1 /* $NetBSD: t_mmap.c,v 1.12 2017/01/16 16:31:05 christos Exp $ */
4 * Copyright (c) 2011 The NetBSD Foundation, Inc.
7 * This code is derived from software contributed to The NetBSD Foundation
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
13 * 1. Redistributions of source code must retain the above copyright
14 * notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in the
17 * documentation and/or other materials provided with the distribution.
19 * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
20 * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
21 * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
22 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
23 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
24 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
27 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
29 * POSSIBILITY OF SUCH DAMAGE.
33 * Copyright (c)2004 YAMAMOTO Takashi,
34 * All rights reserved.
36 * Redistribution and use in source and binary forms, with or without
37 * modification, are permitted provided that the following conditions
39 * 1. Redistributions of source code must retain the above copyright
40 * notice, this list of conditions and the following disclaimer.
41 * 2. Redistributions in binary form must reproduce the above copyright
42 * notice, this list of conditions and the following disclaimer in the
43 * documentation and/or other materials provided with the distribution.
45 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
46 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
47 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
48 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
49 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
50 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
51 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
52 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
53 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
54 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
57 #include <sys/cdefs.h>
58 __RCSID("$NetBSD: t_mmap.c,v 1.12 2017/01/16 16:31:05 christos Exp $");
60 #include <sys/param.h>
61 #include <sys/disklabel.h>
64 #include <sys/socket.h>
65 #include <sys/sysctl.h>
82 static char path[] = "mmap";
83 static void map_check(void *, int);
84 static void map_sighandler(int);
85 static void testloan(void *, void *, char, int);
87 #define BUFSIZE (32 * 1024) /* enough size to trigger sosend_loan */
90 map_check(void *map, int flag)
94 ATF_REQUIRE(map == MAP_FAILED);
98 ATF_REQUIRE(map != MAP_FAILED);
99 ATF_REQUIRE(munmap(map, page) == 0);
103 testloan(void *vp, void *vp2, char pat, int docheck)
106 char backup[BUFSIZE];
115 (void)memcpy(backup, vp, BUFSIZE);
117 if (socketpair(AF_LOCAL, SOCK_STREAM, PF_UNSPEC, fds) != 0)
118 atf_tc_fail("socketpair() failed");
122 if (setsockopt(fds[1], SOL_SOCKET, SO_RCVBUF, &val, sizeof(val)) != 0)
123 atf_tc_fail("setsockopt() failed, SO_RCVBUF");
127 if (setsockopt(fds[0], SOL_SOCKET, SO_SNDBUF, &val, sizeof(val)) != 0)
128 atf_tc_fail("setsockopt() failed, SO_SNDBUF");
130 if (fcntl(fds[0], F_SETFL, O_NONBLOCK) != 0)
131 atf_tc_fail("fcntl() failed");
133 nwritten = write(fds[0], (char *)vp + page, BUFSIZE - page);
136 atf_tc_fail("write() failed");
139 (void)memset(vp2, pat, BUFSIZE);
