From: Petr Vorel <pvorel@suse.cz>
To: zhaogongyi <zhaogongyi@huawei.com>
Cc: Richard Palethorpe <rpalethorpe@suse.com>,
"ltp@lists.linux.it" <ltp@lists.linux.it>,
Martin Doucha <martin.doucha@suse.com>
Subject: Re: [LTP] [PATCH 2/2] needs_root: Add setting of needs_root
Date: Fri, 14 Oct 2022 08:50:55 +0200 [thread overview]
Message-ID: <Y0kGzyqO4o3w6k1i@pevik> (raw)
In-Reply-To: <5eebb471e7dc4cc18758462a918d0596@huawei.com>
Hi all,
> Hi,
> > > > > Hi Petr,
> > > > > It is failed on my system:
> > > > > sh-4.4$ ./msgget03
> > > > > tst_test.c:1535: TINFO: Timeout per run is 0h 00m 30s
> > > > > msgget03.c:42: TINFO: Current environment 0 message queues are
> > > > already
> > > > > in use
> > > > > msgget03.c:45: TBROK: Failed to open FILE
> > '/proc/sys/kernel/msgmni'
> > > > > for writing: EACCES (13)
> > > > Ah, b740bfac5 ("msgget03: Set custom queue limit") causes the need
> > > > for root. IMHO this one is valid.
> > > > I'd suggest to remove needs_root for needs_device and
> > mount_device
> > > > now (i.e. send v2).
> > > Just remove the patch 1 and keep adding needs_root in patch 2?
> > If you haven't added it to any test which would have needs_device or
> > mount_device, then v2 can be kept.
> > But process_vm_readv02 works for me (on master, on Debian) without
> > root:
> > $ ./process_vm_readv02
> > tst_test.c:1526: TINFO: Timeout per run is 0h 00m 30s
> > process_vm_readv02.c:32: TINFO: child 0: memory allocated and
> > initialized
> > process_vm_readv02.c:49: TINFO: child 1: reading string from same
> > memory location
> > process_vm_readv02.c:61: TPASS: expected string received
> > Summary:
> > passed 1
> > failed 0
> > broken 0
> > skipped 0
> > warnings 0
> > Also process_vm_readv03, process_vm_writev02 (I stopped checking
> > now).
> > Why you need it?
> On my system, these testcases failed and report EPERM:
> sh-4.4$ ./process_vm_readv02
OK, your system is Alpine (it can shorten our discussion next time if you report
you have problems on musl - i.e. which kernel and libc + versions you use).
Well, we should first check if this is not a bug in musl or Alpine before
requiring root.
It'd be interesting to know whether tools/testing/selftests/vm/memfd_secret.c
and tools/testing/selftests/x86/test_vsyscall.c also require root.
> tst_test.c:1528: TINFO: Timeout per run is 0h 00m 30s
> process_vm_readv02.c:32: TINFO: child 0: memory allocated and initialized
> process_vm_readv02.c:49: TINFO: child 1: reading string from same memory location
> process_vm_readv02.c:55: TBROK: process_vm_readv: EPERM
> process_vm_readv02.c:107: TFAIL: child 1: exited with 2
Before I wrote to musl ML and/or ptrace maintainer, anybody knows why
__NR_process_vm_readv requires root? Looking at kernel mm/process_vm_access.c,
process_vm_rw() calls process_vm_rw_core(), where:
mm = mm_access(task, PTRACE_MODE_ATTACH_REALCREDS);
if (!mm || IS_ERR(mm)) {
rc = IS_ERR(mm) ? PTR_ERR(mm) : -ESRCH;
/*
* Explicitly map EACCES to EPERM as EPERM is a more
* appropriate error code for process_vw_readv/writev
*/
if (rc == -EACCES)
rc = -EPERM;
goto put_task_struct;
}
=> kernel/fork.c
struct mm_struct *mm_access(struct task_struct *task, unsigned int mode)
{
...
mm = get_task_mm(task);
if (mm && mm != current->mm &&
!ptrace_may_access(task, mode)) {
mmput(mm);
mm = ERR_PTR(-EACCES);
}
=> kernel/ptrace.c
/* Returns 0 on success, -errno on denial. */
static int __ptrace_may_access(struct task_struct *task, unsigned int mode)
{
const struct cred *cred = current_cred(), *tcred;
struct mm_struct *mm;
kuid_t caller_uid;
kgid_t caller_gid;
if (!(mode & PTRACE_MODE_FSCREDS) == !(mode & PTRACE_MODE_REALCREDS)) {
WARN(1, "denying ptrace access check without PTRACE_MODE_*CREDS\n");
return -EPERM;
}
...
rcu_read_unlock();
return -EPERM;
ok:
...
