From: Cyril Hrubis <chrubis@suse.cz>
To: Andrea Cervesato <andrea.cervesato@suse.de>
Cc: Linux Test Project <ltp@lists.linux.it>
Subject: Re: [LTP] [PATCH v2 16/33] keyctl24: Negative tests for KEYCTL_RESTRICT_KEYRING
Date: Fri, 11 Sep 2026 16:36:07 +0200 [thread overview]
Message-ID: <aqQR19a4HTcHxPXs@yuki.lan> (raw)
In-Reply-To: <20260904-keyctl_coverage-v2-16-43b78b15ef9f@suse.com>
> +/*
> + * A tcase with .id = NULL asks verify_negative() to allocate a fresh
> + * unrestricted keyring for the case and unlink it afterwards, so that a
> + * false-positive result cannot restrict a ring shared with later cases.
> + * .self_cycle asks for a "key_or_keyring:<fresh>:chain" restriction string
> + * pointing back at that fresh ring, needed for the EDEADLK check.
> + */
> +static struct tcase {
> + key_serial_t *id;
> + int self_cycle;
> + const char *type;
> + const char *restriction;
> + int exp_errno;
> + int needs_asym;
> + const char *desc;
> +} tcases[] = {
> + {
> + .restriction = "builtin_trusted",
> + .exp_errno = EINVAL,
> + .desc = "NULL type and non-NULL restriction",
> + },
> + {
> + .type = "asymmetric",
> + .exp_errno = EINVAL,
> + .desc = "non-NULL type and NULL restriction",
> + },
> + {
> + .id = &user_key,
> + .exp_errno = ENOTDIR,
> + .desc = "non-keyring key",
> + },
> + {
> + .type = "nosuchtype",
> + .restriction = "builtin_trusted",
> + .exp_errno = ENOKEY,
> + .desc = "unknown key type",
> + },
> + {
> + .type = "user",
> + .restriction = "builtin_trusted",
> + .exp_errno = ENOENT,
> + .desc = "key type having no lookup_restriction",
> + },
> + {
> + .type = "asymmetric",
> + .restriction = "bogus",
> + .exp_errno = EINVAL,
> + .needs_asym = 1,
> + .desc = "asymmetric with invalid restriction string",
> + },
> + {
> + .type = "asymmetric",
> + .restriction = "key_or_keyring:2147483647",
> + .exp_errno = ENOKEY,
> + .needs_asym = 1,
> + .desc = "asymmetric with bogus key serial",
> + },
> + {
> + .id = &ring_reject,
> + .exp_errno = EEXIST,
> + .desc = "already restricted keyring",
> + },
> + {
> + .self_cycle = 1,
> + .type = "asymmetric",
> + .exp_errno = EDEADLK,
> + .needs_asym = 1,
> + .desc = "self-referencing key_or_keyring chain",
> + },
> + {
> + .id = &ring_no_setattr,
> + .exp_errno = EACCES,
> + .desc = "keyring without Setattr permission",
> + },
> +};
> +
> +static void setup(void)
> +{
> + key_serial_t probe_ring;
> +
> + SAFE_KEYCTL(KEYCTL_JOIN_SESSION_KEYRING, 0, 0, 0, 0);
> +
> + ring_reject = new_ring("ltpkeyctl24_reject");
> + ring_no_setattr = new_ring("ltpkeyctl24_no_setattr");
> + SAFE_KEYCTL(KEYCTL_SETPERM, ring_no_setattr, KEY_PERM_NO_SETATTR, 0, 0);
> +
> + /* Permanently restrict ring_reject with reject-all for EEXIST test */
> + SAFE_KEYCTL(KEYCTL_RESTRICT_KEYRING, ring_reject, 0, 0, 0);
> +
> + user_key = new_user_key("k", "payload", 7, KEY_SPEC_PROCESS_KEYRING);
> +
> + /* Probe asymmetric support on a throwaway ring so we cannot poison
> + * any ring reused later by the tcase table.