141 nread = read(fds[1], buf + page, BUFSIZE - page);
144 atf_tc_fail("read() failed");
146 if (nread != nwritten)
147 atf_tc_fail("too short read");
149 if (docheck != 0 && memcmp(backup, buf + page, nread) != 0)
150 atf_tc_fail("data mismatch");
152 ATF_REQUIRE(close(fds[0]) == 0);
153 ATF_REQUIRE(close(fds[1]) == 0);
157 map_sighandler(int signo)
164 ATF_TC_HEAD(mmap_block, tc)
166 atf_tc_set_md_var(tc, "descr", "Test mmap(2) with a block device");
167 atf_tc_set_md_var(tc, "require.user", "root");
170 ATF_TC_BODY(mmap_block, tc)
172 static const int mib[] = { CTL_HW, HW_DISKNAMES };
173 static const unsigned int miblen = __arraycount(mib);
174 char *map, *dk, *drives, dev[PATH_MAX];
178 atf_tc_skip("The test case causes a panic (PR kern/38889, kern/46592)");
180 ATF_REQUIRE(sysctl(mib, miblen, NULL, &len, NULL, 0) == 0);
181 drives = malloc(len);
182 ATF_REQUIRE(drives != NULL);
183 ATF_REQUIRE(sysctl(mib, miblen, drives, &len, NULL, 0) == 0);
184 for (dk = strtok(drives, " "); dk != NULL; dk = strtok(NULL, " ")) {
185 sprintf(dev, _PATH_DEV "%s%c", dk, 'a'+RAW_PART);
186 fprintf(stderr, "trying: %s\n", dev);
188 if ((fd = open(dev, O_RDONLY)) >= 0) {
189 (void)fprintf(stderr, "using %s\n", dev);
196 atf_tc_skip("failed to find suitable block device");
198 map = mmap(NULL, 4096, PROT_READ, MAP_FILE, fd, 0);
199 ATF_REQUIRE(map != MAP_FAILED);
201 (void)fprintf(stderr, "first byte %x\n", *map);
202 ATF_REQUIRE(close(fd) == 0);
203 (void)fprintf(stderr, "first byte %x\n", *map);
205 ATF_REQUIRE(munmap(map, 4096) == 0);
210 ATF_TC_HEAD(mmap_err, tc)
212 atf_tc_set_md_var(tc, "descr", "Test error conditions of mmap(2)");
215 ATF_TC_BODY(mmap_err, tc)
217 size_t addr = SIZE_MAX;
221 map = mmap(NULL, 3, PROT_READ, MAP_FILE|MAP_PRIVATE, -1, 0);
223 ATF_REQUIRE(map == MAP_FAILED);
224 ATF_REQUIRE(errno == EBADF);
227 map = mmap(&addr, page, PROT_READ, MAP_FIXED|MAP_PRIVATE, -1, 0);
229 ATF_REQUIRE(map == MAP_FAILED);
230 ATF_REQUIRE(errno == EINVAL);
233 map = mmap(NULL, page, PROT_READ, MAP_ANON|MAP_PRIVATE, INT_MAX, 0);
235 ATF_REQUIRE(map == MAP_FAILED);
236 ATF_REQUIRE(errno == EINVAL);
239 ATF_TC_WITH_CLEANUP(mmap_loan);
240 ATF_TC_HEAD(mmap_loan, tc)
242 atf_tc_set_md_var(tc, "descr", "Test uvm page loanout with mmap(2)");
245 ATF_TC_BODY(mmap_loan, tc)
251 fd = open(path, O_RDWR | O_CREAT, 0600);
252 ATF_REQUIRE(fd >= 0);
254 (void)memset(buf, 'x', sizeof(buf));
255 (void)write(fd, buf, sizeof(buf));
257 vp = mmap(NULL, BUFSIZE, PROT_READ | PROT_WRITE,
258 MAP_FILE | MAP_PRIVATE, fd, 0);
260 ATF_REQUIRE(vp != MAP_FAILED);
264 testloan(vp, vp2, 'A', 0);
265 testloan(vp, vp2, 'B', 1);
267 ATF_REQUIRE(munmap(vp, BUFSIZE) == 0);
269 vp = mmap(NULL, BUFSIZE, PROT_READ | PROT_WRITE,
270 MAP_FILE | MAP_SHARED, fd, 0);
272 vp2 = mmap(NULL, BUFSIZE, PROT_READ | PROT_WRITE,
273 MAP_FILE | MAP_SHARED, fd, 0);
275 ATF_REQUIRE(vp != MAP_FAILED);
276 ATF_REQUIRE(vp2 != MAP_FAILED);
278 testloan(vp, vp2, 'E', 1);
280 ATF_REQUIRE(munmap(vp, BUFSIZE) == 0);
281 ATF_REQUIRE(munmap(vp2, BUFSIZE) == 0);
284 ATF_TC_CLEANUP(mmap_loan, tc)
289 ATF_TC_WITH_CLEANUP(mmap_prot_1);
290 ATF_TC_HEAD(mmap_prot_1, tc)
292 atf_tc_set_md_var(tc, "descr", "Test mmap(2) protections, #1");
295 ATF_TC_BODY(mmap_prot_1, tc)
301 * Open a file write-only and try to
302 * map it read-only. This should fail.
