1e483b020SAlexey Dobriyan /*
2e483b020SAlexey Dobriyan * Copyright (c) 2019 Alexey Dobriyan <adobriyan@gmail.com>
3e483b020SAlexey Dobriyan *
4e483b020SAlexey Dobriyan * Permission to use, copy, modify, and distribute this software for any
5e483b020SAlexey Dobriyan * purpose with or without fee is hereby granted, provided that the above
6e483b020SAlexey Dobriyan * copyright notice and this permission notice appear in all copies.
7e483b020SAlexey Dobriyan *
8e483b020SAlexey Dobriyan * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9e483b020SAlexey Dobriyan * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10e483b020SAlexey Dobriyan * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11e483b020SAlexey Dobriyan * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12e483b020SAlexey Dobriyan * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13e483b020SAlexey Dobriyan * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14e483b020SAlexey Dobriyan * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15e483b020SAlexey Dobriyan */
16e483b020SAlexey Dobriyan /*
17e483b020SAlexey Dobriyan * Fork and exec tiny 1 page executable which precisely controls its VM.
18e483b020SAlexey Dobriyan * Test /proc/$PID/maps
19e483b020SAlexey Dobriyan * Test /proc/$PID/smaps
20e483b020SAlexey Dobriyan * Test /proc/$PID/smaps_rollup
21e483b020SAlexey Dobriyan * Test /proc/$PID/statm
22e483b020SAlexey Dobriyan *
23e483b020SAlexey Dobriyan * FIXME require CONFIG_TMPFS which can be disabled
24e483b020SAlexey Dobriyan * FIXME test other values from "smaps"
25e483b020SAlexey Dobriyan * FIXME support other archs
26e483b020SAlexey Dobriyan */
27e483b020SAlexey Dobriyan #undef NDEBUG
28e483b020SAlexey Dobriyan #include <assert.h>
29e483b020SAlexey Dobriyan #include <errno.h>
30e483b020SAlexey Dobriyan #include <sched.h>
31e483b020SAlexey Dobriyan #include <signal.h>
3217415606SAlexey Dobriyan #include <stdbool.h>
33e483b020SAlexey Dobriyan #include <stdint.h>
34e483b020SAlexey Dobriyan #include <stdio.h>
35e483b020SAlexey Dobriyan #include <string.h>
36e483b020SAlexey Dobriyan #include <stdlib.h>
37e483b020SAlexey Dobriyan #include <sys/mount.h>
38e483b020SAlexey Dobriyan #include <sys/types.h>
39e483b020SAlexey Dobriyan #include <sys/stat.h>
4017415606SAlexey Dobriyan #include <sys/wait.h>
41e483b020SAlexey Dobriyan #include <fcntl.h>
42e483b020SAlexey Dobriyan #include <unistd.h>
43e483b020SAlexey Dobriyan #include <sys/syscall.h>
44e483b020SAlexey Dobriyan #include <sys/uio.h>
45e483b020SAlexey Dobriyan #include <linux/kdev_t.h>
4617415606SAlexey Dobriyan #include <sys/time.h>
4717415606SAlexey Dobriyan #include <sys/resource.h>
