aboutsummaryrefslogtreecommitdiffstats
path: root/sys/linux/test/landlock_layers
blob: fdc044963c6e807aa7e16cb0c8b50b85be40684c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
# Creates a file hierarchy.

mkdirat(0xffffffffffffff9c, &AUTO='./file0\x00', 0x1c0)
mkdirat(0xffffffffffffff9c, &AUTO='./file0/file0\x00', 0x1c0)

# Creates a first ruleset to restrict file creation.

r0 = landlock_create_ruleset(&AUTO={0x100}, AUTO, 0x0)
r1 = openat$dir(0xffffffffffffff9c, &AUTO='./file0\x00', 0x200000, 0x0)
landlock_add_rule$LANDLOCK_RULE_PATH_BENEATH(r0, AUTO, &AUTO={0x100, r1}, 0x0)

# No need to close FDs for this test.

# Enforces the first ruleset.

prctl$PR_SET_NO_NEW_PRIVS(0x26, 0x1)
landlock_restrict_self(r0, 0x0)

# Creates and remove a file: allowed by the first ruleset.

mknodat(0xffffffffffffff9c, &AUTO='./file0/file1\x00', 0x81c0, 0x0)
unlinkat(0xffffffffffffff9c, &AUTO='./file0/file1\x00', 0x0)

# Tries to create a file: denied by the first ruleset.

mknodat(0xffffffffffffff9c, &AUTO='./file1\x00', 0x81c0, 0x0) # EACCES

# Creates a second ruleset to restrict file removal.

r2 = landlock_create_ruleset(&AUTO={0x20}, AUTO, 0x0)
r3 = openat$dir(0xffffffffffffff9c, &AUTO='./file0/file0\x00', 0x200000, 0x0)
landlock_add_rule$LANDLOCK_RULE_PATH_BENEATH(r2, AUTO, &AUTO={0x20, r3}, 0x0)

# Enforces the second ruleset.

landlock_restrict_self(r2, 0x0)

# Creates and remove files: allowed by both rulesets.

mknodat(0xffffffffffffff9c, &AUTO='./file0/file0/file0\x00', 0x81c0, 0x0)
unlinkat(0xffffffffffffff9c, &AUTO='./file0/file0/file0\x00', 0x0)

# Creates a file: allowed by the first ruleset.

mknodat(0xffffffffffffff9c, &AUTO='./file0/file1\x00', 0x81c0, 0x0)

# Tries to remove a file: denied by the second ruleset.

unlinkat(0xffffffffffffff9c, &AUTO='./file0/file1\x00', 0x0) # EACCES