304 fd = open(path, O_WRONLY | O_CREAT, 0700);
309 ATF_REQUIRE(write(fd, "XXX", 3) == 3);
311 map = mmap(NULL, 3, PROT_READ, MAP_FILE|MAP_PRIVATE, fd, 0);
314 map = mmap(NULL, 3, PROT_WRITE, MAP_FILE|MAP_PRIVATE, fd, 0);
317 ATF_REQUIRE(close(fd) == 0);
320 ATF_TC_CLEANUP(mmap_prot_1, tc)
326 ATF_TC_HEAD(mmap_prot_2, tc)
328 atf_tc_set_md_var(tc, "descr", "Test mmap(2) protections, #2");
331 ATF_TC_BODY(mmap_prot_2, tc)
339 * Make a PROT_NONE mapping and try to access it.
340 * If we catch a SIGSEGV, all works as expected.
342 map = mmap(NULL, page, PROT_NONE, MAP_ANON|MAP_PRIVATE, -1, 0);
343 ATF_REQUIRE(map != MAP_FAILED);
346 ATF_REQUIRE(pid >= 0);
349 ATF_REQUIRE(signal(SIGSEGV, map_sighandler) != SIG_ERR);
350 ATF_REQUIRE(strlcpy(buf, map, sizeof(buf)) != 0);
355 ATF_REQUIRE(WIFEXITED(sta) != 0);
356 ATF_REQUIRE(WEXITSTATUS(sta) == SIGSEGV);
357 ATF_REQUIRE(munmap(map, page) == 0);
360 ATF_TC_WITH_CLEANUP(mmap_prot_3);
361 ATF_TC_HEAD(mmap_prot_3, tc)
363 atf_tc_set_md_var(tc, "descr", "Test mmap(2) protections, #3");
366 ATF_TC_BODY(mmap_prot_3, tc)
374 * Open a file, change the permissions
375 * to read-only, and try to map it as
376 * PROT_NONE. This should succeed, but
377 * the access should generate SIGSEGV.
379 fd = open(path, O_RDWR | O_CREAT, 0700);
383 atf_tc_skip("opening %s failed; skipping testcase: %s",
384 path, strerror(errno));
389 ATF_REQUIRE(write(fd, "XXX", 3) == 3);
390 ATF_REQUIRE(close(fd) == 0);
391 ATF_REQUIRE(chmod(path, 0444) == 0);
393 fd = open(path, O_RDONLY);
394 ATF_REQUIRE(fd != -1);
396 map = mmap(NULL, 3, PROT_NONE, MAP_FILE | MAP_SHARED, fd, 0);
397 ATF_REQUIRE(map != MAP_FAILED);
401 ATF_REQUIRE(pid >= 0);
404 ATF_REQUIRE(signal(SIGSEGV, map_sighandler) != SIG_ERR);
405 ATF_REQUIRE(strlcpy(buf, map, sizeof(buf)) != 0);
410 ATF_REQUIRE(WIFEXITED(sta) != 0);
411 ATF_REQUIRE(WEXITSTATUS(sta) == SIGSEGV);
412 ATF_REQUIRE(munmap(map, 3) == 0);
418 ATF_TC_CLEANUP(mmap_prot_3, tc)
423 ATF_TC_WITH_CLEANUP(mmap_truncate);
424 ATF_TC_HEAD(mmap_truncate, tc)
426 atf_tc_set_md_var(tc, "descr", "Test mmap(2) and ftruncate(2)");
429 ATF_TC_BODY(mmap_truncate, tc)
435 fd = open(path, O_RDWR | O_CREAT, 0700);
441 * See that ftruncate(2) works
442 * while the file is mapped.