> + */
> + probe_ring = new_ring("ltpkeyctl24_probe");
> + TEST(keyctl(KEYCTL_RESTRICT_KEYRING, probe_ring,
> + (unsigned long)"asymmetric", (unsigned long)"bogus", 0));
> + asym_supported = (TST_RET != -1 || TST_ERR != ENODEV);
> + keyctl(KEYCTL_UNLINK, probe_ring, KEY_SPEC_PROCESS_KEYRING, 0, 0);
> +}
> +
> +static void verify_negative(unsigned int n)
> +{
> + struct tcase *tc = &tcases[n];
> + key_serial_t id, fresh_ring = 0;
> + const char *restriction = tc->restriction;
> + char cycle_buf[64];
> +
> + if (tc->needs_asym && !asym_supported) {
> + tst_res(TCONF, "asymmetric key type not supported");
> + return;
> + }
> +
> + if (tc->id) {
> + id = *tc->id;
> + } else {
> + fresh_ring = new_ring("ltpkeyctl24_fresh");
> + id = fresh_ring;
> + if (tc->self_cycle) {
> + snprintf(cycle_buf, sizeof(cycle_buf),
> + "key_or_keyring:%d:chain", fresh_ring);
> + restriction = cycle_buf;
> + }
Maybe it would have been better if we moved the self cycle test to a
seprate testcase, instead of adding special cases to this test...
> + }
> +
> + TST_EXP_FAIL(keyctl(KEYCTL_RESTRICT_KEYRING, (unsigned long)id,
> + (unsigned long)tc->type,
> + (unsigned long)restriction, 0),
> + tc->exp_errno,
> + "KEYCTL_RESTRICT_KEYRING with %s", tc->desc);
> +
> + if (fresh_ring)
> + keyctl(KEYCTL_UNLINK, fresh_ring, KEY_SPEC_PROCESS_KEYRING,
> + 0, 0);
> +}
> +
> +static struct tst_test test = {
> + .setup = setup,
> + .test = verify_negative,
> + .tcnt = ARRAY_SIZE(tcases),
> + .min_kver = "4.12",
> +};
>
> --
> 2.51.0
>
>
> --
> Mailing list info: https://lists.linux.it/listinfo/ltp
--
Cyril Hrubis
chrubis@suse.cz
--
Mailing list info: https://lists.linux.it/listinfo/ltp
next prev parent reply other threads:[~2026-09-11 14:36 UTC|newest]
Thread overview: 60+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 12:08 [LTP] [PATCH v2 00/33] Improve coverage for keyctl() syscall Andrea Cervesato
2026-09-04 12:08 ` [LTP] [PATCH v2 01/33] lapi/keyctl.h: Add fallback definitions for extended ops Andrea Cervesato
2026-09-04 15:18 ` [LTP] " linuxtestproject.agent
2026-09-11 7:31 ` [LTP] [PATCH v2 01/33] " Cyril Hrubis
2026-09-11 8:58 ` Petr Vorel
2026-09-04 12:08 ` [LTP] [PATCH v2 02/33] keyctl10: Test KEYCTL_DESCRIBE format parsing Andrea Cervesato
2026-09-11 7:54 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 03/33] keyctl11: Test KEYCTL_DESCRIBE with exact buffer size Andrea Cervesato
2026-09-11 8:01 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 04/33] keyctl12: Test KEYCTL_DESCRIBE with too small buffer Andrea Cervesato
2026-09-11 8:09 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 05/33] keyctl13: Test KEYCTL_DESCRIBE size query Andrea Cervesato
2026-09-04 12:08 ` [LTP] [PATCH v2 06/33] keyctl14: Negative tests for KEYCTL_DESCRIBE Andrea Cervesato
2026-09-11 8:17 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 07/33] keyctl15: Test KEYCTL_GET_SECURITY label retrieval Andrea Cervesato
2026-09-11 8:20 ` Cyril Hrubis
2026-09-11 9:11 ` Petr Vorel
2026-09-11 15:34 ` Cyril Hrubis
2026-09-11 19:24 ` Petr Vorel
2026-09-04 12:08 ` [LTP] [PATCH v2 08/33] keyctl16: Test KEYCTL_GET_SECURITY truncated copy Andrea Cervesato
2026-09-11 8:30 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 09/33] keyctl17: Negative tests for KEYCTL_GET_SECURITY Andrea Cervesato
2026-09-11 8:40 ` Cyril Hrubis