48*81510a0eSAndrii Nakryiko #include <linux/fs.h>
49e483b020SAlexey Dobriyan
501585b1b5SGuo Zhengkui #include "../kselftest.h"
511585b1b5SGuo Zhengkui
sys_execveat(int dirfd,const char * pathname,char ** argv,char ** envp,int flags)52e483b020SAlexey Dobriyan static inline long sys_execveat(int dirfd, const char *pathname, char **argv, char **envp, int flags)
53e483b020SAlexey Dobriyan {
54e483b020SAlexey Dobriyan return syscall(SYS_execveat, dirfd, pathname, argv, envp, flags);
55e483b020SAlexey Dobriyan }
56e483b020SAlexey Dobriyan
make_private_tmp(void)57e483b020SAlexey Dobriyan static void make_private_tmp(void)
58e483b020SAlexey Dobriyan {
59e483b020SAlexey Dobriyan if (unshare(CLONE_NEWNS) == -1) {
60e483b020SAlexey Dobriyan if (errno == ENOSYS || errno == EPERM) {
61e483b020SAlexey Dobriyan exit(4);
62e483b020SAlexey Dobriyan }
63e483b020SAlexey Dobriyan exit(1);
64e483b020SAlexey Dobriyan }
65e483b020SAlexey Dobriyan if (mount(NULL, "/", NULL, MS_PRIVATE|MS_REC, NULL) == -1) {
66e483b020SAlexey Dobriyan exit(1);
67e483b020SAlexey Dobriyan }
68e483b020SAlexey Dobriyan if (mount(NULL, "/tmp", "tmpfs", 0, NULL) == -1) {
69e483b020SAlexey Dobriyan exit(1);
70e483b020SAlexey Dobriyan }
71e483b020SAlexey Dobriyan }
72e483b020SAlexey Dobriyan
73e483b020SAlexey Dobriyan static pid_t pid = -1;
ate(void)74e483b020SAlexey Dobriyan static void ate(void)
75e483b020SAlexey Dobriyan {
76e483b020SAlexey Dobriyan if (pid > 0) {
77e483b020SAlexey Dobriyan kill(pid, SIGTERM);
78e483b020SAlexey Dobriyan }
79e483b020SAlexey Dobriyan }
80e483b020SAlexey Dobriyan
81e483b020SAlexey Dobriyan struct elf64_hdr {
82e483b020SAlexey Dobriyan uint8_t e_ident[16];
83e483b020SAlexey Dobriyan uint16_t e_type;
84e483b020SAlexey Dobriyan uint16_t e_machine;
85e483b020SAlexey Dobriyan uint32_t e_version;
86e483b020SAlexey Dobriyan uint64_t e_entry;
87e483b020SAlexey Dobriyan uint64_t e_phoff;
88e483b020SAlexey Dobriyan uint64_t e_shoff;
89e483b020SAlexey Dobriyan uint32_t e_flags;
90e483b020SAlexey Dobriyan uint16_t e_ehsize;
91e483b020SAlexey Dobriyan uint16_t e_phentsize;
92e483b020SAlexey Dobriyan uint16_t e_phnum;
93e483b020SAlexey Dobriyan uint16_t e_shentsize;
94e483b020SAlexey Dobriyan uint16_t e_shnum;
95e483b020SAlexey Dobriyan uint16_t e_shstrndx;
96e483b020SAlexey Dobriyan };
97e483b020SAlexey Dobriyan
98e483b020SAlexey Dobriyan struct elf64_phdr {
99e483b020SAlexey Dobriyan uint32_t p_type;
100e483b020SAlexey Dobriyan uint32_t p_flags;
101e483b020SAlexey Dobriyan uint64_t p_offset;
102e483b020SAlexey Dobriyan uint64_t p_vaddr;
103e483b020SAlexey Dobriyan uint64_t p_paddr;
104e483b020SAlexey Dobriyan uint64_t p_filesz;
105e483b020SAlexey Dobriyan uint64_t p_memsz;
106e483b020SAlexey Dobriyan uint64_t p_align;
107e483b020SAlexey Dobriyan };
108e483b020SAlexey Dobriyan
109e483b020SAlexey Dobriyan #ifdef __x86_64__
110e483b020SAlexey Dobriyan #define PAGE_SIZE 4096
111e483b020SAlexey Dobriyan #define VADDR (1UL << 32)
112e483b020SAlexey Dobriyan #define MAPS_OFFSET 73
113e483b020SAlexey Dobriyan
114e483b020SAlexey Dobriyan #define syscall 0x0f, 0x05
115e483b020SAlexey Dobriyan #define mov_rdi(x) \
116e483b020SAlexey Dobriyan 0x48, 0xbf, \
117e483b020SAlexey Dobriyan (x)&0xff, ((x)>>8)&0xff, ((x)>>16)&0xff, ((x)>>24)&0xff, \
118e483b020SAlexey Dobriyan ((x)>>32)&0xff, ((x)>>40)&0xff, ((x)>>48)&0xff, ((x)>>56)&0xff
119e483b020SAlexey Dobriyan
120e483b020SAlexey Dobriyan #define mov_rsi(x) \
121e483b020SAlexey Dobriyan 0x48, 0xbe, \
122e483b020SAlexey Dobriyan (x)&0xff, ((x)>>8)&0xff, ((x)>>16)&0xff, ((x)>>24)&0xff, \
123e483b020SAlexey Dobriyan ((x)>>32)&0xff, ((x)>>40)&0xff, ((x)>>48)&0xff, ((x)>>56)&0xff
124e483b020SAlexey Dobriyan
125e483b020SAlexey Dobriyan #define mov_eax(x) \
126e483b020SAlexey Dobriyan 0xb8, (x)&0xff, ((x)>>8)&0xff, ((x)>>16)&0xff, ((x)>>24)&0xff
127e483b020SAlexey Dobriyan
128e483b020SAlexey Dobriyan static const uint8_t payload[] = {
129e483b020SAlexey Dobriyan /* Casually unmap stack, vDSO and everything else. */
130e483b020SAlexey Dobriyan /* munmap */
131e483b020SAlexey Dobriyan mov_rdi(VADDR + 4096),
132e483b020SAlexey Dobriyan mov_rsi((1ULL << 47) - 4096 - VADDR - 4096),
133e483b020SAlexey Dobriyan mov_eax(11),
134e483b020SAlexey Dobriyan syscall,
135e483b020SAlexey Dobriyan
136e483b020SAlexey Dobriyan /* Ping parent. */
137e483b020SAlexey Dobriyan /* write(0, &c, 1); */
138e483b020SAlexey Dobriyan 0x31, 0xff, /* xor edi, edi */
139e483b020SAlexey Dobriyan 0x48, 0x8d, 0x35, 0x00, 0x00, 0x00, 0x00, /* lea rsi, [rip] */
140e483b020SAlexey Dobriyan 0xba, 0x01, 0x00, 0x00, 0x00, /* mov edx, 1 */
141e483b020SAlexey Dobriyan mov_eax(1),
142e483b020SAlexey Dobriyan syscall,
143e483b020SAlexey Dobriyan
144e483b020SAlexey Dobriyan /* 1: pause(); */
145e483b020SAlexey Dobriyan mov_eax(34),
146e483b020SAlexey Dobriyan syscall,
147e483b020SAlexey Dobriyan
148e483b020SAlexey Dobriyan 0xeb, 0xf7, /* jmp 1b */
149e483b020SAlexey Dobriyan };
150e483b020SAlexey Dobriyan
make_exe(const uint8_t * payload,size_t len)151e483b020SAlexey Dobriyan static int make_exe(const uint8_t *payload, size_t len)
152e483b020SAlexey Dobriyan {
153e483b020SAlexey Dobriyan struct elf64_hdr h;
154e483b020SAlexey Dobriyan struct elf64_phdr ph;
155e483b020SAlexey Dobriyan
156e483b020SAlexey Dobriyan struct iovec iov[3] = {
157e483b020SAlexey Dobriyan {&h, sizeof(struct elf64_hdr)},
158e483b020SAlexey Dobriyan {&ph, sizeof(struct elf64_phdr)},
159e483b020SAlexey Dobriyan {(void *)payload, len},
160e483b020SAlexey Dobriyan };
161e483b020SAlexey Dobriyan int fd, fd1;
162e483b020SAlexey Dobriyan char buf[64];
163e483b020SAlexey Dobriyan
164e483b020SAlexey Dobriyan memset(&h, 0, sizeof(h));
165e483b020SAlexey Dobriyan h.e_ident[0] = 0x7f;
166e483b020SAlexey Dobriyan h.e_ident[1] = 'E';
167e483b020SAlexey Dobriyan h.e_ident[2] = 'L';
168e483b020SAlexey Dobriyan h.e_ident[3] = 'F';
169e483b020SAlexey Dobriyan h.e_ident[4] = 2;
170e483b020SAlexey Dobriyan h.e_ident[5] = 1;
171e483b020SAlexey Dobriyan h.e_ident[6] = 1;
172e483b020SAlexey Dobriyan h.e_ident[7] = 0;
173e483b020SAlexey Dobriyan h.e_type = 2;
174e483b020SAlexey Dobriyan h.e_machine = 0x3e;
175e483b020SAlexey Dobriyan h.e_version = 1;
176e483b020SAlexey Dobriyan h.e_entry = VADDR + sizeof(struct elf64_hdr) + sizeof(struct elf64_phdr);
177e483b020SAlexey Dobriyan h.e_phoff = sizeof(struct elf64_hdr);
178e483b020SAlexey Dobriyan h.e_shoff = 0;
179e483b020SAlexey Dobriyan h.e_flags = 0;
180e483b020SAlexey Dobriyan h.e_ehsize = sizeof(struct elf64_hdr);
181e483b020SAlexey Dobriyan h.e_phentsize = sizeof(struct elf64_phdr);
182e483b020SAlexey Dobriyan h.e_phnum = 1;
183e483b020SAlexey Dobriyan h.e_shentsize = 0;
184e483b020SAlexey Dobriyan h.e_shnum = 0;
185e483b020SAlexey Dobriyan h.e_shstrndx = 0;
186e483b020SAlexey Dobriyan
187e483b020SAlexey Dobriyan memset(&ph, 0, sizeof(ph));
188e483b020SAlexey Dobriyan ph.p_type = 1;
189e483b020SAlexey Dobriyan ph.p_flags = (1<<2)|1;
190e483b020SAlexey Dobriyan ph.p_offset = 0;
191e483b020SAlexey Dobriyan ph.p_vaddr = VADDR;
192e483b020SAlexey Dobriyan ph.p_paddr = 0;
19368545aa1SAlexey Dobriyan ph.p_filesz = sizeof(struct elf64_hdr) + sizeof(struct elf64_phdr) + len;
19468545aa1SAlexey Dobriyan ph.p_memsz = sizeof(struct elf64_hdr) + sizeof(struct elf64_phdr) + len;
195e483b020SAlexey Dobriyan ph.p_align = 4096;
196e483b020SAlexey Dobriyan
197e483b020SAlexey Dobriyan fd = openat(AT_FDCWD, "/tmp", O_WRONLY|O_EXCL|O_TMPFILE, 0700);
198e483b020SAlexey Dobriyan if (fd == -1) {
199e483b020SAlexey Dobriyan exit(1);
200e483b020SAlexey Dobriyan }
201e483b020SAlexey Dobriyan
202e483b020SAlexey Dobriyan if (writev(fd, iov, 3) != sizeof(struct elf64_hdr) + sizeof(struct elf64_phdr) + len) {
203e483b020SAlexey Dobriyan exit(1);
204e483b020SAlexey Dobriyan }
205e483b020SAlexey Dobriyan
206e483b020SAlexey Dobriyan /* Avoid ETXTBSY on exec. */
207e483b020SAlexey Dobriyan snprintf(buf, sizeof(buf), "/proc/self/fd/%u", fd);
208e483b020SAlexey Dobriyan fd1 = open(buf, O_RDONLY|O_CLOEXEC);
209e483b020SAlexey Dobriyan close(fd);
210e483b020SAlexey Dobriyan
211e483b020SAlexey Dobriyan return fd1;
212e483b020SAlexey Dobriyan }
213e483b020SAlexey Dobriyan #endif
214e483b020SAlexey Dobriyan
2153adb2d87SAlexey Dobriyan /*
2163adb2d87SAlexey Dobriyan * 0: vsyscall VMA doesn't exist vsyscall=none
217f4068af3SBrian Foster * 1: vsyscall VMA is --xp vsyscall=xonly
218f4068af3SBrian Foster * 2: vsyscall VMA is r-xp vsyscall=emulate
2193adb2d87SAlexey Dobriyan */
220f4068af3SBrian Foster static volatile int g_vsyscall;
2213adb2d87SAlexey Dobriyan static const char *str_vsyscall;
22217415606SAlexey Dobriyan
2233adb2d87SAlexey Dobriyan static const char str_vsyscall_0[] = "";
2243adb2d87SAlexey Dobriyan static const char str_vsyscall_1[] =
2253adb2d87SAlexey Dobriyan "ffffffffff600000-ffffffffff601000 --xp 00000000 00:00 0 [vsyscall]\n";
226f4068af3SBrian Foster static const char str_vsyscall_2[] =
227f4068af3SBrian Foster "ffffffffff600000-ffffffffff601000 r-xp 00000000 00:00 0 [vsyscall]\n";
22817415606SAlexey Dobriyan
229e483b020SAlexey Dobriyan #ifdef __x86_64__
sigaction_SIGSEGV(int _,siginfo_t * __,void * ___)230bca1eac5SAlexey Dobriyan static void sigaction_SIGSEGV(int _, siginfo_t *__, void *___)
231bca1eac5SAlexey Dobriyan {
232f4068af3SBrian Foster _exit(g_vsyscall);
233bca1eac5SAlexey Dobriyan }
234bca1eac5SAlexey Dobriyan
23517415606SAlexey Dobriyan /*
2363adb2d87SAlexey Dobriyan * vsyscall page can't be unmapped, probe it directly.
23717415606SAlexey Dobriyan */
vsyscall(void)23817415606SAlexey Dobriyan static void vsyscall(void)
23917415606SAlexey Dobriyan {
24017415606SAlexey Dobriyan pid_t pid;
24117415606SAlexey Dobriyan int wstatus;
24217415606SAlexey Dobriyan
24317415606SAlexey Dobriyan pid = fork();
24417415606SAlexey Dobriyan if (pid < 0) {
24517415606SAlexey Dobriyan fprintf(stderr, "fork, errno %d\n", errno);
24617415606SAlexey Dobriyan exit(1);
24717415606SAlexey Dobriyan }
24817415606SAlexey Dobriyan if (pid == 0) {
24917415606SAlexey Dobriyan struct rlimit rlim = {0, 0};
25017415606SAlexey Dobriyan (void)setrlimit(RLIMIT_CORE, &rlim);
251bca1eac5SAlexey Dobriyan
252bca1eac5SAlexey Dobriyan /* Hide "segfault at ffffffffff600000" messages. */
253bca1eac5SAlexey Dobriyan struct sigaction act;
254bca1eac5SAlexey Dobriyan memset(&act, 0, sizeof(struct sigaction));
255bca1eac5SAlexey Dobriyan act.sa_flags = SA_SIGINFO;
256bca1eac5SAlexey Dobriyan act.sa_sigaction = sigaction_SIGSEGV;
257bca1eac5SAlexey Dobriyan (void)sigaction(SIGSEGV, &act, NULL);
258bca1eac5SAlexey Dobriyan
259f4068af3SBrian Foster g_vsyscall = 0;
2603adb2d87SAlexey Dobriyan /* gettimeofday(NULL, NULL); */
2615316a017SAlexey Dobriyan uint64_t rax = 0xffffffffff600000;
2623adb2d87SAlexey Dobriyan asm volatile (
