERO_LABEL(rv
);
625 rv
= strncasecmp(s1
, s2
, 3);
626 assert(rv
> 0); // 'Z' > 'y'
627 #ifdef STRICT_DATA_DEPENDENCIES
628 ASSERT_ZERO_LABEL(rv
);
630 ASSERT_LABEL(rv
, dfsan_union(i_label
, j_label
));
631 ASSERT_EQ_ORIGIN(rv
, s1
[2]);
636 char str1
[] = "str1";
637 dfsan_set_label(i_label
, &str1
[3], 1);
641 dfsan_set_label(k_label
, &c
, sizeof(c
));
643 char *crv
= strchr(p1
, c
);
644 assert(crv
== &str1
[2]);
645 #ifdef STRICT_DATA_DEPENDENCIES
646 ASSERT_ZERO_LABEL(crv
);
648 ASSERT_LABEL(crv
, k_label
);
649 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&crv
, c
);
652 dfsan_set_label(j_label
, &p1
, sizeof(p1
));
653 crv
= strchr(p1
, 'r');
654 assert(crv
== &str1
[2]);
655 ASSERT_LABEL(crv
, j_label
);
656 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&crv
, p1
);
658 crv
= strchr(p1
, '1');
659 assert(crv
== &str1
[3]);
660 #ifdef STRICT_DATA_DEPENDENCIES
661 ASSERT_LABEL(crv
, j_label
);
662 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&crv
, p1
);
664 ASSERT_LABEL(crv
, i_j_label
);
665 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&crv
, str1
[3]);
668 crv
= strchr(p1
, 'x');
670 #ifdef STRICT_DATA_DEPENDENCIES
671 ASSERT_LABEL(crv
, j_label
);
672 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&crv
, p1
);
674 ASSERT_LABEL(crv
, i_j_label
);
675 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&crv
, str1
[3]);
678 // `man strchr` says:
679 // The terminating null byte is considered part of the string, so that if c
680 // is specified as '\0', these functions return a pointer to the terminator.
681 crv
= strchr(p1
, '\0');
682 assert(crv
== &str1
[4]);
683 #ifdef STRICT_DATA_DEPENDENCIES
684 ASSERT_LABEL(crv
, j_label
);
685 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&crv
, p1
);
687 ASSERT_LABEL(crv
, i_j_label
);
688 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&crv
, str1
[3]);
692 void test_recvmmsg() {
694 int ret
= socketpair(AF_UNIX
, SOCK_DGRAM
, 0, sockfds
);
697 // Setup messages to send.
698 struct mmsghdr smmsg
[2] = {};
699 char sbuf0
[] = "abcdefghijkl";
700 struct iovec siov0
[2] = {{&sbuf0
[0], 4}, {&sbuf0
[4], 4}};
701 smmsg
[0].msg_hdr
.msg_iov
= siov0
;
702 smmsg
[0].msg_hdr
.msg_iovlen
= 2;
703 char sbuf1
[] = "1234567890";
704 struct iovec siov1
[1] = {{&sbuf1
[0], 7}};
705 smmsg
[1].msg_hdr
.msg_iov
= siov1
;
706 smmsg
[1].msg_hdr
.msg_iovlen
= 1;
709 int sent_msgs
= sendmmsg(sockfds
[0], smmsg
, 2, 0);
710 assert(sent_msgs
== 2);
712 // Setup receive buffers.
713 struct mmsghdr rmmsg
[2] = {};
715 struct iovec riov0
[2] = {{&rbuf0
[0], 4}, {&rbuf0
[4], 4}};
716 rmmsg
[0].msg_hdr
.msg_iov
= riov0
;
717 rmmsg
[0].msg_hdr
.msg_iovlen
= 2;
719 struct iovec riov1
[1] = {{&rbuf1
[0], 16}};
720 rmmsg
[1].msg_hdr
.msg_iov
= riov1
;
721 rmmsg
[1].msg_hdr
.msg_iovlen
= 1;
722 struct timespec timeout
= {1, 1};
723 dfsan_set_label(i_label
, rbuf0
, sizeof(rbuf0
));
724 dfsan_set_label(i_label
, rbuf1
, sizeof(rbuf1
));
725 dfsan_set_label(i_label
, &rmmsg
[0].msg_len
, sizeof(rmmsg
[0].msg_len
));
726 dfsan_set_label(i_label
, &rmmsg
[1].msg_len
, sizeof(rmmsg
[1].msg_len
));
727 dfsan_set_label(i_label
, &timeout
, sizeof(timeout
));
729 dfsan_origin msg_len0_o
= dfsan_get_origin((long)(rmmsg
[0].msg_len
));
730 dfsan_origin msg_len1_o
= dfsan_get_origin((long)(rmmsg
[1].msg_len
));
731 #ifndef ORIGIN_TRACKING
736 // Receive messages and check labels.
737 int received_msgs
= recvmmsg(sockfds
[1], rmmsg
, 2, 0, &timeout
);
738 assert(received_msgs
== sent_msgs
);
739 assert(rmmsg
[0].msg_len
== smmsg
[0].msg_len
);
740 assert(rmmsg
[1].msg_len
== smmsg
[1].msg_len
);
741 assert(memcmp(sbuf0
, rbuf0
, 8) == 0);
742 assert(memcmp(sbuf1
, rbuf1
, 7) == 0);
743 ASSERT_ZERO_LABEL(received_msgs
);
744 ASSERT_ZERO_LABEL(rmmsg
[0].msg_len
);
745 ASSERT_ZERO_LABEL(rmmsg
[1].msg_len
);
746 ASSERT_READ_ZERO_LABEL(&rbuf0
[0], 8);
747 ASSERT_READ_LABEL(&rbuf0
[8], 1, i_label
);
748 ASSERT_READ_ZERO_LABEL(&rbuf1
[0], 7);
749 ASSERT_READ_LABEL(&rbuf1
[7], 1, i_label
);
750 ASSERT_LABEL(timeout
.tv_sec
, i_label
);
751 ASSERT_LABEL(timeout
.tv_nsec
, i_label
);
753 ASSERT_ORIGIN((long)(rmmsg
[0].msg_len
), msg_len0_o
);
754 ASSERT_ORIGIN((long)(rmmsg
[1].msg_len
), msg_len1_o
);
760 void test_recvmsg() {
762 int ret
= socketpair(AF_UNIX
, SOCK_DGRAM
, 0, sockfds
);
765 char sbuf
[] = "abcdefghijkl";
766 struct iovec siovs
[2] = {{&sbuf
[0], 4}, {&sbuf
[4], 4}};
767 struct msghdr smsg
= {};
768 smsg
.msg_iov
= siovs
;
771 ssize_t sent
= sendmsg(sockfds
[0], &smsg
, 0);
775 struct iovec riovs
[2] = {{&rbuf
[0], 4}, {&rbuf
[4], 4}};
776 struct msghdr rmsg
= {};
777 rmsg
.msg_iov
= riovs
;
780 dfsan_set_label(i_label
, rbuf
, sizeof(rbuf
));
781 dfsan_set_label(i_label
, &rmsg
, sizeof(rmsg
));
783 DEFINE_AND_SAVE_ORIGINS(rmsg
)
785 ssize_t received
= recvmsg(sockfds
[1], &rmsg
, 0);
786 assert(received
== sent
);
787 assert(memcmp(sbuf
, rbuf
, 8) == 0);
788 ASSERT_ZERO_LABEL(received
);
789 ASSERT_READ_ZERO_LABEL(&rmsg
, sizeof(rmsg
));
790 ASSERT_READ_ZERO_LABEL(&rbuf
[0], 8);
791 ASSERT_READ_LABEL(&rbuf
[8], 1, i_label
);
793 ASSERT_SAVED_ORIGINS(rmsg
)
801 dfsan_set_label(i_label
, buf
, 1);
802 dfsan_set_label(j_label
, buf
+ 15, 1);
804 DEFINE_AND_SAVE_ORIGINS(buf
)
805 ASSERT_LABEL(buf
[0], i_label
);
806 ASSERT_LABEL(buf
[15], j_label
);
808 int fd
= open("/dev/zero", O_RDONLY
);
809 int rv
= read(fd
, buf
, sizeof(buf
));
810 assert(rv
== sizeof(buf
));
811 ASSERT_ZERO_LABEL(rv
);
812 ASSERT_ZERO_LABEL(buf
[0]);
813 ASSERT_ZERO_LABEL(buf
[15]);
814 ASSERT_SAVED_ORIGINS(buf
)
820 dfsan_set_label(i_label
, buf
, 1);
821 dfsan_set_label(j_label
, buf
+ 15, 1);
823 DEFINE_AND_SAVE_ORIGINS(buf
)
824 ASSERT_LABEL(buf
[0], i_label
);
825 ASSERT_LABEL(buf
[15], j_label
);
827 int fd
= open("/bin/sh", O_RDONLY
);
828 int rv
= pread(fd
, buf
, sizeof(buf
), 0);
829 assert(rv
== sizeof(buf
));
830 ASSERT_ZERO_LABEL(rv
);
831 ASSERT_ZERO_LABEL(buf
[0]);
832 ASSERT_ZERO_LABEL(buf
[15]);
833 ASSERT_SAVED_ORIGINS(buf
)
838 void *map
= dlopen(NULL
, RTLD_NOW
);
840 ASSERT_ZERO_LABEL(map
);
842 map
= dlopen("/nonexistent", RTLD_NOW
);
844 ASSERT_ZERO_LABEL(map
);
847 void test_clock_gettime() {
849 dfsan_set_label(j_label
, ((char *)&tp
) + 3, 1);
850 dfsan_origin origin
= dfsan_get_origin((long)(((char *)&tp
)[3]));
851 #ifndef ORIGIN_TRACKING
854 int t
= clock_gettime(CLOCK_REALTIME
, &tp
);
856 ASSERT_ZERO_LABEL(t
);
857 ASSERT_ZERO_LABEL(((char *)&tp
)[3]);
858 ASSERT_ORIGIN(((char *)&tp
)[3], origin
);
861 void test_ctime_r() {
862 char *buf
= (char*) malloc(64);
865 DEFINE_AND_SAVE_ORIGINS(buf
)
866 dfsan_origin t_o
= dfsan_get_origin((long)t
);
868 char *ret
= ctime_r(&t
, buf
);
869 ASSERT_ZERO_LABEL(ret
);
871 ASSERT_READ_ZERO_LABEL(buf
, strlen(buf
) + 1);
872 ASSERT_SAVED_ORIGINS(buf
)
874 dfsan_set_label(i_label
, &t
, sizeof(t
));
875 t_o
= dfsan_get_origin((long)t
);
876 ret
= ctime_r(&t
, buf
);
877 ASSERT_ZERO_LABEL(ret
);
878 ASSERT_READ_LABEL(buf
, strlen(buf
) + 1, i_label
);
879 for (int i
= 0; i
< strlen(buf
) + 1; ++i
)
880 ASSERT_ORIGIN(buf
[i
], t_o
);
883 dfsan_set_label(j_label
, &buf
, sizeof(&buf
));
884 dfsan_origin buf_ptr_o
= dfsan_get_origin((long)buf
);
885 #ifndef ORIGIN_TRACKING
888 ret
= ctime_r(&t
, buf
);
889 ASSERT_LABEL(ret
, j_label
);
890 ASSERT_ORIGIN(ret
, buf_ptr_o
);
891 ASSERT_READ_ZERO_LABEL(buf
, strlen(buf
) + 1);
892 for (int i
= 0; i
< strlen(buf
) + 1; ++i
)
893 ASSERT_ORIGIN(buf
[i
], t_o
);
896 static int write_callback_count
= 0;
898 static const unsigned char *last_buf
;
899 static size_t last_count
;
901 void write_callback(int fd
, const void *buf
, size_t count
) {
902 write_callback_count
++;
905 last_buf
= (const unsigned char*) buf
;
909 void test_dfsan_set_write_callback() {
910 char a_buf
[] = "Sample chars";
911 int a_buf_len
= strlen(a_buf
);
913 int fd
= open("/dev/null", O_WRONLY
);
915 dfsan_set_write_callback(write_callback
);
917 write_callback_count
= 0;
919 DEFINE_AND_SAVE_ORIGINS(a_buf
)
921 // Callback should be invoked on every call to write().
922 int res
= write(fd
, a_buf
, a_buf_len
);
923 assert(write_callback_count
== 1);
924 ASSERT_READ_ZERO_LABEL(&res
, sizeof(res
));
925 ASSERT_READ_ZERO_LABEL(&last_fd
, sizeof(last_fd
));
926 ASSERT_READ_ZERO_LABEL(last_buf
, sizeof(last_buf
));
928 for (int i
= 0; i
< a_buf_len
; ++i
)
929 ASSERT_ORIGIN(last_buf
[i
], a_buf_o
[i
]);
931 ASSERT_ZERO_ORIGINS(&last_count
, sizeof(last_count
));
936 char b_buf
[] = "Other chars";
937 int b_buf_len
= strlen(b_buf
);
938 // Create a separate variable so we can taint the pointer.
939 // We would always get a shadow of 0 for b_buf because it is a constant.
940 const unsigned char *buf
= (const unsigned char *)b_buf
;
942 // Add a label to write() arguments. Check that the labels are readable from
943 // the values passed to the callback.
944 dfsan_set_label(i_label
, &fd
, sizeof(fd
));
945 dfsan_set_label(j_label
, &buf
, sizeof(buf
)); // ptr
946 dfsan_set_label(k_label
, &(b_buf
[3]), 1); // content
947 dfsan_set_label(m_label
, &b_buf_len
, sizeof(b_buf_len
));
949 dfsan_origin fd_o
= dfsan_get_origin((long)fd
);
950 dfsan_origin b_buf3_o
= dfsan_get_origin((long)(b_buf
[3]));
951 dfsan_origin b_buf_len_o
= dfsan_get_origin((long)b_buf_len
);
952 #ifndef ORIGIN_TRACKING
957 DEFINE_AND_SAVE_ORIGINS(b_buf
)
959 res
= write(fd
, buf
, b_buf_len
);
960 assert(write_callback_count
== 2);
961 assert(last_fd
== fd
);
962 assert(last_buf
== (const unsigned char *)b_buf
);
963 assert(last_count
== b_buf_len
);
965 ASSERT_READ_ZERO_LABEL(&res
, sizeof(res
));
966 ASSERT_READ_LABEL(&last_fd
, sizeof(last_fd
), i_label
);
967 ASSERT_READ_LABEL(&last_buf
, sizeof(&last_buf
), j_label
); // ptr
968 ASSERT_READ_LABEL(last_buf
, last_count
, k_label
); // content
969 ASSERT_READ_LABEL(&last_buf
[3], sizeof(last_buf
[3]), k_label
); // content
970 ASSERT_READ_LABEL(&last_count
, sizeof(last_count
), m_label
);
971 ASSERT_ZERO_ORIGINS(&res
, sizeof(res
));
972 ASSERT_INIT_ORIGINS(&last_fd
, sizeof(last_fd
), fd_o
);
973 ASSERT_INIT_ORIGINS(&last_buf
[3], sizeof(last_buf
[3]), b_buf3_o
);
975 // Origins are assigned for every 4 contiguous 4-aligned bytes. After
976 // appending src to dst, origins of src can overwrite origins of dst if their
977 // application adddresses are within an aligned range. Other origins are not
979 for (int i
= 0; i
< b_buf_len
; ++i
) {
980 size_t i_addr
= size_t(&last_buf
[i
]);
981 if (((size_t(&last_buf
[3]) & ~3UL) > i_addr
) ||
982 (((size_t(&last_buf
[3]) + 4) & ~3UL) <= i_addr
))
983 ASSERT_ORIGIN(last_buf
[i
], b_buf_o
[i
]);
986 ASSERT_INIT_ORIGINS(&last_count
, sizeof(last_count
), b_buf_len_o
);
988 dfsan_set_write_callback(NULL
);
992 char *buf
= (char*) malloc(128);
993 FILE *f
= fopen("/etc/passwd", "r");
994 dfsan_set_label(j_label
, buf
, 1);
995 DEFINE_AND_SAVE_N_ORIGINS(buf
, 128)
997 char *ret
= fgets(buf
, sizeof(buf
), f
);
999 ASSERT_ZERO_LABEL(ret
);
1000 ASSERT_EQ_ORIGIN(ret
, buf
);
1001 ASSERT_READ_ZERO_LABEL(buf
, 128);
1002 ASSERT_SAVED_N_ORIGINS(buf
, 128)
1004 dfsan_set_label(j_label
, &buf
, sizeof(&buf
));
1005 ret
= fgets(buf
, sizeof(buf
), f
);
1006 ASSERT_LABEL(ret
, j_label
);
1007 ASSERT_EQ_ORIGIN(ret
, buf
);
1008 ASSERT_SAVED_N_ORIGINS(buf
, 128)
1014 void test_getcwd() {
1017 dfsan_set_label(i_label
, buf
+ 2, 2);
1018 DEFINE_AND_SAVE_ORIGINS(buf
)
1020 char* ret
= getcwd(buf
, sizeof(buf
));
1022 assert(ret
[0] == '/');
1023 ASSERT_ZERO_LABEL(ret
);
1024 ASSERT_EQ_ORIGIN(ret
, buf
);
1025 ASSERT_READ_ZERO_LABEL(buf
+ 2, 2);
1026 ASSERT_SAVED_ORIGINS(buf
)
1028 dfsan_set_label(i_label
, &ptr
, sizeof(ptr
));
1029 ret
= getcwd(ptr
, sizeof(buf
));
1030 ASSERT_LABEL(ret
, i_label
);
1031 ASSERT_EQ_ORIGIN(ret
, ptr
);
1032 ASSERT_SAVED_ORIGINS(buf
)
1035 void test_get_current_dir_name() {
1036 char* ret
= get_current_dir_name();
1038 assert(ret
[0] == '/');
1039 ASSERT_READ_ZERO_LABEL(ret
, strlen(ret
) + 1);
1040 ASSERT_ZERO_LABEL(ret
);
1043 void test_getentropy() {
1045 dfsan_set_label(i_label
, buf
+ 2, 2);
1046 DEFINE_AND_SAVE_ORIGINS(buf
)
1047 #if __GLIBC_PREREQ(2, 25)
1048 // glibc >= 2.25 has getentropy()
1049 int ret
= getentropy(buf
, sizeof(buf
));
1050 ASSERT_ZERO_LABEL(ret
);
1052 ASSERT_READ_ZERO_LABEL(buf
+ 2, 2);
1053 ASSERT_SAVED_ORIGINS(buf
)
1058 void test_gethostname() {
1060 dfsan_set_label(i_label
, buf
+ 2, 2);
1061 DEFINE_AND_SAVE_ORIGINS(buf
)
1062 int ret
= gethostname(buf
, sizeof(buf
));
1064 ASSERT_ZERO_LABEL(ret
);
1065 ASSERT_READ_ZERO_LABEL(buf
+ 2, 2);
1066 ASSERT_SAVED_ORIGINS(buf
)
1069 void test_getrlimit() {
1071 dfsan_set_label(i_label
, &rlim
, sizeof(rlim
));
1072 DEFINE_AND_SAVE_ORIGINS(rlim
);
1073 int ret
= getrlimit(RLIMIT_CPU
, &rlim
);
1075 ASSERT_ZERO_LABEL(ret
);
1076 ASSERT_READ_ZERO_LABEL(&rlim
, sizeof(rlim
));
1077 ASSERT_SAVED_ORIGINS(rlim
)
1080 void test_getrusage() {
1081 struct rusage usage
;
1082 dfsan_set_label(i_label
, &usage
, sizeof(usage
));
1083 DEFINE_AND_SAVE_ORIGINS(usage
);
1084 int ret
= getrusage(RUSAGE_SELF
, &usage
);
1086 ASSERT_ZERO_LABEL(ret
);
1087 ASSERT_READ_ZERO_LABEL(&usage
, sizeof(usage
));
1088 ASSERT_SAVED_ORIGINS(usage
)
1091 void test_strcpy() {
1092 char src
[] = "hello world";
1093 char dst
[sizeof(src
) + 2];
1095 dfsan_set_label(0, src
, sizeof(src
));
1096 dfsan_set_label(0, dst
, sizeof(dst
));
1097 dfsan_set_label(k_label
, &p_dst
, sizeof(p_dst
));
1098 dfsan_set_label(i_label
, src
+ 2, 1);
1099 dfsan_set_label(j_label
, src
+ 3, 1);
1100 dfsan_set_label(j_label
, dst
+ 4, 1);
1101 dfsan_set_label(i_label
, dst
+ 12, 1);
1102 char *ret
= strcpy(p_dst
, src
);
1104 assert(strcmp(src
, dst
) == 0);
1105 ASSERT_LABEL(ret
, k_label
);
1106 ASSERT_EQ_ORIGIN(ret
, p_dst
);
1107 for (int i
= 0; i
< strlen(src
) + 1; ++i
) {
1108 assert(dfsan_get_label(dst
[i
]) == dfsan_get_label(src
[i
]));
1109 if (dfsan_get_label(dst
[i
]))
1110 assert(dfsan_get_init_origin(&dst
[i
]) == dfsan_get_origin(src
[i
]));
1112 // Note: if strlen(src) + 1 were used instead to compute the first untouched
1113 // byte of dest, the label would be I|J. This is because strlen() might
1114 // return a non-zero label, and because by default pointer labels are not
1115 // ignored on loads.
1116 ASSERT_LABEL(dst
[12], i_label
);
1119 void test_strtol() {
1120 char non_number_buf
[] = "ab ";
1121 char *endptr
= NULL
;
1122 long int ret
= strtol(non_number_buf
, &endptr
, 10);
1124 assert(endptr
== non_number_buf
);
1125 ASSERT_ZERO_LABEL(ret
);
1127 char buf
[] = "1234578910";
1129 dfsan_set_label(k_label
, &base
, sizeof(base
));
1130 ret
= strtol(buf
, &endptr
, base
);
1131 assert(ret
== 1234578910);
1132 assert(endptr
== buf
+ 10);
1133 ASSERT_LABEL(ret
, k_label
);
1134 ASSERT_EQ_ORIGIN(ret
, base
);
1136 dfsan_set_label(i_label
, buf
+ 1, 1);
1137 dfsan_set_label(j_label
, buf
+ 10, 1);
1138 ret
= strtol(buf
, &endptr
, 10);
1139 assert(ret
== 1234578910);
1140 assert(endptr
== buf
+ 10);
1141 ASSERT_LABEL(ret
, i_j_label
);
1142 ASSERT_EQ_ORIGIN(ret
, buf
[1]);
1145 void test_strtoll() {
1146 char non_number_buf
[] = "ab ";
1147 char *endptr
= NULL
;
1148 long long int ret
= strtoll(non_number_buf
, &endptr
, 10);
1150 assert(endptr
== non_number_buf
);
1151 ASSERT_ZERO_LABEL(ret
);
1153 char buf
[] = "1234578910 ";
1155 dfsan_set_label(k_label
, &base
, sizeof(base
));
1156 ret
= strtoll(buf
, &endptr
, base
);
1157 assert(ret
== 1234578910);
1158 assert(endptr
== buf
+ 10);
1159 ASSERT_LABEL(ret
, k_label
);
1160 ASSERT_EQ_ORIGIN(ret
, base
);
1162 dfsan_set_label(i_label
, buf
+ 1, 1);
1163 dfsan_set_label(j_label
, buf
+ 2, 1);
1164 ret
= strtoll(buf
, &endptr
, 10);
1165 assert(ret
== 1234578910);
1166 assert(endptr
== buf
+ 10);
1167 ASSERT_LABEL(ret
, i_j_label
);
1168 ASSERT_EQ_ORIGIN(ret
, buf
[1]);
1171 void test_strtoul() {
1172 char non_number_buf
[] = "xy ";
1173 char *endptr
= NULL
;
1174 long unsigned int ret
= strtoul(non_number_buf
, &endptr
, 16);
1176 assert(endptr
== non_number_buf
);
1177 ASSERT_ZERO_LABEL(ret
);
1179 char buf
[] = "ffffffffffffaa";
1181 dfsan_set_label(k_label
, &base
, sizeof(base
));
1182 ret
= strtoul(buf
, &endptr
, base
);
1183 assert(ret
== 72057594037927850);
1184 assert(endptr
== buf
+ 14);
1185 ASSERT_LABEL(ret
, k_label
);
1186 ASSERT_EQ_ORIGIN(ret
, base
);
1188 dfsan_set_label(i_label
, buf
+ 1, 1);
1189 dfsan_set_label(j_label
, buf
+ 2, 1);
1190 ret
= strtoul(buf
, &endptr
, 16);
1191 assert(ret
== 72057594037927850);
1192 assert(endptr
== buf
+ 14);
1193 ASSERT_LABEL(ret
, i_j_label
);
1194 ASSERT_EQ_ORIGIN(ret
, buf
[1]);
1197 void test_strtoull() {
1198 char non_number_buf
[] = "xy ";
1199 char *endptr
= NULL
;
1200 long long unsigned int ret
= strtoull(non_number_buf
, &endptr
, 16);
1202 assert(endptr
== non_number_buf
);
1203 ASSERT_ZERO_LABEL(ret
);
1205 char buf
[] = "ffffffffffffffaa";
1207 dfsan_set_label(k_label
, &base
, sizeof(base
));
1208 ret
= strtoull(buf
, &endptr
, base
);
1209 assert(ret
== 0xffffffffffffffaa);
1210 assert(endptr
== buf
+ 16);
1211 ASSERT_LABEL(ret
, k_label
);
1212 ASSERT_EQ_ORIGIN(ret
, base
);
1214 dfsan_set_label(i_label
, buf
+ 1, 1);
1215 dfsan_set_label(j_label
, buf
+ 2, 1);
1216 ret
= strtoull(buf
, &endptr
, 16);
1217 assert(ret
== 0xffffffffffffffaa);
1218 assert(endptr
== buf
+ 16);
1219 ASSERT_LABEL(ret
, i_j_label
);
1220 ASSERT_EQ_ORIGIN(ret
, buf
[1]);
1223 void test_strtod() {
1224 char non_number_buf
[] = "ab ";
1225 char *endptr
= NULL
;
1226 double ret
= strtod(non_number_buf
, &endptr
);
1228 assert(endptr