2026-09-04 12:08 ` [LTP] [PATCH v2 10/33] keyctl18: Test basic KEYCTL_MOVE Andrea Cervesato
2026-09-11 11:48 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 11/33] keyctl19: Test KEYCTL_MOVE with same source and destination Andrea Cervesato
2026-09-11 11:52 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 12/33] keyctl20: Test KEYCTL_MOVE displacement Andrea Cervesato
2026-09-11 12:00 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 13/33] keyctl21: Negative and boundary tests for KEYCTL_MOVE Andrea Cervesato
2026-09-11 12:11 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 14/33] keyctl22: Test KEYCTL_RESTRICT_KEYRING reject-all Andrea Cervesato
2026-09-11 12:13 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 15/33] keyctl23: Test KEYCTL_RESTRICT_KEYRING builtin_trusted Andrea Cervesato
2026-09-11 12:34 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 16/33] keyctl24: Negative tests for KEYCTL_RESTRICT_KEYRING Andrea Cervesato
2026-09-11 14:36 ` Cyril Hrubis [this message]
2026-09-04 12:09 ` [LTP] [PATCH v2 17/33] keyctl25: Test KEYCTL_DH_COMPUTE shared secret computation Andrea Cervesato
2026-09-11 14:53 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 18/33] keyctl26: Test KEYCTL_DH_COMPUTE size query Andrea Cervesato
2026-09-11 14:54 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 19/33] keyctl27: Test KEYCTL_DH_COMPUTE KDF key derivation Andrea Cervesato
2026-09-11 15:05 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 20/33] keyctl28: Negative and boundary tests for KEYCTL_DH_COMPUTE Andrea Cervesato
2026-09-11 15:17 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 21/33] lapi/keyctl.h: Add fallback definitions for public key ops Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 22/33] keyctl29: Test KEYCTL_PKEY_QUERY on public key Andrea Cervesato
2026-09-11 15:35 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 23/33] keyctl30: Test KEYCTL_PKEY_QUERY on private key Andrea Cervesato
2026-09-11 15:37 ` Cyril Hrubis
2026-09-04 12:09 ` [LTP] [PATCH v2 24/33] keyctl31: Test KEYCTL_PKEY_ENCRYPT and KEYCTL_PKEY_DECRYPT Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 25/33] keyctl32: Test KEYCTL_PKEY_SIGN and VERIFY Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 26/33] keyctl33: Negative tests for KEYCTL_PKEY_* Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 27/33] lapi/keyctl.h: Add capability fallback defines Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 28/33] keyctl34: Test KEYCTL_CAPABILITIES flag retrieval Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 29/33] keyctl35: Test KEYCTL_CAPABILITIES size query Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 30/33] keyctl36: Test KEYCTL_CAPABILITIES buffer sizing Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 31/33] keyctl37: Negative tests for KEYCTL_CAPABILITIES Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 32/33] keyctl38: Test KEYCTL_WATCH_KEY add and remove Andrea Cervesato
2026-09-04 12:09 ` [LTP] [PATCH v2 33/33] keyctl39: Negative tests for KEYCTL_WATCH_KEY Andrea Cervesato
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aqQR19a4HTcHxPXs@yuki.lan \
--to=chrubis@suse.cz \
--cc=andrea.cervesato@suse.de \
--cc=ltp@lists.linux.it \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox