Skip to content

Commit a80d605

Browse files
keesshuahkh
authored andcommitted
selftests: kmod: Add module address visibility test
Make sure we don't regress the CAP_SYSLOG behavior of the module address visibility via /proc/modules nor /sys/module/*/sections/*. Cc: Luis Chamberlain <[email protected]> Cc: Shuah Khan <[email protected]> Cc: [email protected] Signed-off-by: Kees Cook <[email protected]> Reviewed-by: Luis Chamberlain <[email protected]> Signed-off-by: Shuah Khan <[email protected]>
1 parent 541f564 commit a80d605

File tree

1 file changed

+36
-0
lines changed
  • tools/testing/selftests/kmod

1 file changed

+36
-0
lines changed

tools/testing/selftests/kmod/kmod.sh

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -63,6 +63,8 @@ ALL_TESTS="$ALL_TESTS 0008:150:1"
6363
ALL_TESTS="$ALL_TESTS 0009:150:1"
6464
ALL_TESTS="$ALL_TESTS 0010:1:1"
6565
ALL_TESTS="$ALL_TESTS 0011:1:1"
66+
ALL_TESTS="$ALL_TESTS 0012:1:1"
67+
ALL_TESTS="$ALL_TESTS 0013:1:1"
6668

6769
# Kselftest framework requirement - SKIP code is 4.
6870
ksft_skip=4
@@ -470,6 +472,38 @@ kmod_test_0011()
470472
echo "$MODPROBE" > /proc/sys/kernel/modprobe
471473
}
472474

475+
kmod_check_visibility()
476+
{
477+
local name="$1"
478+
local cmd="$2"
479+
480+
modprobe $DEFAULT_KMOD_DRIVER
481+
482+
local priv=$(eval $cmd)
483+
local unpriv=$(capsh --drop=CAP_SYSLOG -- -c "$cmd")
484+
485+
if [ "$priv" = "$unpriv" ] || \
486+
[ "${priv:0:3}" = "0x0" ] || \
487+
[ "${unpriv:0:3}" != "0x0" ] ; then
488+
echo "${FUNCNAME[0]}: FAIL, $name visible to unpriv: '$priv' vs '$unpriv'" >&2
489+
exit 1
490+
else
491+
echo "${FUNCNAME[0]}: OK!"
492+
fi
493+
}
494+
495+
kmod_test_0012()
496+
{
497+
kmod_check_visibility /proc/modules \
498+
"grep '^${DEFAULT_KMOD_DRIVER}\b' /proc/modules | awk '{print \$NF}'"
499+
}
500+
501+
kmod_test_0013()
502+
{
503+
kmod_check_visibility '/sys/module/*/sections/*' \
504+
"cat /sys/module/${DEFAULT_KMOD_DRIVER}/sections/.*text | head -n1"
505+
}
506+
473507
list_tests()
474508
{
475509
echo "Test ID list:"
@@ -489,6 +523,8 @@ list_tests()
489523
echo "0009 x $(get_test_count 0009) - multithreaded - push kmod_concurrent over max_modprobes for get_fs_type()"
490524
echo "0010 x $(get_test_count 0010) - test nonexistent modprobe path"
491525
echo "0011 x $(get_test_count 0011) - test completely disabling module autoloading"
526+
echo "0012 x $(get_test_count 0012) - test /proc/modules address visibility under CAP_SYSLOG"
527+
echo "0013 x $(get_test_count 0013) - test /sys/module/*/sections/* visibility under CAP_SYSLOG"
492528
}
493529

494530
usage()

0 commit comments

Comments
 (0)