From: Cyril Hrubis <chrubis@suse.cz>
To: Andrea Cervesato <andrea.cervesato@suse.de>
Cc: Linux Test Project <ltp@lists.linux.it>
Subject: Re: [LTP] [PATCH v2 13/33] keyctl21: Negative and boundary tests for KEYCTL_MOVE
Date: Fri, 11 Sep 2026 14:11:48 +0200 [thread overview]
Message-ID: <aqPwBHMeuGApyhzG@yuki.lan> (raw)
In-Reply-To: <20260904-keyctl_coverage-v2-13-43b78b15ef9f@suse.com>
Hi!
> Test error and boundary conditions of KEYCTL_MOVE using a
> parameterized tcase table: KEYCTL_MOVE_EXCL (EEXIST), unknown flag
> bits (EINVAL), bogus IDs (ENOKEY), non-keyrings (ENOTDIR), unlinked
> key (ENOENT), keyring cycle (EDEADLK), and destination without
> Write permission (EACCES).
>
> Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
> ---
> runtest/syscalls | 1 +
> testcases/kernel/syscalls/keyctl/.gitignore | 1 +
> testcases/kernel/syscalls/keyctl/keyctl21.c | 111 ++++++++++++++++++++++++++++
> 3 files changed, 113 insertions(+)
>
> diff --git a/runtest/syscalls b/runtest/syscalls
> index bfe4090a0..b95264564 100644
> --- a/runtest/syscalls
> +++ b/runtest/syscalls
> @@ -738,6 +738,7 @@ keyctl17 keyctl17
> keyctl18 keyctl18
> keyctl19 keyctl19
> keyctl20 keyctl20
> +keyctl21 keyctl21
>
> kcmp01 kcmp01
> kcmp02 kcmp02
> diff --git a/testcases/kernel/syscalls/keyctl/.gitignore b/testcases/kernel/syscalls/keyctl/.gitignore
> index acddfa79e..e8c71e79e 100644
> --- a/testcases/kernel/syscalls/keyctl/.gitignore
> +++ b/testcases/kernel/syscalls/keyctl/.gitignore
> @@ -18,3 +18,4 @@
> /keyctl18
> /keyctl19
> /keyctl20
> +/keyctl21
> diff --git a/testcases/kernel/syscalls/keyctl/keyctl21.c b/testcases/kernel/syscalls/keyctl/keyctl21.c
> new file mode 100644
> index 000000000..a2db5a406
> --- /dev/null
> +++ b/testcases/kernel/syscalls/keyctl/keyctl21.c
> @@ -0,0 +1,111 @@
> +// SPDX-License-Identifier: GPL-2.0-or-later
> +/*
> + * Copyright (c) 2026 Andrea Cervesato <andrea.cervesato@suse.com>
> + */
> +
> +/*\
> + * Negative and boundary test cases for ``KEYCTL_MOVE`` of :manpage:`keyctl(2)`.
> + *
> + * [Algorithm]
> + *
> + * - ``KEYCTL_MOVE_EXCL`` fails with ``EEXIST`` when the destination already
> + * holds a matching key
> + * - unknown flag bits are rejected with ``EINVAL``
> + * - bogus key or keyring ids fail with ``ENOKEY``
> + * - a plain key used as source or destination keyring fails with ``ENOTDIR``
> + * - moving a key that is not linked in the source fails with ``ENOENT``
> + * - moving a keyring into itself fails with ``EDEADLK`` from the keyring
> + * cycle detection
> + * - moving into a keyring without Write permission fails with ``EACCES``
> + */
> +
> +#include "keyctl_common.h"
> +
> +#define RING_A_DESC "ltpkeyctl21_a"
> +#define RING_B_DESC "ltpkeyctl21_b"
> +#define RING_C_DESC "ltpkeyctl21_c"
> +#define KEY_A_DESC "ka"
> +#define KEY_B_DESC "kb"
> +#define PAYLOAD "payload"
> +
> +static key_serial_t ring_a, ring_b, ring_c, ring_no_write;
> +static key_serial_t key_a, key_b, key_excl;
> +static key_serial_t bogus_id = INT32_MAX;
> +
> +static struct tcase {
> + key_serial_t *keyid;
> + key_serial_t *from;
> + key_serial_t *to;
> + unsigned int flags;
> + int exp_errno;
> + const char *desc;
> +} tcases[] = {
> + { &key_a, &ring_a, &ring_b, KEYCTL_MOVE_EXCL,
> + EEXIST, "KEYCTL_MOVE_EXCL on existing key" },
> +
> + { &key_a, &ring_a, &ring_b, 0x2,
> + EINVAL, "unknown flag bits" },
> +
> + { &bogus_id, &ring_a, &ring_b, 0,
> + ENOKEY, "bogus key id" },
> +
> + { &key_a, &bogus_id, &ring_b, 0,
> + ENOKEY, "bogus source keyring" },
> +
> + { &key_a, &ring_a, &bogus_id, 0,
> + ENOKEY, "bogus destination keyring" },
> +
> + { &key_a, &key_b, &ring_b, 0,
> + ENOTDIR, "plain key as source keyring" },
> +
> + { &key_a, &ring_a, &key_b, 0,
> + ENOTDIR, "plain key as destination keyring" },
> +
> + { &key_b, &ring_a, &ring_b, 0,
> + ENOENT, "key not linked in the source keyring" },
> +
> + { &ring_c, &ring_b, &ring_c, 0,
> + EDEADLK, "keyring into itself" },
> +
> + { &key_a, &ring_a, &ring_no_write, 0,
> + EACCES, "destination without Write permission" },
> +};
> +
> +static void setup(void)
> +{
> + SAFE_KEYCTL(KEYCTL_JOIN_SESSION_KEYRING, 0, 0, 0, 0);
> +
> + ring_a = new_ring(RING_A_DESC);
> + ring_b = new_ring(RING_B_DESC);
> + ring_c = new_ring(RING_C_DESC);
> + ring_no_write = new_ring("ltpkeyctl21_nowrite");
> + SAFE_KEYCTL(KEYCTL_SETPERM, ring_no_write, KEY_PERM_NO_WRITE, 0, 0);
> +
> + key_a = new_user_key(KEY_A_DESC, PAYLOAD, sizeof(PAYLOAD), ring_a);
> + key_b = new_user_key(KEY_B_DESC, PAYLOAD, sizeof(PAYLOAD), ring_b);
> + key_excl = new_user_key(KEY_A_DESC, PAYLOAD, sizeof(PAYLOAD), ring_b);
Same here, the new_ring and new_user_key should have been SAFE_..
macros.
Other than that it looks fine.
--
Cyril Hrubis
chrubis@suse.cz
--
Mailing list info: https://lists.linux.it/listinfo/ltp
next prev parent reply other threads:[~2026-09-11 12:12 UTC|newest]
Thread overview: 60+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 12:08 [LTP] [PATCH v2 00/33] Improve coverage for keyctl() syscall Andrea Cervesato
2026-09-04 12:08 ` [LTP] [PATCH v2 01/33] lapi/keyctl.h: Add fallback definitions for extended ops Andrea Cervesato
2026-09-04 15:18 ` [LTP] " linuxtestproject.agent
2026-09-11 7:31 ` [LTP] [PATCH v2 01/33] " Cyril Hrubis
2026-09-11 8:58 ` Petr Vorel
2026-09-04 12:08 ` [LTP] [PATCH v2 02/33] keyctl10: Test KEYCTL_DESCRIBE format parsing Andrea Cervesato
2026-09-11 7:54 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 03/33] keyctl11: Test KEYCTL_DESCRIBE with exact buffer size Andrea Cervesato
2026-09-11 8:01 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 04/33] keyctl12: Test KEYCTL_DESCRIBE with too small buffer Andrea Cervesato
2026-09-11 8:09 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 05/33] keyctl13: Test KEYCTL_DESCRIBE size query Andrea Cervesato
2026-09-04 12:08 ` [LTP] [PATCH v2 06/33] keyctl14: Negative tests for KEYCTL_DESCRIBE Andrea Cervesato
