* [LTP] [PATCH v4 1/4] Add landlock ABI v6 fallback
2025-05-27 10:54 [LTP] [PATCH v4 0/4] Landlock tests for ABI v6 Andrea Cervesato
@ 2025-05-27 10:54 ` Andrea Cervesato
2025-05-27 10:54 ` [LTP] [PATCH v4 2/4] landlock02: support landlock ABI v6 Andrea Cervesato
` (3 subsequent siblings)
4 siblings, 0 replies; 6+ messages in thread
From: Andrea Cervesato @ 2025-05-27 10:54 UTC (permalink / raw)
To: ltp
From: Andrea Cervesato <andrea.cervesato@suse.com>
The new ABI v6 is defining the following IPC scoped operations:
* LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET
* LANDLOCK_SCOPE_SIGNAL
Reviewed-by: Cyril Hrubis <chrubis@suse.cz>
Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
include/lapi/landlock.h | 23 +++++++++++++++++------
1 file changed, 17 insertions(+), 6 deletions(-)
diff --git a/include/lapi/landlock.h b/include/lapi/landlock.h
index b3c8c548e661680541cdf6e4a8fb68a3f5029fec..e579500ec26cdc0a568620bc35386f3d2b68952e 100644
--- a/include/lapi/landlock.h
+++ b/include/lapi/landlock.h
@@ -15,15 +15,19 @@
#include "lapi/syscalls.h"
-struct tst_landlock_ruleset_attr_abi1
-{
+struct tst_landlock_ruleset_attr_abi1 {
uint64_t handled_access_fs;
};
-struct tst_landlock_ruleset_attr_abi4
-{
+struct tst_landlock_ruleset_attr_abi4 {
+ uint64_t handled_access_fs;
+ uint64_t handled_access_net;
+};
+
+struct tst_landlock_ruleset_attr_abi6 {
uint64_t handled_access_fs;
uint64_t handled_access_net;
+ uint64_t scoped;
};
#ifndef HAVE_STRUCT_LANDLOCK_PATH_BENEATH_ATTR
@@ -43,8 +47,7 @@ struct landlock_path_beneath_attr
#endif
#ifndef HAVE_STRUCT_LANDLOCK_NET_PORT_ATTR
-struct landlock_net_port_attr
-{
+struct landlock_net_port_attr {
uint64_t allowed_access;
uint64_t port;
};
@@ -126,6 +129,14 @@ struct landlock_net_port_attr
# define LANDLOCK_ACCESS_NET_CONNECT_TCP (1ULL << 1)
#endif
+#ifndef LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET
+# define LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET (1ULL << 0)
+#endif
+
+#ifndef LANDLOCK_SCOPE_SIGNAL
+# define LANDLOCK_SCOPE_SIGNAL (1ULL << 1)
+#endif
+
static inline int safe_landlock_create_ruleset(const char *file, const int lineno,
const void *attr, size_t size , uint32_t flags)
{
--
2.43.0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply related [flat|nested] 6+ messages in thread* [LTP] [PATCH v4 2/4] landlock02: support landlock ABI v6
2025-05-27 10:54 [LTP] [PATCH v4 0/4] Landlock tests for ABI v6 Andrea Cervesato
2025-05-27 10:54 ` [LTP] [PATCH v4 1/4] Add landlock ABI v6 fallback Andrea Cervesato
@ 2025-05-27 10:54 ` Andrea Cervesato
2025-05-27 10:54 ` [LTP] [PATCH v4 3/4] landlock: add landlock09 test Andrea Cervesato
` (2 subsequent siblings)
4 siblings, 0 replies; 6+ messages in thread
From: Andrea Cervesato @ 2025-05-27 10:54 UTC (permalink / raw)
To: ltp
From: Andrea Cervesato <andrea.cervesato@suse.com>
Reviewed-by: Cyril Hrubis <chrubis@suse.cz>
Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