== non_number_buf
);
1229 ASSERT_ZERO_LABEL(ret
);
1231 char buf
[] = "12345.76 foo";
1232 dfsan_set_label(i_label
, buf
+ 1, 1);
1233 dfsan_set_label(j_label
, buf
+ 6, 1);
1234 ret
= strtod(buf
, &endptr
);
1235 assert(ret
== 12345.76);
1236 assert(endptr
== buf
+ 8);
1237 ASSERT_LABEL(ret
, i_j_label
);
1238 ASSERT_EQ_ORIGIN(ret
, buf
[1]);
1243 dfsan_set_label(i_label
, &t
, 1);
1244 DEFINE_AND_SAVE_ORIGINS(t
)
1245 time_t ret
= time(&t
);
1248 ASSERT_ZERO_LABEL(ret
);
1249 ASSERT_ZERO_LABEL(t
);
1250 ASSERT_SAVED_ORIGINS(t
)
1253 void test_inet_pton() {
1254 char addr4
[] = "127.0.0.1";
1255 dfsan_set_label(i_label
, addr4
+ 3, 1);
1257 int ret4
= inet_pton(AF_INET
, addr4
, &in4
);
1259 ASSERT_ZERO_LABEL(ret4
);
1260 ASSERT_READ_LABEL(&in4
, sizeof(in4
), i_label
);
1261 ASSERT_ORIGINS(&in4
, sizeof(in4
), dfsan_get_origin((long)(addr4
[3])))
1262 assert(in4
.s_addr
== htonl(0x7f000001));
1264 char addr6
[] = "::1";
1265 dfsan_set_label(j_label
, addr6
+ 3, 1);
1266 struct in6_addr in6
;
1267 int ret6
= inet_pton(AF_INET6
, addr6
, &in6
);
1269 ASSERT_ZERO_LABEL(ret6
);
1270 ASSERT_READ_LABEL(((char *) &in6
) + sizeof(in6
) - 1, 1, j_label
);
1271 ASSERT_ORIGINS(&in6
, sizeof(in6
), dfsan_get_origin((long)(addr6
[3])))
1274 void test_localtime_r() {
1275 time_t t0
= 1384800998;
1277 dfsan_set_label(i_label
, &t0
, sizeof(t0
));
1278 dfsan_origin t0_o
= dfsan_get_origin((long)t0
);
1279 struct tm
*pt1
= &t1
;
1280 dfsan_set_label(j_label
, &pt1
, sizeof(pt1
));
1281 dfsan_origin pt1_o
= dfsan_get_origin((long)pt1
);
1283 #ifndef ORIGIN_TRACKING
1288 struct tm
*ret
= localtime_r(&t0
, pt1
);
1290 assert(t1
.tm_min
== 56);
1291 ASSERT_LABEL(ret
, j_label
);
1292 ASSERT_INIT_ORIGIN(&ret
, pt1_o
);
1293 ASSERT_READ_LABEL(&ret
, sizeof(ret
), j_label
);
1294 ASSERT_LABEL(t1
.tm_mon
, i_label
);
1295 ASSERT_ORIGIN(t1
.tm_mon
, t0_o
);
1298 void test_getpwuid_r() {
1301 struct passwd
*result
;
1303 dfsan_set_label(i_label
, &pwd
, 4);
1304 DEFINE_AND_SAVE_ORIGINS(pwd
)
1305 DEFINE_AND_SAVE_ORIGINS(buf
)
1306 int ret
= getpwuid_r(0, &pwd
, buf
, sizeof(buf
), &result
);
1308 assert(strcmp(pwd
.pw_name
, "root") == 0);
1309 assert(result
== &pwd
);
1310 ASSERT_ZERO_LABEL(ret
);
1311 ASSERT_READ_ZERO_LABEL(&pwd
, 4);
1312 ASSERT_SAVED_ORIGINS(pwd
)
1313 ASSERT_SAVED_ORIGINS(buf
)
1316 void test_epoll_wait() {
1317 // Set up a pipe to monitor with epoll.
1319 int ret
= pipe(pipe_fds
);
1322 // Configure epoll to monitor the pipe.
1323 int epfd
= epoll_create1(0);
1325 struct epoll_event event
;
1326 event
.events
= EPOLLIN
;
1327 event
.data
.fd
= pipe_fds
[0];
1328 ret
= epoll_ctl(epfd
, EPOLL_CTL_ADD
, pipe_fds
[0], &event
);
1331 // Test epoll_wait when no events have occurred.
1333 dfsan_set_label(i_label
, &event
, sizeof(event
));
1334 DEFINE_AND_SAVE_ORIGINS(event
)
1335 ret
= epoll_wait(epfd
, &event
, /*maxevents=*/1, /*timeout=*/0);
1337 assert(event
.events
== 0);
1338 assert(event
.data
.fd
== 0);
1339 ASSERT_ZERO_LABEL(ret
);
1340 ASSERT_READ_LABEL(&event
, sizeof(event
), i_label
);
1341 ASSERT_SAVED_ORIGINS(event
)
1343 // Test epoll_wait when an event occurs.
1344 write(pipe_fds
[1], "x", 1);
1345 ret
= epoll_wait(epfd
, &event
, /*maxevents=*/1, /*timeout=*/0);
1347 assert(event
.events
== EPOLLIN
);
1348 assert(event
.data
.fd
== pipe_fds
[0]);
1349 ASSERT_ZERO_LABEL(ret
);
1350 ASSERT_READ_ZERO_LABEL(&event
, sizeof(event
));
1351 ASSERT_SAVED_ORIGINS(event
)
1363 dfsan_set_label(i_label
, &fd
.revents
, sizeof(fd
.revents
));
1364 DEFINE_AND_SAVE_ORIGINS(fd
)
1365 int ret
= poll(&fd
, 1, 1);
1366 ASSERT_ZERO_LABEL(ret
);
1367 ASSERT_ZERO_LABEL(fd
.revents
);
1368 ASSERT_SAVED_ORIGINS(fd
)
1372 void test_select() {
1377 dfsan_set_label(i_label
, &fds
, sizeof(fds
));
1378 dfsan_set_label(j_label
, &t
, sizeof(t
));
1379 DEFINE_AND_SAVE_ORIGINS(fds
)
1380 DEFINE_AND_SAVE_ORIGINS(t
)
1381 int ret
= select(1, &fds
, NULL
, NULL
, &t
);
1383 ASSERT_ZERO_LABEL(ret
);
1384 ASSERT_ZERO_LABEL(t
.tv_sec
);
1385 ASSERT_READ_ZERO_LABEL(&fds
, sizeof(fds
));
1386 ASSERT_SAVED_ORIGINS(fds
)
1387 ASSERT_SAVED_ORIGINS(t
)
1390 void test_sched_getaffinity() {
1392 dfsan_set_label(j_label
, &mask
, 1);
1393 DEFINE_AND_SAVE_ORIGINS(mask
)
1394 int ret
= sched_getaffinity(0, sizeof(mask
), &mask
);
1396 ASSERT_ZERO_LABEL(ret
);
1397 ASSERT_READ_ZERO_LABEL(&mask
, sizeof(mask
));
1398 ASSERT_SAVED_ORIGINS(mask
)
1401 void test_sigemptyset() {
1403 dfsan_set_label(j_label
, &set
, 1);
1404 DEFINE_AND_SAVE_ORIGINS(set
)
1405 int ret
= sigemptyset(&set
);
1407 ASSERT_ZERO_LABEL(ret
);
1408 ASSERT_READ_ZERO_LABEL(&set
, sizeof(set
));
1409 ASSERT_SAVED_ORIGINS(set
)
1412 static void SignalHandler(int signo
) {}
1414 static void SignalAction(int signo
, siginfo_t
*si
, void *uc
) {}
1416 void test_sigaction() {
1417 struct sigaction newact_with_sigaction
= {};
1418 newact_with_sigaction
.sa_flags
= SA_SIGINFO
;
1419 newact_with_sigaction
.sa_sigaction
= SignalAction
;
1421 // Set sigaction to be SignalAction, save the last one into origin_act
1422 struct sigaction origin_act
;
1423 dfsan_set_label(j_label
, &origin_act
, 1);
1424 DEFINE_AND_SAVE_ORIGINS(origin_act
)
1425 int ret
= sigaction(SIGUSR1
, &newact_with_sigaction
, &origin_act
);
1427 ASSERT_ZERO_LABEL(ret
);
1428 ASSERT_READ_ZERO_LABEL(&origin_act
, sizeof(origin_act
));
1429 ASSERT_SAVED_ORIGINS(origin_act
)
1431 struct sigaction newact_with_sighandler
= {};
1432 newact_with_sighandler
.sa_handler
= SignalHandler
;
1434 // Set sigaction to be SignalHandler, check the last one is SignalAction
1435 struct sigaction oldact
;
1436 assert(0 == sigaction(SIGUSR1
, &newact_with_sighandler
, &oldact
));
1437 assert(oldact
.sa_sigaction
== SignalAction
);
1438 assert(oldact
.sa_flags
& SA_SIGINFO
);
1440 // Set SIG_IGN or SIG_DFL, and check the previous one is expected.
1441 newact_with_sighandler
.sa_handler
= SIG_IGN
;
1442 assert(0 == sigaction(SIGUSR1
, &newact_with_sighandler
, &oldact
));
1443 assert(oldact
.sa_handler
== SignalHandler
);
1444 assert((oldact
.sa_flags
& SA_SIGINFO
) == 0);
1446 newact_with_sighandler
.sa_handler
= SIG_DFL
;
1447 assert(0 == sigaction(SIGUSR1
, &newact_with_sighandler
, &oldact
));
1448 assert(oldact
.sa_handler
== SIG_IGN
);
1449 assert((oldact
.sa_flags
& SA_SIGINFO
) == 0);
1451 // Restore sigaction to the orginal setting, check the last one is SignalHandler
1452 assert(0 == sigaction(SIGUSR1
, &origin_act
, &oldact
));
1453 assert(oldact
.sa_handler
== SIG_DFL
);
1454 assert((oldact
.sa_flags
& SA_SIGINFO
) == 0);
1457 void test_signal() {
1458 // Set signal to be SignalHandler, save the previous one into
1459 // old_signal_handler.
1460 sighandler_t old_signal_handler
= signal(SIGHUP
, SignalHandler
);
1461 ASSERT_ZERO_LABEL(old_signal_handler
);
1463 // Set SIG_IGN or SIG_DFL, and check the previous one is expected.
1464 assert(SignalHandler
== signal(SIGHUP
, SIG_DFL
));
1465 assert(SIG_DFL
== signal(SIGHUP
, SIG_IGN
));
1467 // Restore signal to old_signal_handler.
1468 assert(SIG_IGN
== signal(SIGHUP
, old_signal_handler
));
1471 void test_sigaltstack() {
1472 stack_t old_altstack
= {};
1473 dfsan_set_label(j_label
, &old_altstack
, sizeof(old_altstack
));
1474 DEFINE_AND_SAVE_ORIGINS(old_altstack
)
1475 int ret
= sigaltstack(NULL
, &old_altstack
);
1477 ASSERT_ZERO_LABEL(ret
);
1478 ASSERT_READ_ZERO_LABEL(&old_altstack
, sizeof(old_altstack
));
1479 ASSERT_SAVED_ORIGINS(old_altstack
)
1482 void test_gettimeofday() {
1485 dfsan_set_label(i_label
, &tv
, sizeof(tv
));
1486 dfsan_set_label(j_label
, &tz
, sizeof(tz
));
1487 DEFINE_AND_SAVE_ORIGINS(tv
)
1488 DEFINE_AND_SAVE_ORIGINS(tz
)
1489 int ret
= gettimeofday(&tv
, &tz
);
1491 ASSERT_READ_ZERO_LABEL(&tv
, sizeof(tv
));
1492 ASSERT_READ_ZERO_LABEL(&tz
, sizeof(tz
));
1493 ASSERT_SAVED_ORIGINS(tv
)
1494 ASSERT_SAVED_ORIGINS(tz
)
1497 void *pthread_create_test_cb(void *p
) {
1498 assert(p
== (void *)1);
1499 ASSERT_ZERO_LABEL(p
);
1503 void test_pthread_create() {
1505 int create_ret
= pthread_create(&pt
, 0, pthread_create_test_cb
, (void *)1);
1506 assert(create_ret
== 0);
1507 ASSERT_ZERO_LABEL(create_ret
);
1509 dfsan_set_label(i_label
, &cbrv
, sizeof(cbrv
));
1510 DEFINE_AND_SAVE_ORIGINS(cbrv
)
1511 int joint_ret
= pthread_join(pt
, &cbrv
);
1512 assert(joint_ret
== 0);
1513 assert(cbrv
== (void *)2);
1514 ASSERT_ZERO_LABEL(joint_ret
);
1515 ASSERT_ZERO_LABEL(cbrv
);
1516 ASSERT_SAVED_ORIGINS(cbrv
);
1519 // Tested by test_pthread_create(). This empty function is here to appease the
1520 // check-wrappers script.
1521 void test_pthread_join() {}
1523 int dl_iterate_phdr_test_cb(struct dl_phdr_info
*info
, size_t size
,
1525 assert(data
== (void *)3);
1526 ASSERT_ZERO_LABEL(info
);
1527 ASSERT_ZERO_LABEL(size
);
1528 ASSERT_ZERO_LABEL(data
);
1532 void test_dl_iterate_phdr() {
1533 dl_iterate_phdr(dl_iterate_phdr_test_cb
, (void *)3);
1536 // On glibc < 2.27, this symbol is not available. Mark it weak so we can skip
1537 // testing in this case.
1538 __attribute__((weak
)) extern "C" void _dl_get_tls_static_info(size_t *sizep
,
1541 void test__dl_get_tls_static_info() {
1542 if (!_dl_get_tls_static_info
)
1544 size_t sizep
= 0, alignp
= 0;
1545 dfsan_set_label(i_label
, &sizep
, sizeof(sizep
));
1546 dfsan_set_label(i_label
, &alignp
, sizeof(alignp
));
1547 dfsan_origin sizep_o
= dfsan_get_origin(sizep
);
1548 dfsan_origin alignp_o
= dfsan_get_origin(alignp
);
1549 #ifndef ORIGIN_TRACKING
1553 _dl_get_tls_static_info(&sizep
, &alignp
);
1554 ASSERT_ZERO_LABEL(sizep
);
1555 ASSERT_ZERO_LABEL(alignp
);
1556 ASSERT_ORIGIN(sizep
, sizep_o
);
1557 ASSERT_ORIGIN(alignp
, alignp_o
);
1560 void test_strrchr() {
1561 char str1
[] = "str1str1";
1564 dfsan_set_label(j_label
, &p
, sizeof(p
));
1566 char *rv
= strrchr(p
, 'r');
1567 assert(rv
== &str1
[6]);
1568 ASSERT_LABEL(rv
, j_label
);
1569 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, p
);
1572 dfsan_set_label(k_label
, &c
, sizeof(c
));
1573 rv
= strrchr(str1
, c
);
1574 assert(rv
== &str1
[6]);
1575 #ifdef STRICT_DATA_DEPENDENCIES
1576 ASSERT_ZERO_LABEL(rv
);
1578 ASSERT_LABEL(rv
, k_label
);
1579 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, c
);
1582 dfsan_set_label(i_label
, &str1
[7], 1);
1584 rv
= strrchr(str1
, 'r');
1585 assert(rv
== &str1
[6]);
1586 #ifdef STRICT_DATA_DEPENDENCIES
1587 ASSERT_ZERO_LABEL(rv
);
1589 ASSERT_LABEL(rv
, i_label
);
1590 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, str1
[7]);
1594 void test_strstr() {
1595 char str1
[] = "str1str1";
1598 dfsan_set_label(k_label
, &p1
, sizeof(p1
));
1599 char *rv
= strstr(p1
, "1s");
1600 assert(rv
== &str1
[3]);
1601 ASSERT_LABEL(rv
, k_label
);
1602 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, p1
);
1606 dfsan_set_label(m_label
, &p2
, sizeof(p2
));
1607 rv
= strstr(str1
, p2
);
1608 assert(rv
== &str1
[3]);
1609 #ifdef STRICT_DATA_DEPENDENCIES
1610 ASSERT_ZERO_LABEL(rv
);
1612 ASSERT_LABEL(rv
, m_label
);
1613 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, p2
);
1616 dfsan_set_label(n_label
, &str2
[0], 1);
1617 rv
= strstr(str1
, str2
);
1618 assert(rv
== &str1
[3]);
1619 #ifdef STRICT_DATA_DEPENDENCIES
1620 ASSERT_ZERO_LABEL(rv
);
1622 ASSERT_LABEL(rv
, n_label
);
1623 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, str2
[0]);
1626 dfsan_set_label(i_label
, &str1
[3], 1);
1627 dfsan_set_label(j_label
, &str1
[5], 1);
1629 rv
= strstr(str1
, "1s");
1630 assert(rv
== &str1
[3]);
1631 #ifdef STRICT_DATA_DEPENDENCIES
1632 ASSERT_ZERO_LABEL(rv
);
1634 ASSERT_LABEL(rv
, i_label
);
1635 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, str1
[3]);
1638 rv
= strstr(str1
, "2s");
1640 #ifdef STRICT_DATA_DEPENDENCIES
1641 ASSERT_ZERO_LABEL(rv
);
1643 ASSERT_LABEL(rv
, i_j_label
);
1644 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, str1
[3]);
1648 void test_strpbrk() {
1649 char s
[] = "abcdefg";
1650 char accept
[] = "123fd";
1653 char *p_accept
= accept
;
1655 dfsan_set_label(n_label
, &p_accept
, sizeof(p_accept
));
1657 char *rv
= strpbrk(p_s
, p_accept
);
1658 assert(rv
== &s
[3]);
1659 #ifdef STRICT_DATA_DEPENDENCIES
1660 ASSERT_ZERO_LABEL(rv
);
1662 ASSERT_LABEL(rv
, n_label
);
1663 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, p_accept
);
1666 dfsan_set_label(m_label
, &p_s
, sizeof(p_s
));
1668 rv
= strpbrk(p_s
, p_accept
);
1669 assert(rv
== &s
[3]);
1670 #ifdef STRICT_DATA_DEPENDENCIES
1671 ASSERT_LABEL(rv
, m_label
);
1672 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, p_s
);
1674 ASSERT_LABEL(rv