444 ATF_REQUIRE(ftruncate(fd, page) == 0);
446 map = mmap(NULL, page, PROT_READ | PROT_WRITE, MAP_FILE|MAP_PRIVATE,
448 ATF_REQUIRE(map != MAP_FAILED);
450 for (i = 0; i < page; i++)
453 ATF_REQUIRE(ftruncate(fd, 0) == 0);
454 ATF_REQUIRE(ftruncate(fd, page / 8) == 0);
455 ATF_REQUIRE(ftruncate(fd, page / 4) == 0);
456 ATF_REQUIRE(ftruncate(fd, page / 2) == 0);
457 ATF_REQUIRE(ftruncate(fd, page / 12) == 0);
458 ATF_REQUIRE(ftruncate(fd, page / 64) == 0);
460 (void)munmap(map, page);
461 ATF_REQUIRE(close(fd) == 0);
464 ATF_TC_CLEANUP(mmap_truncate, tc)
469 ATF_TC_WITH_CLEANUP(mmap_truncate_signal);
470 ATF_TC_HEAD(mmap_truncate_signal, tc)
472 atf_tc_set_md_var(tc, "descr",
473 "Test mmap(2) ftruncate(2) causing signal");
476 ATF_TC_BODY(mmap_truncate_signal, tc)
484 atf_tc_expect_fail("testcase fails with SIGSEGV on FreeBSD; bug # 211924");
487 fd = open(path, O_RDWR | O_CREAT, 0700);
492 ATF_REQUIRE(write(fd, "foo\n", 5) == 5);
494 map = mmap(NULL, page, PROT_READ, MAP_FILE|MAP_PRIVATE, fd, 0);
495 ATF_REQUIRE(map != MAP_FAILED);
498 for (i = 0; i < 5; i++)
500 ATF_REQUIRE(sta == 334);
502 ATF_REQUIRE(ftruncate(fd, 0) == 0);
504 ATF_REQUIRE(pid >= 0);
507 ATF_REQUIRE(signal(SIGBUS, map_sighandler) != SIG_ERR);
508 ATF_REQUIRE(signal(SIGSEGV, map_sighandler) != SIG_ERR);
510 for (i = 0; i < page; i++)
512 /* child never will get this far, but the compiler will
513 not know, so better use the values calculated to
514 prevent the access to be optimized out */
516 ATF_REQUIRE(sta == 0);
517 (void)munmap(map, page);
524 ATF_REQUIRE(WIFEXITED(sta) != 0);
525 if (WEXITSTATUS(sta) == SIGSEGV)
526 atf_tc_fail("child process got SIGSEGV instead of SIGBUS");
527 ATF_REQUIRE(WEXITSTATUS(sta) == SIGBUS);
528 ATF_REQUIRE(munmap(map, page) == 0);
529 ATF_REQUIRE(close(fd) == 0);
532 ATF_TC_CLEANUP(mmap_truncate_signal, tc)
538 ATF_TC_HEAD(mmap_va0, tc)
540 atf_tc_set_md_var(tc, "descr", "Test mmap(2) and vm.user_va0_disable");
543 ATF_TC_BODY(mmap_va0, tc)
545 int flags = MAP_ANON | MAP_FIXED | MAP_PRIVATE;
546 size_t len = sizeof(int);
551 * Make an anonymous fixed mapping at zero address. If the address
552 * is restricted as noted in security(7), the syscall should fail.
555 if (sysctlbyname("security.bsd.map_at_zero", &val, &len, NULL, 0) != 0)
556 atf_tc_fail("failed to read security.bsd.map_at_zero");
557 val = !val; /* 1 == enable map at zero */
560 if (sysctlbyname("vm.user_va0_disable", &val, &len, NULL, 0) != 0)
561 atf_tc_fail("failed to read vm.user_va0_disable");
564 map = mmap(NULL, page, PROT_EXEC, flags, -1, 0);
567 map = mmap(NULL, page, PROT_READ, flags, -1, 0);
570 map = mmap(NULL, page, PROT_WRITE, flags, -1, 0);
573 map = mmap(NULL, page, PROT_READ|PROT_WRITE, flags, -1, 0);
576 map = mmap(NULL, page, PROT_EXEC|PROT_READ|PROT_WRITE, flags, -1, 0);
582 page = sysconf(_SC_PAGESIZE);
583 ATF_REQUIRE(page >= 0);
586 ATF_TP_ADD_TC(tp, mmap_block);
588 ATF_TP_ADD_TC(tp, mmap_err);
589 ATF_TP_ADD_TC(tp, mmap_loan);
590 ATF_TP_ADD_TC(tp, mmap_prot_1);
591 ATF_TP_ADD_TC(tp, mmap_prot_2);
592 ATF_TP_ADD_TC(tp, mmap_prot_3);
593 ATF_TP_ADD_TC(tp, mmap_truncate);
594 ATF_TP_ADD_TC(tp, mmap_truncate_signal);
595 ATF_TP_ADD_TC(tp, mmap_va0);
597 return atf_no_error();