testcases/kernel/syscalls/landlock/landlock02.c | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/testcases/kernel/syscalls/landlock/landlock02.c b/testcases/kernel/syscalls/landlock/landlock02.c
index 60010f554b001156f3feb30283bb5c22a5fea1fc..37dc72d32c633a2f249c5a9ef879b6d288a63259 100644
--- a/testcases/kernel/syscalls/landlock/landlock02.c
+++ b/testcases/kernel/syscalls/landlock/landlock02.c
@@ -20,6 +20,7 @@
static struct tst_landlock_ruleset_attr_abi1 *attr_abi1;
static struct tst_landlock_ruleset_attr_abi4 *attr_abi4;
+static struct tst_landlock_ruleset_attr_abi6 *attr_abi6;
static struct landlock_path_beneath_attr *path_beneath_attr;
static struct landlock_path_beneath_attr *rule_null;
static struct landlock_net_port_attr *net_port_attr;
@@ -144,15 +145,19 @@ static void setup(void)
{
abi_current = verify_landlock_is_enabled();
- attr_abi1->handled_access_fs =
- attr_abi4->handled_access_fs = LANDLOCK_ACCESS_FS_EXECUTE;
+ attr_abi1->handled_access_fs = LANDLOCK_ACCESS_FS_EXECUTE;
+ attr_abi4->handled_access_fs = LANDLOCK_ACCESS_FS_EXECUTE;
+ attr_abi6->handled_access_fs = LANDLOCK_ACCESS_FS_EXECUTE;
if (abi_current < 4) {
ruleset_fd = TST_EXP_FD_SILENT(tst_syscall(__NR_landlock_create_ruleset,
attr_abi1, sizeof(struct tst_landlock_ruleset_attr_abi1), 0));
- } else {
+ } else if (abi_current < 6) {
ruleset_fd = TST_EXP_FD_SILENT(tst_syscall(__NR_landlock_create_ruleset,
attr_abi4, sizeof(struct tst_landlock_ruleset_attr_abi4), 0));
+ } else {
+ ruleset_fd = TST_EXP_FD_SILENT(tst_syscall(__NR_landlock_create_ruleset,
+ attr_abi6, sizeof(struct tst_landlock_ruleset_attr_abi6), 0));
}
}
@@ -171,6 +176,7 @@ static struct tst_test test = {
.bufs = (struct tst_buffers []) {
{&attr_abi1, .size = sizeof(struct tst_landlock_ruleset_attr_abi1)},
{&attr_abi4, .size = sizeof(struct tst_landlock_ruleset_attr_abi4)},
+ {&attr_abi6, .size = sizeof(struct tst_landlock_ruleset_attr_abi6)},
{&path_beneath_attr, .size = sizeof(struct landlock_path_beneath_attr)},
{&net_port_attr, .size = sizeof(struct landlock_net_port_attr)},
{},
--
2.43.0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply related [flat|nested] 6+ messages in thread* [LTP] [PATCH v4 3/4] landlock: add landlock09 test
2025-05-27 10:54 [LTP] [PATCH v4 0/4] Landlock tests for ABI v6 Andrea Cervesato
2025-05-27 10:54 ` [LTP] [PATCH v4 1/4] Add landlock ABI v6 fallback Andrea Cervesato
2025-05-27 10:54 ` [LTP] [PATCH v4 2/4] landlock02: support landlock ABI v6 Andrea Cervesato
@ 2025-05-27 10:54 ` Andrea Cervesato
2025-05-27 10:54 ` [LTP] [PATCH v4 4/4] landlock: add landlock10 test Andrea Cervesato
2025-06-05 12:38 ` [LTP] [PATCH v4 0/4] Landlock tests for ABI v6 Andrea Cervesato via ltp
4 siblings, 0 replies; 6+ messages in thread
From: Andrea Cervesato @ 2025-05-27 10:54 UTC (permalink / raw)
To: ltp
From: Andrea Cervesato <andrea.cervesato@suse.com>
Create landlock09 test in order to verify that sandboxed processes
enforced with LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET rule can't
connect to any UNIX socket from non-sandboxed processes.