, dfsan_union(m_label
, n_label
));
1675 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, p_s
);
1678 dfsan_set_label(i_label
, &s
[5], 1);
1679 dfsan_set_label(j_label
, &accept
[1], 1);
1681 rv
= strpbrk(s
, accept
);
1682 assert(rv
== &s
[3]);
1683 #ifdef STRICT_DATA_DEPENDENCIES
1684 ASSERT_ZERO_LABEL(rv
);
1686 ASSERT_LABEL(rv
, j_label
);
1687 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, accept
[1]);
1691 dfsan_set_label(j_label
, &ps
, sizeof(ps
));
1693 rv
= strpbrk(ps
, "123gf");
1694 assert(rv
== &s
[5]);
1695 #ifdef STRICT_DATA_DEPENDENCIES
1696 ASSERT_LABEL(rv
, j_label
);
1698 ASSERT_LABEL(rv
, i_j_label
);
1699 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, s
[5]);
1702 rv
= strpbrk(ps
, "123");
1704 #ifdef STRICT_DATA_DEPENDENCIES
1705 ASSERT_ZERO_LABEL(rv
);
1707 ASSERT_LABEL(rv
, i_j_label
);
1708 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, s
[5]);
1712 void test_strsep() {
1713 char *s
= strdup("Hello world/");
1714 char *delim
= strdup(" /");
1718 char *p_delim
= delim
;
1720 // taint delim bytes
1721 dfsan_set_label(i_label
, p_delim
, strlen(p_delim
));
1722 // taint delim pointer
1723 dfsan_set_label(j_label
, &p_delim
, sizeof(p_delim
));
1724 // taint the string data bytes
1725 dfsan_set_label(k_label
, s
, 5);
1726 // taint the string pointer
1727 dfsan_set_label(m_label
, &p_s
, sizeof(p_s
));
1729 char *rv
= strsep(&p_s
, p_delim
);
1730 assert(rv
== &base
[0]);
1731 #ifdef STRICT_DATA_DEPENDENCIES
1732 ASSERT_LABEL(rv
, m_label
);
1733 ASSERT_READ_LABEL(rv
, strlen(rv
), k_label
);
1735 ASSERT_LABEL(rv
, dfsan_union(dfsan_union(i_label
, j_label
),
1736 dfsan_union(k_label
, m_label
)));
1737 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, p_s
);
1740 // taint the remaining string's pointer
1742 char **pp_s_base
= pp_s
;
1743 dfsan_set_label(n_label
, pp_s
, sizeof(pp_s
));
1745 rv
= strsep(pp_s
, p_delim
);
1747 assert(rv
== &base
[6]);
1748 #ifdef STRICT_DATA_DEPENDENCIES
1749 ASSERT_LABEL(rv
, n_label
);
1750 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, *pp_s
);
1752 ASSERT_LABEL(rv
, dfsan_union(dfsan_union(i_label
, j_label
), n_label
));
1753 ASSERT_INIT_ORIGIN_EQ_ORIGIN(&rv
, *pp_s
);
1757 void test_memchr() {
1758 char str1
[] = "str1";
1759 dfsan_set_label(i_label
, &str1
[3], 1);
1760 dfsan_set_label(j_label
, &str1
[4], 1);
1762 char *crv
= (char *) memchr(str1
, 'r', sizeof(str1
));
1763 assert(crv
== &str1
[2]);
1764 ASSERT_ZERO_LABEL(crv
);
1767 dfsan_set_label(k_label
, &c
, sizeof(c
));
1768 crv
= (char *)memchr(str1
, c
, sizeof(str1
));
1769 assert(crv
== &str1
[2]);
1770 #ifdef STRICT_DATA_DEPENDENCIES
1771 ASSERT_ZERO_LABEL(crv
);
1773 ASSERT_LABEL(crv
, k_label
);
1774 ASSERT_EQ_ORIGIN(crv
, c
);
1778 dfsan_set_label(k_label
, &ptr
, sizeof(ptr
));
1779 crv
= (char *)memchr(ptr
, 'r', sizeof(str1
));
1780 assert(crv
== &str1
[2]);
1781 ASSERT_LABEL(crv
, k_label
);
1782 ASSERT_EQ_ORIGIN(crv
, ptr
);
1784 crv
= (char *) memchr(str1
, '1', sizeof(str1
));
1785 assert(crv
== &str1
[3]);
1786 #ifdef STRICT_DATA_DEPENDENCIES
1787 ASSERT_ZERO_LABEL(crv
);
1789 ASSERT_LABEL(crv
, i_label
);
1790 ASSERT_EQ_ORIGIN(crv
, str1
[3]);
1793 crv
= (char *) memchr(str1
, 'x', sizeof(str1
));
1795 #ifdef STRICT_DATA_DEPENDENCIES
1796 ASSERT_ZERO_LABEL(crv
);
1798 ASSERT_LABEL(crv
, i_j_label
);
1799 ASSERT_EQ_ORIGIN(crv
, str1
[3]);
1803 void alarm_handler(int unused
) {
1807 void test_nanosleep() {
1808 struct timespec req
, rem
;
1811 dfsan_set_label(i_label
, &rem
, sizeof(rem
));
1812 DEFINE_AND_SAVE_ORIGINS(rem
)
1815 int rv
= nanosleep(&req
, &rem
);
1817 ASSERT_ZERO_LABEL(rv
);
1818 ASSERT_READ_LABEL(&rem
, 1, i_label
);
1819 ASSERT_SAVED_ORIGINS(rem
)
1821 // interrupted by an alarm
1822 signal(SIGALRM
, alarm_handler
);
1825 rv
= nanosleep(&req
, &rem
);
1827 ASSERT_ZERO_LABEL(rv
);
1828 ASSERT_READ_ZERO_LABEL(&rem
, sizeof(rem
));
1829 ASSERT_SAVED_ORIGINS(rem
)
1832 void test_socketpair() {
1834 dfsan_origin fd_o
[2];
1836 dfsan_set_label(i_label
, fd
, sizeof(fd
));
1837 fd_o
[0] = dfsan_get_origin((long)(fd
[0]));
1838 fd_o
[1] = dfsan_get_origin((long)(fd
[1]));
1839 int rv
= socketpair(PF_LOCAL
, SOCK_STREAM
, 0, fd
);
1841 ASSERT_ZERO_LABEL(rv
);
1842 ASSERT_READ_ZERO_LABEL(fd
, sizeof(fd
));
1843 ASSERT_ORIGIN(fd
[0], fd_o
[0]);
1844 ASSERT_ORIGIN(fd
[1], fd_o
[1]);
1847 void test_getpeername() {
1849 int ret
= socketpair(AF_UNIX
, SOCK_DGRAM
, 0, sockfds
);
1852 struct sockaddr addr
= {};
1853 socklen_t addrlen
= sizeof(addr
);
1854 dfsan_set_label(i_label
, &addr
, addrlen
);
1855 dfsan_set_label(i_label
, &addrlen
, sizeof(addrlen
));
1856 DEFINE_AND_SAVE_ORIGINS(addr
)
1857 DEFINE_AND_SAVE_ORIGINS(addrlen
)
1859 ret
= getpeername(sockfds
[0], &addr
, &addrlen
);
1861 ASSERT_ZERO_LABEL(ret
);
1862 ASSERT_ZERO_LABEL(addrlen
);
1863 assert(addrlen
< sizeof(addr
));
1864 ASSERT_READ_ZERO_LABEL(&addr
, addrlen
);
1865 ASSERT_READ_LABEL(((char *)&addr
) + addrlen
, 1, i_label
);
1866 ASSERT_SAVED_ORIGINS(addr
)
1867 ASSERT_SAVED_ORIGINS(addrlen
)
1873 void test_getsockname() {
1874 int sockfd
= socket(AF_UNIX
, SOCK_DGRAM
, 0);
1875 assert(sockfd
!= -1);
1877 struct sockaddr addr
= {};
1878 socklen_t addrlen
= sizeof(addr
);
1879 dfsan_set_label(i_label
, &addr
, addrlen
);
1880 dfsan_set_label(i_label
, &addrlen
, sizeof(addrlen
));
1881 DEFINE_AND_SAVE_ORIGINS(addr
)
1882 DEFINE_AND_SAVE_ORIGINS(addrlen
)
1883 int ret
= getsockname(sockfd
, &addr
, &addrlen
);
1885 ASSERT_ZERO_LABEL(ret
);
1886 ASSERT_ZERO_LABEL(addrlen
);
1887 assert(addrlen
< sizeof(addr
));
1888 ASSERT_READ_ZERO_LABEL(&addr
, addrlen
);
1889 ASSERT_READ_LABEL(((char *)&addr
) + addrlen
, 1, i_label
);
1890 ASSERT_SAVED_ORIGINS(addr
)
1891 ASSERT_SAVED_ORIGINS(addrlen
)
1896 void test_getsockopt() {
1897 int sockfd
= socket(AF_UNIX
, SOCK_DGRAM
, 0);
1898 assert(sockfd
!= -1);
1900 int optval
[2] = {-1, -1};
1901 socklen_t optlen
= sizeof(optval
);
1902 dfsan_set_label(i_label
, &optval
, sizeof(optval
));
1903 dfsan_set_label(i_label
, &optlen
, sizeof(optlen
));
1904 DEFINE_AND_SAVE_ORIGINS(optval
)
1905 DEFINE_AND_SAVE_ORIGINS(optlen
)
1906 int ret
= getsockopt(sockfd
, SOL_SOCKET
, SO_KEEPALIVE
, &optval
, &optlen
);
1908 assert(optlen
== sizeof(int));
1909 assert(optval
[0] == 0);
1910 assert(optval
[1] == -1);
1911 ASSERT_ZERO_LABEL(ret
);
1912 ASSERT_ZERO_LABEL(optlen
);
1913 ASSERT_ZERO_LABEL(optval
[0]);
1914 ASSERT_LABEL(optval
[1], i_label
);
1915 ASSERT_SAVED_ORIGINS(optval
)
1916 ASSERT_SAVED_ORIGINS(optlen
)
1922 int fd
= open("/dev/null", O_WRONLY
);
1924 char buf
[] = "a string";
1925 int len
= strlen(buf
);
1927 // The result of a write always unlabeled.