Failing LTP code:
TEST(tst_syscall(__NR_process_vm_readv, pid_alloc, &local, 1UL, &remote,
1UL, 0UL));
if (TST_RET != length)
tst_brk(TBROK, "process_vm_readv: %s", tst_strerrno(-TST_RET));
> Summary:
> passed 0
> failed 1
> broken 1
> skipped 0
> warnings 0
> sh-4.4$ ./process_vm_readv03
> tst_test.c:1528: TINFO: Timeout per run is 0h 00m 30s
> process_vm_readv03.c:165: TINFO: bufsize=1024, remote_iovecs=1024, local_iovecs=8
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 1024 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=1024, remote_iovecs=512, local_iovecs=16
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 1024 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=1024, remote_iovecs=256, local_iovecs=32
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 1024 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=1024, remote_iovecs=128, local_iovecs=64
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 1024 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=1024, remote_iovecs=64, local_iovecs=128
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 1024 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=1024, remote_iovecs=32, local_iovecs=256
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 1024 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=1024, remote_iovecs=16, local_iovecs=512
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 1024 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=1024, remote_iovecs=8, local_iovecs=1024
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 1024 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=131072, remote_iovecs=1024, local_iovecs=8
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 131072 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=131072, remote_iovecs=512, local_iovecs=16
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 131072 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=131072, remote_iovecs=256, local_iovecs=32
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 131072 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=131072, remote_iovecs=128, local_iovecs=64
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 131072 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=131072, remote_iovecs=64, local_iovecs=128
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 131072 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=131072, remote_iovecs=32, local_iovecs=256
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 131072 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=131072, remote_iovecs=16, local_iovecs=512
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 131072 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> process_vm_readv03.c:165: TINFO: bufsize=131072, remote_iovecs=8, local_iovecs=1024
> process_vm_readv03.c:83: TINFO: child_alloc: memory allocated and initialized
> process_vm_readv03.c:110: TINFO: child_read: reading string from same memory location
> process_vm_readv03.c:114: TFAIL: process_vm_read() failed: EPERM (1)
> process_vm_readv03.c:118: TBROK: process_vm_readv: expected 131072 bytes but got -1
> process_vm_readv03.c:185: TFAIL: child_read: exited with 2
> Summary:
> passed 0
> failed 32
> broken 16
> skipped 0
> warnings 0
> sh-4.4$ ./process_vm_writev02
> tst_test.c:1528: TINFO: Timeout per run is 0h 00m 30s
> process_vm_writev02.c:32: TINFO: child 0: allocate memory
> process_vm_writev02.c:55: TINFO: child 1: write to the same memory location
> process_vm_writev02.c:65: TFAIL: tst_syscall(__NR_process_vm_writev, pid_alloc, &local, 1UL, &remote, 1UL, 0UL) failed: EPERM (1)
> process_vm_writev02.c:69: TBROK: process_vm_writev: expected 100000 bytes but got -1
> process_vm_writev02.c:112: TFAIL: write child: exited with 2
> process_vm_writev02.c:45: TFAIL: child 0: found 100000 differences from expected data
> Summary:
> passed 0
> failed 3
> broken 1
> skipped 0
> warnings 0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
next prev parent reply other threads:[~2022-10-14 6:51 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-10-14 2:00 [LTP] [PATCH 2/2] needs_root: Add setting of needs_root zhaogongyi via ltp
2022-10-14 6:50 ` Petr Vorel [this message]
-- strict thread matches above, loose matches on Subject: below --
2022-10-20 12:21 zhaogongyi via ltp
2022-10-14 7:02 zhaogongyi via ltp
2022-10-13 14:03 zhaogongyi via ltp
2022-10-13 22:26 ` Petr Vorel
2022-10-13 7:45 zhaogongyi via ltp
2022-10-13 9:19 ` Petr Vorel
2022-10-12 9:15 [LTP] [PATCH 0/2] Optimization reference to needs_root Zhao Gongyi via ltp
2022-10-12 9:15 ` [LTP] [PATCH 2/2] needs_root: Add setting of needs_root Zhao Gongyi via ltp
2022-10-13 7:41 ` Petr Vorel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Y0kGzyqO4o3w6k1i@pevik \
--to=pvorel@suse.cz \
--cc=ltp@lists.linux.it \
--cc=martin.doucha@suse.com \
--cc=rpalethorpe@suse.com \
--cc=zhaogongyi@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.