Reviewed-by: Cyril Hrubis <chrubis@suse.cz>
Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
runtest/syscalls | 1 +
testcases/kernel/syscalls/landlock/.gitignore | 1 +
testcases/kernel/syscalls/landlock/landlock09.c | 131 +++++++++++++++++++++
.../kernel/syscalls/landlock/landlock_common.h | 11 ++
4 files changed, 144 insertions(+)
diff --git a/runtest/syscalls b/runtest/syscalls
index e7bc7b27b604e0f0f69b6bad99955662c6c58a91..d37c43f20bf292b58b10a8531eeaff295f6c1ab1 100644
--- a/runtest/syscalls
+++ b/runtest/syscalls
@@ -712,6 +712,7 @@ landlock05 landlock05
landlock06 landlock06
landlock07 landlock07
landlock08 landlock08
+landlock09 landlock09
lchown01 lchown01
lchown01_16 lchown01_16
diff --git a/testcases/kernel/syscalls/landlock/.gitignore b/testcases/kernel/syscalls/landlock/.gitignore
index fc7317394948c4ac20cd14c3cd7ba7a47282b2bf..cda8d871e051ec88abba4634a2bcda4b10470d9f 100644
--- a/testcases/kernel/syscalls/landlock/.gitignore
+++ b/testcases/kernel/syscalls/landlock/.gitignore
@@ -7,3 +7,4 @@ landlock05
landlock06
landlock07
landlock08
+landlock09
diff --git a/testcases/kernel/syscalls/landlock/landlock09.c b/testcases/kernel/syscalls/landlock/landlock09.c
new file mode 100644
index 0000000000000000000000000000000000000000..2e7f0021299152a1dbd0d7d7594487f551f04a24
--- /dev/null
+++ b/testcases/kernel/syscalls/landlock/landlock09.c
@@ -0,0 +1,131 @@
+// SPDX-License-Identifier: GPL-2.0-or-later
+/*
+ * Copyright (C) 2025 SUSE LLC Andrea Cervesato <andrea.cervesato@suse.com>
+ */
+
+/*\
+ * Verify that landlock's LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET rule reject any
+ * connect() coming from a client on a different server domain, but accept any
+ * connection.
+ */
+
+#include <stddef.h>
+#include "tst_test.h"
+#include "landlock_common.h"
+
+#define SOCKET_NAME "test.sock"
+#define ABSTRACT_SOCKET_NAME "\0"SOCKET_NAME
+#define SOCKET_LENGTH (offsetof(struct sockaddr_un, sun_path) + strlen(SOCKET_NAME) + 1)
+
+enum {
+ DOMAIN_CLIENT = 0,
+ DOMAIN_SERVER,
+ DOMAIN_BOTH,
+};
+
+static struct tst_landlock_ruleset_attr_abi6 *ruleset_attr;
+
+static void scoped_sandbox(const char *from)
+{
+ tst_res(TINFO, "Enforcing rule LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET on %s", from);
+
+ ruleset_attr->scoped = LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET;
+ apply_landlock_scoped_layer(ruleset_attr, sizeof(*ruleset_attr));
+}
+
+static void run_client(void)
+{
+ if (tst_variant == DOMAIN_CLIENT)
+ scoped_sandbox("client");
+
+ int sendsock;
+ struct sockaddr_un addr = {
+ .sun_family = AF_UNIX,
+ .sun_path = ABSTRACT_SOCKET_NAME,
+ };
+
+ TST_CHECKPOINT_WAIT(0);
+
+ tst_res(TINFO, "Connecting to UNIX socket");
+
+ sendsock = SAFE_SOCKET(AF_UNIX, SOCK_STREAM, 0);
+
+ if (tst_variant != DOMAIN_CLIENT)
+ TST_EXP_PASS(connect(sendsock, (struct sockaddr *)&addr, SOCKET_LENGTH));
+ else
+ TST_EXP_FAIL(connect(sendsock, (struct sockaddr *)&addr, SOCKET_LENGTH), EPERM);
+
+ SAFE_CLOSE(sendsock);
+
+ TST_CHECKPOINT_WAKE(0);
+}
+
+static void run_server(void)
+{
+ if (tst_variant == DOMAIN_SERVER)
+ scoped_sandbox("server");
+
+ int recvsock;
+ struct sockaddr_un addr = {
+ .sun_family = AF_UNIX,
+ .sun_path = ABSTRACT_SOCKET_NAME,
+ };
+
+ recvsock = SAFE_SOCKET(AF_UNIX, SOCK_STREAM, 0);
+
+ SAFE_BIND(recvsock, (struct sockaddr *)&addr, SOCKET_LENGTH);
+ SAFE_LISTEN(recvsock, 5);
+
+ tst_res(TINFO, "Listening on UNIX socket");
+
+ TST_CHECKPOINT_WAKE_AND_WAIT(0);
+
+ SAFE_CLOSE(recvsock);
+}
+
+static void run(void)
+{
+ /* isolate test inside a process so we won't stack too many
+ * layers (-E2BIG) when there are multiple test's iterations
+ */
+ if (SAFE_FORK())
+ return;
+
+ if (tst_variant == DOMAIN_BOTH)
+ scoped_sandbox("server and client");
+
+ if (!SAFE_FORK()) {
+ run_client();
+ exit(0);
+ }
+
+ run_server();
+