1928 int res
= write(fd
, buf
, len
);
1930 ASSERT_ZERO_LABEL(res
);
1932 // Label all arguments to write().
1933 dfsan_set_label(i_label
, &(buf
[3]), 1);
1934 dfsan_set_label(j_label
, &fd
, sizeof(fd
));
1935 dfsan_set_label(k_label
, &len
, sizeof(len
));
1937 // The value returned by write() should have no label.
1938 res
= write(fd
, buf
, len
);
1939 ASSERT_ZERO_LABEL(res
);
1945 void test_sprintf_chunk(const char* expected
, const char* format
, T arg
) {
1947 memset(buf
, 'a', sizeof(buf
));
1949 char padded_expected
[512];
1950 strcpy(padded_expected
, "foo ");
1951 strcat(padded_expected
, expected
);
1952 strcat(padded_expected
, " bar");
1954 char padded_format
[512];
1955 strcpy(padded_format
, "foo ");
1956 strcat(padded_format
, format
);
1957 strcat(padded_format
, " bar");
1959 // Non labelled arg.
1960 assert(sprintf(buf
, padded_format
, arg
) == strlen(padded_expected
));
1961 assert(strcmp(buf
, padded_expected
) == 0);
1962 ASSERT_READ_LABEL(buf
, strlen(padded_expected
), 0);
1963 memset(buf
, 'a', sizeof(buf
));
1966 dfsan_set_label(i_label
, &arg
, sizeof(arg
));
1967 dfsan_origin a_o
= dfsan_get_origin((long)(arg
));
1968 #ifndef ORIGIN_TRACKING
1971 assert(sprintf(buf
, padded_format
, arg
) == strlen(padded_expected
));
1972 assert(strcmp(buf
, padded_expected
) == 0);
1973 ASSERT_READ_LABEL(buf
, 4, 0);
1974 ASSERT_READ_LABEL(buf
+ 4, strlen(padded_expected
) - 8, i_label
);
1975 ASSERT_INIT_ORIGINS(buf
+ 4, strlen(padded_expected
) - 8, a_o
);
1976 ASSERT_READ_LABEL(buf
+ (strlen(padded_expected
) - 4), 4, 0);
1979 void test_sprintf() {
1981 memset(buf
, 'a', sizeof(buf
));
1983 // Test formatting (no conversion specifier).
1984 assert(sprintf(buf
, "Hello world!") == 12);
1985 assert(strcmp(buf
, "Hello world!") == 0);
1986 ASSERT_READ_LABEL(buf
, sizeof(buf
), 0);
1988 // Test for extra arguments.
1989 assert(sprintf(buf
, "Hello world!", 42, "hello") == 12);
1990 assert(strcmp(buf
, "Hello world!") == 0);
1991 ASSERT_READ_LABEL(buf
, sizeof(buf
), 0);
1993 // Test formatting & label propagation (multiple conversion specifiers): %s,
1994 // %d, %n, %f, and %%.
1995 const char* s
= "world";
1998 dfsan_set_label(k_label
, (void *) (s
+ 1), 2);
1999 dfsan_origin s_o
= dfsan_get_origin((long)(s
[1]));
2000 dfsan_set_label(i_label
, &m
, sizeof(m
));
2001 dfsan_origin m_o
= dfsan_get_origin((long)m
);
2002 dfsan_set_label(j_label
, &d
, sizeof(d
));
2003 dfsan_origin d_o
= dfsan_get_origin((long)d
);
2004 #ifndef ORIGIN_TRACKING
2010 int r
= sprintf(buf
, "hello %s, %-d/%d/%d %f %% %n%d", s
, 2014, m
, d
,
2011 12345.6781234, &n
, 1000);
2013 assert(strcmp(buf
, "hello world, 2014/8/27 12345.678123 % 1000") == 0);
2014 ASSERT_READ_LABEL(buf
, 7, 0);
2015 ASSERT_READ_LABEL(buf
+ 7, 2, k_label
);
2016 ASSERT_INIT_ORIGINS(buf
+ 7, 2, s_o
);
2017 ASSERT_READ_LABEL(buf
+ 9, 9, 0);
2018 ASSERT_READ_LABEL(buf
+ 18, 1, i_label
);
2019 ASSERT_INIT_ORIGINS(buf
+ 18, 1, m_o
);
2020 ASSERT_READ_LABEL(buf
+ 19, 1, 0);
2021 ASSERT_READ_LABEL(buf
+ 20, 2, j_label
);
2022 ASSERT_INIT_ORIGINS(buf
+ 20, 2, d_o
);
2023 ASSERT_READ_LABEL(buf
+ 22, 15, 0);
2027 // Test formatting & label propagation (single conversion specifier, with
2028 // additional length and precision modifiers).
2029 test_sprintf_chunk("-559038737", "%d", 0xdeadbeef);
2030 test_sprintf_chunk("3735928559", "%u", 0xdeadbeef);
2031 test_sprintf_chunk("12345", "%i", 12345);
2032 test_sprintf_chunk("751", "%o", 0751);
2033 test_sprintf_chunk("babe", "%x", 0xbabe);
2034 test_sprintf_chunk("0000BABE", "%.8X", 0xbabe);
2035 test_sprintf_chunk("-17", "%hhd", 0xdeadbeef);
2036 test_sprintf_chunk("-16657", "%hd", 0xdeadbeef);
2037 test_sprintf_chunk("deadbeefdeadbeef", "%lx", 0xdeadbeefdeadbeef);
2038 test_sprintf_chunk("0xdeadbeefdeadbeef", "%p",
2039 (void *) 0xdeadbeefdeadbeef);
2040 test_sprintf_chunk("18446744073709551615", "%ju", (intmax_t) -1);
2041 test_sprintf_chunk("18446744073709551615", "%zu", (size_t) -1);
2042 test_sprintf_chunk("18446744073709551615", "%tu", (size_t) -1);
2044 test_sprintf_chunk("0x1.f9acffa7eb6bfp-4", "%a", 0.123456);
2045 test_sprintf_chunk("0X1.F9ACFFA7EB6BFP-4", "%A", 0.123456);
2046 test_sprintf_chunk("0.12346", "%.5f", 0.123456);
2047 test_sprintf_chunk("0.123456", "%g", 0.123456);
2048 test_sprintf_chunk("1.234560e-01", "%e", 0.123456);
2049 test_sprintf_chunk("1.234560E-01", "%E", 0.123456);
2050 test_sprintf_chunk("0.1234567891234560", "%.16Lf",
2051 (long double) 0.123456789123456);
2053 test_sprintf_chunk("z", "%c", 'z');
2055 // %n, %s, %d, %f, and %% already tested
2057 // Test formatting with width passed as an argument.
2058 r
= sprintf(buf
, "hi %*d my %*s friend %.*f", 3, 1, 6, "dear", 4, 3.14159265359);
2060 assert(strcmp(buf
, "hi 1 my dear friend 3.1416") == 0);
2063 void test_snprintf() {
2065 memset(buf
, 'a', sizeof(buf
));
2066 dfsan_set_label(0, buf
, sizeof(buf
));
2067 const char* s
= "world";
2071 dfsan_set_label(k_label
, (void *) (s
+ 1), 2);
2072 dfsan_origin s_o
= dfsan_get_origin((long)(s
[1]));
2073 dfsan_set_label(i_label
, &y
, sizeof(y
));
2074 dfsan_origin y_o
= dfsan_get_origin((long)y
);
2075 dfsan_set_label(j_label
, &m
, sizeof(m
));
2076 dfsan_origin m_o
= dfsan_get_origin((long)m
);
2077 #ifndef ORIGIN_TRACKING
2082 int r
= snprintf(buf
, 19, "hello %s, %-d/ %d/%d %f", s
, y
, m
, d
,
2084 // The return value is the number of bytes that would have been written to
2085 // the final string if enough space had been available.