2026-09-11 8:17 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 07/33] keyctl15: Test KEYCTL_GET_SECURITY label retrieval Andrea Cervesato
2026-09-11 8:20 ` Cyril Hrubis
2026-09-11 9:11 ` Petr Vorel
2026-09-11 15:34 ` Cyril Hrubis
2026-09-11 19:24 ` Petr Vorel
2026-09-04 12:08 ` [LTP] [PATCH v2 08/33] keyctl16: Test KEYCTL_GET_SECURITY truncated copy Andrea Cervesato
2026-09-11 8:30 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 09/33] keyctl17: Negative tests for KEYCTL_GET_SECURITY Andrea Cervesato
2026-09-11 8:40 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 10/33] keyctl18: Test basic KEYCTL_MOVE Andrea Cervesato
2026-09-11 11:48 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 11/33] keyctl19: Test KEYCTL_MOVE with same source and destination Andrea Cervesato
2026-09-11 11:52 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 12/33] keyctl20: Test KEYCTL_MOVE displacement Andrea Cervesato
2026-09-11 12:00 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 13/33] keyctl21: Negative and boundary tests for KEYCTL_MOVE Andrea Cervesato
2026-09-11 12:11 ` Cyril Hrubis [this message]
2026-09-04 12:09 ` [LTP] [PATCH v2 14/33] keyctl22: Test KEYCTL_RESTRICT_KEYRING reject-all Andrea Cervesato
2026-09-11 12:13 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 15/33] keyctl23: Test KEYCTL_RESTRICT_KEYRING builtin_trusted Andrea Cervesato
2026-09-11 12:34 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 16/33] keyctl24: Negative tests for KEYCTL_RESTRICT_KEYRING Andrea Cervesato
2026-09-11 14:36 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 17/33] keyctl25: Test KEYCTL_DH_COMPUTE shared secret computation Andrea Cervesato
2026-09-11 14:53 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 18/33] keyctl26: Test KEYCTL_DH_COMPUTE size query Andrea Cervesato
2026-09-11 14:54 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 19/33] keyctl27: Test KEYCTL_DH_COMPUTE KDF key derivation Andrea Cervesato
2026-09-11 15:05 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 20/33] keyctl28: Negative and boundary tests for KEYCTL_DH_COMPUTE Andrea Cervesato
2026-09-11 15:17 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 21/33] lapi/keyctl.h: Add fallback definitions for public key ops Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 22/33] keyctl29: Test KEYCTL_PKEY_QUERY on public key Andrea Cervesato
2026-09-11 15:35 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 23/33] keyctl30: Test KEYCTL_PKEY_QUERY on private key Andrea Cervesato
2026-09-11 15:37 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 24/33] keyctl31: Test KEYCTL_PKEY_ENCRYPT and KEYCTL_PKEY_DECRYPT Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 25/33] keyctl32: Test KEYCTL_PKEY_SIGN and VERIFY Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 26/33] keyctl33: Negative tests for KEYCTL_PKEY_* Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 27/33] lapi/keyctl.h: Add capability fallback defines Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 28/33] keyctl34: Test KEYCTL_CAPABILITIES flag retrieval Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 29/33] keyctl35: Test KEYCTL_CAPABILITIES size query Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 30/33] keyctl36: Test KEYCTL_CAPABILITIES buffer sizing Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 31/33] keyctl37: Negative tests for KEYCTL_CAPABILITIES Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 32/33] keyctl38: Test KEYCTL_WATCH_KEY add and remove Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 33/33] keyctl39: Negative tests for KEYCTL_WATCH_KEY Andrea Cervesato
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aqPwBHMeuGApyhzG@yuki.lan \
--to=chrubis@suse.cz \
--cc=andrea.cervesato@suse.de \
--cc=ltp@lists.linux.it \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.