+ tst_reap_children();
+}
+
+static void setup(void)
+{
+ int abi;
+
+ abi = verify_landlock_is_enabled();
+ if (abi < 6)
+ tst_brk(TCONF, "LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET is unsupported on ABI < 6");
+}
+
+static struct tst_test test = {
+ .test_all = run,
+ .setup = setup,
+ .needs_root = 1,
+ .forks_child = 1,
+ .needs_checkpoints = 1,
+ .test_variants = 3,
+ .bufs = (struct tst_buffers []) {
+ {&ruleset_attr, .size = sizeof(struct tst_landlock_ruleset_attr_abi6)},
+ {},
+ },
+ .caps = (struct tst_cap []) {
+ TST_CAP(TST_CAP_REQ, CAP_SYS_ADMIN),
+ {}
+ },
+};
diff --git a/testcases/kernel/syscalls/landlock/landlock_common.h b/testcases/kernel/syscalls/landlock/landlock_common.h
index 4aa11b7d2ad46915cd1ce1592bdaa2fb6ad77628..8857745d6f1c1c30fc914924b8d0da381b36059f 100644
--- a/testcases/kernel/syscalls/landlock/landlock_common.h
+++ b/testcases/kernel/syscalls/landlock/landlock_common.h
@@ -115,6 +115,17 @@ static inline void apply_landlock_net_layer(
SAFE_CLOSE(ruleset_fd);
}
+static inline void apply_landlock_scoped_layer(
+ void *ruleset_attr, size_t attr_size)
+{
+ int ruleset_fd;
+
+ ruleset_fd = SAFE_LANDLOCK_CREATE_RULESET(ruleset_attr, attr_size, 0);
+ enforce_ruleset(ruleset_fd);
+
+ SAFE_CLOSE(ruleset_fd);
+}
+
static inline in_port_t getsocket_port(struct socket_data *socket,
const int addr_family)
{
--
2.43.0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply related [flat|nested] 6+ messages in thread* [LTP] [PATCH v4 4/4] landlock: add landlock10 test
2025-05-27 10:54 [LTP] [PATCH v4 0/4] Landlock tests for ABI v6 Andrea Cervesato
` (2 preceding siblings ...)
2025-05-27 10:54 ` [LTP] [PATCH v4 3/4] landlock: add landlock09 test Andrea Cervesato
@ 2025-05-27 10:54 ` Andrea Cervesato
2025-06-05 12:38 ` [LTP] [PATCH v4 0/4] Landlock tests for ABI v6 Andrea Cervesato via ltp
4 siblings, 0 replies; 6+ messages in thread
From: Andrea Cervesato @ 2025-05-27 10:54 UTC (permalink / raw)
To: ltp
From: Andrea Cervesato <andrea.cervesato@suse.com>
Verify that landlock's LANDLOCK_SCOPE_SIGNAL rule rejects any
signal coming from a process on a different domain, but accept
signals from processes in the same domain.
Reviewed-by: Cyril Hrubis <chrubis@suse.cz>
Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
runtest/syscalls | 1 +
testcases/kernel/syscalls/landlock/.gitignore | 1 +
testcases/kernel/syscalls/landlock/landlock10.c | 108 ++++++++++++++++++++++++
3 files changed, 110 insertions(+)
diff --git a/runtest/syscalls b/runtest/syscalls
index d37c43f20bf292b58b10a8531eeaff295f6c1ab1..12e09c2ca328afb0425be13179ee22f6d0d979ce 100644
--- a/runtest/syscalls
+++ b/runtest/syscalls
@@ -713,6 +713,7 @@ landlock06 landlock06
landlock07 landlock07
landlock08 landlock08
landlock09 landlock09
+landlock10 landlock10
lchown01 lchown01
lchown01_16 lchown01_16
diff --git a/testcases/kernel/syscalls/landlock/.gitignore b/testcases/kernel/syscalls/landlock/.gitignore
index cda8d871e051ec88abba4634a2bcda4b10470d9f..8c88803df4580605da800c414ada62994b35d268 100644
--- a/testcases/kernel/syscalls/landlock/.gitignore
+++ b/testcases/kernel/syscalls/landlock/.gitignore
@@ -8,3 +8,4 @@ landlock06
landlock07
landlock08
landlock09
+landlock10
diff --git a/testcases/kernel/syscalls/landlock/landlock10.c b/testcases/kernel/syscalls/landlock/landlock10.c
new file mode 100644
index 0000000000000000000000000000000000000000..a29e3bca82fe813e9e2dbec5f1f0f42db9ebf367
--- /dev/null
+++ b/testcases/kernel/syscalls/landlock/landlock10.c
@@ -0,0 +1,108 @@
+// SPDX-License-Identifier: GPL-2.0-or-later
+/*
+ * Copyright (C) 2025 SUSE LLC Andrea Cervesato <andrea.cervesato@suse.com>
+ */
+
+/*\
+ * Verify that landlock's LANDLOCK_SCOPE_SIGNAL rule rejects any signal coming
+ * from a process on a different domain, but accept signals from processes in
+ * the same domain.