2087 assert(memcmp(buf
, "hello world, 2014/", 19) == 0);
2088 ASSERT_READ_LABEL(buf
, 7, 0);
2089 ASSERT_READ_LABEL(buf
+ 7, 2, k_label
);
2090 ASSERT_INIT_ORIGINS(buf
+ 7, 2, s_o
);
2091 ASSERT_READ_LABEL(buf
+ 9, 4, 0);
2092 ASSERT_READ_LABEL(buf
+ 13, 4, i_label
);
2093 ASSERT_INIT_ORIGINS(buf
+ 13, 4, y_o
);
2094 ASSERT_READ_LABEL(buf
+ 17, 2, 0);
2099 void test_sscanf_chunk(T expected
, const char *format
, char *input
,
2101 char padded_input
[512];
2102 strcpy(padded_input
, "foo ");
2103 strcat(padded_input
, input
);
2104 strcpy(padded_input
, "@");
2105 strcat(padded_input
, input
);
2106 strcat(padded_input
, " bar");
2108 char padded_format
[512];
2109 strcpy(padded_format
, "foo ");
2110 // Swap the first '%' for '%*' so this input is skipped.
2111 strcpy(padded_format
, "%*");
2112 strcat(padded_format
, format
+ 1);
2113 strcpy(padded_format
, "@");
2114 strcat(padded_format
, format
);
2115 strcat(padded_format
, " bar");
2117 char *s
= padded_input
+ 4;
2119 memset(&arg
, 0, sizeof(arg
));
2120 dfsan_set_label(i_label
, (void *)(padded_input
), strlen(padded_input
));
2121 dfsan_set_label(j_label
, (void *)(padded_format
), strlen(padded_format
));
2122 dfsan_origin a_o
= dfsan_get_origin((long)(*s
));
2123 #ifndef ORIGIN_TRACKING
2128 int rv
= sscanf(padded_input
, padded_format
, &arg
);
2129 assert(rv
== items_num
);
2130 assert(arg
== expected
);
2131 ASSERT_READ_LABEL(&arg
, sizeof(arg
), i_label
);
2132 ASSERT_INIT_ORIGINS(&arg
, 1, a_o
);
2135 void test_sscanf() {
2138 memset(buf
, 'a', sizeof(buf
));
2139 memset(buf_out
, 'a', sizeof(buf_out
));
2142 strcpy(buf
, "Hello world!");
2143 assert(sscanf(buf
, "%s", buf_out
) == 1);
2144 assert(strcmp(buf
, "Hello world!") == 0);
2145 assert(strcmp(buf_out
, "Hello") == 0);
2146 ASSERT_READ_LABEL(buf
, sizeof(buf
), 0);
2147 ASSERT_READ_LABEL(buf_out
, sizeof(buf_out
), 0);
2149 // Test for extra arguments.
2150 assert(sscanf(buf
, "%s", buf_out
, 42, "hello") == 1);
2151 assert(strcmp(buf
, "Hello world!") == 0);
2152 assert(strcmp(buf_out
, "Hello") == 0);
2153 ASSERT_READ_LABEL(buf
, sizeof(buf
), 0);
2154 ASSERT_READ_LABEL(buf_out
, sizeof(buf_out
), 0);
2156 // Test formatting & label propagation (multiple conversion specifiers): %s,
2157 // %d, %n, %f, and %%.
2159 strcpy(buf
, "hello world, 42 2014/8/31 12345.678123 % 1000");
2160 char *s
= buf
+ 6; //starts with world
2166 dfsan_set_label(k_label
, (void *)(s
+ 1), 2); // buf[7]-b[9]
2167 dfsan_origin s_o
= dfsan_get_origin((long)(s
[1]));
2168 assert(s
[10] == '2');
2169 dfsan_set_label(i_label
, (void *)(s
+ 10), 4); // 2014
2170 dfsan_origin y_o
= dfsan_get_origin((long)s
[10]); // buf[16]
2171 assert(s
[17] == '3');
2172 dfsan_set_label(j_label
, (void *)(s
+ 17), 2); // 31
2173 dfsan_origin d_o
= dfsan_get_origin((long)s
[17]); // buf[23]
2174 assert(s
[20] == '1');
2175 dfsan_set_label(m_label
, (void *)(s
+ 20), 5); // 12345
2176 dfsan_origin f_o
= dfsan_get_origin((long)s
[20]); //buf[26]
2178 #ifndef ORIGIN_TRACKING
2189 int r
= sscanf(buf
, "hello %s %*d %d/%d/%d %f %% %n%d", buf_out
, &y
, &m
, &d
,
2192 assert(strcmp(buf_out
, "world,") == 0);
2196 assert(fval
> 12300.0f
);
2197 assert(fval
< 12400.0f
);
2198 ASSERT_READ_LABEL(buf_out
, 1, 0);
2199 ASSERT_READ_LABEL(buf_out
+ 1, 2, k_label
);
2200 ASSERT_INIT_ORIGINS(buf_out
+ 1, 2, s_o
);
2201 ASSERT_READ_LABEL(&y
, sizeof(y
), i_label
);
2202 ASSERT_INIT_ORIGINS(&y
, sizeof(y
), y_o
);
2203 ASSERT_READ_LABEL(&d
, sizeof(d
), j_label
);
2204 ASSERT_INIT_ORIGINS(&d
, sizeof(d
), d_o
);
2205 ASSERT_READ_LABEL(&fval
, sizeof(fval
), m_label
);
2206 ASSERT_INIT_ORIGINS(&fval
, sizeof(fval
), f_o
);
2207 ASSERT_READ_LABEL(&val
, 4, 0);
2210 assert(val
== 1000);
2212 // Test formatting & label propagation (single conversion specifier, with
2213 // additional length and precision modifiers).
2214 char input_buf
[512];
2215 char *input_ptr
= input_buf
;
2216 strcpy(input_buf
, "-559038737");
2217 test_sscanf_chunk(-559038737, "%d", input_ptr
, 1);
2218 strcpy(input_buf
, "3735928559");
2219 test_sscanf_chunk(3735928559, "%u", input_ptr
, 1);
2220 strcpy(input_buf
, "12345");
2221 test_sscanf_chunk(12345, "%i", input_ptr
, 1);
2222 strcpy(input_buf
, "0751");
2223 test_sscanf_chunk(489, "%o", input_ptr
, 1);
2224 strcpy(input_buf
, "0xbabe");
2225 test_sscanf_chunk(47806, "%x", input_ptr
, 1);
2226 strcpy(input_buf
, "0x0000BABE");
2227 test_sscanf_chunk(47806, "%10X", input_ptr
, 1);
2228 strcpy(input_buf
, "3735928559");
2229 test_sscanf_chunk((char)-17, "%hhd", input_ptr
, 1);
2230 strcpy(input_buf
, "3735928559");
2231 test_sscanf_chunk((short)-16657, "%hd", input_ptr
, 1);
2232 strcpy(input_buf
, "0xdeadbeefdeadbeef");
2233 test_sscanf_chunk(0xdeadbeefdeadbeefL
, "%lx", input_buf
, 1);
2234 test_sscanf_chunk((void *)0xdeadbeefdeadbeefL
, "%p", input_buf
, 1);
2236 intmax_t _x
= (intmax_t)-1;
2238 memset(_buf
, 0, sizeof(_buf
));
2239 sprintf(_buf
, "%ju", _x
);
2240 test_sscanf_chunk((intmax_t)18446744073709551615, "%ju", _buf
, 1);
2241 memset(_buf
, 0, sizeof(_buf
));
2242 size_t _y
= (size_t)-1;
2243 sprintf(_buf
, "%zu", _y
);
2244 test_sscanf_chunk((size_t)18446744073709551615, "%zu", _buf
, 1);
2245 memset(_buf
, 0, sizeof(_buf
));
2246 ptrdiff_t _z
= (size_t)-1;
2247 sprintf(_buf
, "%tu", _z
);
2248 test_sscanf_chunk((ptrdiff_t)18446744073709551615, "%tu", _buf
, 1);
2250 strcpy(input_buf
, "0.123456");
2251 test_sscanf_chunk((float)0.123456, "%8f", input_ptr
, 1);
2252 test_sscanf_chunk((float)0.123456, "%g", input_ptr
, 1);
2253 test_sscanf_chunk((float)1.234560e-01, "%e", input_ptr
, 1);
2254 test_sscanf_chunk((char)'z', "%c", "z", 1);
2256 // %n, %s, %d, %f, and %% already tested
2259 // Tested by a seperate source file. This empty function is here to appease the
2260 // check-wrappers script.
2269 i_j_label
= dfsan_union(i_label
, j_label
);
2270 assert(i_j_label
!= i_label
);
2271 assert(i_j_label
!= j_label
);
2272 assert(i_j_label
!= k_label
);
2274 test__dl_get_tls_static_info();
2276 test_clock_gettime();
2278 test_dfsan_set_write_callback();
2279 test_dl_iterate_phdr();
2285 test_get_current_dir_name();
2295 test_gettimeofday();
2306 test_pthread_create();
2307 test_pthread_join();
2311 test_sched_getaffinity();