+ */
+
+#include "tst_test.h"
+#include "landlock_common.h"
+
+static struct tst_landlock_ruleset_attr_abi6 *ruleset_attr;
+
+enum {
+ DOMAIN_PAUSED = 0,
+ DOMAIN_KILLER,
+ DOMAIN_BOTH,
+};
+
+static void scoped_sandbox(const char *from)
+{
+ tst_res(TINFO, "Enforcing rule LANDLOCK_SCOPE_SIGNAL for %s process", from);
+
+ ruleset_attr->scoped = LANDLOCK_SCOPE_SIGNAL;
+ apply_landlock_scoped_layer(ruleset_attr, sizeof(*ruleset_attr));
+}
+
+static void run(void)
+{
+ /* isolate test inside a process so we won't stack too many
+ * layers (-E2BIG) when there are multiple test's iterations
+ */
+ if (SAFE_FORK())
+ return;
+
+ if (tst_variant == DOMAIN_BOTH)
+ scoped_sandbox("paused and killer");
+
+ pid_t paused_pid;
+ pid_t killer_pid;
+
+ paused_pid = SAFE_FORK();
+ if (!paused_pid) {
+ if (tst_variant == DOMAIN_PAUSED)
+ scoped_sandbox("paused");
+
+ TST_CHECKPOINT_WAKE(0);
+ pause();
+ exit(0);
+ }
+
+ TST_CHECKPOINT_WAIT(0);
+ TST_PROCESS_STATE_WAIT(paused_pid, 'S', 10000);
+
+ killer_pid = SAFE_FORK();
+ if (!killer_pid) {
+ if (tst_variant == DOMAIN_KILLER)
+ scoped_sandbox("killer");
+
+ TST_CHECKPOINT_WAKE(0);
+
+ if (tst_variant == DOMAIN_KILLER)
+ TST_EXP_FAIL(kill(paused_pid, SIGKILL), EPERM);
+ else
+ TST_EXP_PASS(kill(paused_pid, SIGKILL));
+
+ exit(0);
+ }
+
+ TST_CHECKPOINT_WAIT(0);
+ SAFE_WAITPID(killer_pid, NULL, 0);
+
+ if (kill(paused_pid, SIGKILL) == -1) {
+ if (errno != ESRCH)
+ tst_brk(TBROK | TERRNO, "kill(%u, SIGKILL) error", paused_pid);
+ }
+
+ SAFE_WAITPID(paused_pid, NULL, 0);
+}
+
+static void setup(void)
+{
+ int abi;
+
+ abi = verify_landlock_is_enabled();
+ if (abi < 6)
+ tst_brk(TCONF, "LANDLOCK_SCOPE_SIGNAL is unsupported on ABI < 6");
+}
+
+static struct tst_test test = {
+ .test_all = run,
+ .setup = setup,
+ .needs_root = 1,
+ .forks_child = 1,
+ .needs_checkpoints = 1,
+ .test_variants = 3,
+ .bufs = (struct tst_buffers []) {
+ {&ruleset_attr, .size = sizeof(struct tst_landlock_ruleset_attr_abi6)},
+ {},
+ },
+ .caps = (struct tst_cap []) {
+ TST_CAP(TST_CAP_REQ, CAP_SYS_ADMIN),
+ {}
+ },
+};
--
2.43.0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply related [flat|nested] 6+ messages in thread* Re: [LTP] [PATCH v4 0/4] Landlock tests for ABI v6
2025-05-27 10:54 [LTP] [PATCH v4 0/4] Landlock tests for ABI v6 Andrea Cervesato
` (3 preceding siblings ...)
2025-05-27 10:54 ` [LTP] [PATCH v4 4/4] landlock: add landlock10 test Andrea Cervesato
@ 2025-06-05 12:38 ` Andrea Cervesato via ltp
4 siblings, 0 replies; 6+ messages in thread
From: Andrea Cervesato via ltp @ 2025-06-05 12:38 UTC (permalink / raw)
To: Andrea Cervesato, ltp
Merged, thanks!
- Andrea
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 6+ messages in thread