2635316a017SAlexey Dobriyan "call *%[rax]"
2645316a017SAlexey Dobriyan : [rax] "+a" (rax)
2655316a017SAlexey Dobriyan : "D" (NULL), "S" (NULL)
2665316a017SAlexey Dobriyan : "rcx", "r11"
2673adb2d87SAlexey Dobriyan );
268f4068af3SBrian Foster
269f4068af3SBrian Foster g_vsyscall = 1;
270f4068af3SBrian Foster *(volatile int *)0xffffffffff600000UL;
271f4068af3SBrian Foster
272f4068af3SBrian Foster g_vsyscall = 2;
273f4068af3SBrian Foster exit(g_vsyscall);
2743adb2d87SAlexey Dobriyan }
2753adb2d87SAlexey Dobriyan waitpid(pid, &wstatus, 0);
276f4068af3SBrian Foster if (WIFEXITED(wstatus)) {
277f4068af3SBrian Foster g_vsyscall = WEXITSTATUS(wstatus);
2783adb2d87SAlexey Dobriyan } else {
279f4068af3SBrian Foster fprintf(stderr, "error: wstatus %08x\n", wstatus);
2803adb2d87SAlexey Dobriyan exit(1);
2813adb2d87SAlexey Dobriyan }
28217415606SAlexey Dobriyan }
28317415606SAlexey Dobriyan
main(void)284e483b020SAlexey Dobriyan int main(void)
285e483b020SAlexey Dobriyan {
286e483b020SAlexey Dobriyan int pipefd[2];
287e483b020SAlexey Dobriyan int exec_fd;
288e483b020SAlexey Dobriyan
28917415606SAlexey Dobriyan vsyscall();
2903adb2d87SAlexey Dobriyan switch (g_vsyscall) {
2913adb2d87SAlexey Dobriyan case 0:
2923adb2d87SAlexey Dobriyan str_vsyscall = str_vsyscall_0;
2933adb2d87SAlexey Dobriyan break;
2943adb2d87SAlexey Dobriyan case 1:
2953adb2d87SAlexey Dobriyan str_vsyscall = str_vsyscall_1;
2963adb2d87SAlexey Dobriyan break;
2973adb2d87SAlexey Dobriyan case 2:
2983adb2d87SAlexey Dobriyan str_vsyscall = str_vsyscall_2;
2993adb2d87SAlexey Dobriyan break;
3003adb2d87SAlexey Dobriyan default:
3013adb2d87SAlexey Dobriyan abort();
3023adb2d87SAlexey Dobriyan }
30317415606SAlexey Dobriyan
304e483b020SAlexey Dobriyan atexit(ate);
305e483b020SAlexey Dobriyan
306e483b020SAlexey Dobriyan make_private_tmp();
307e483b020SAlexey Dobriyan
308e483b020SAlexey Dobriyan /* Reserve fd 0 for 1-byte pipe ping from child. */
309e483b020SAlexey Dobriyan close(0);
310e483b020SAlexey Dobriyan if (open("/", O_RDONLY|O_DIRECTORY|O_PATH) != 0) {
311e483b020SAlexey Dobriyan return 1;
312e483b020SAlexey Dobriyan }
313e483b020SAlexey Dobriyan
314e483b020SAlexey Dobriyan exec_fd = make_exe(payload, sizeof(payload));
315e483b020SAlexey Dobriyan
316e483b020SAlexey Dobriyan if (pipe(pipefd) == -1) {
317e483b020SAlexey Dobriyan return 1;
318e483b020SAlexey Dobriyan }
319e483b020SAlexey Dobriyan if (dup2(pipefd[1], 0) != 0) {
320e483b020SAlexey Dobriyan return 1;
321e483b020SAlexey Dobriyan }
322e483b020SAlexey Dobriyan
323e483b020SAlexey Dobriyan pid = fork();
324e483b020SAlexey Dobriyan if (pid == -1) {
325e483b020SAlexey Dobriyan return 1;
326e483b020SAlexey Dobriyan }
327e483b020SAlexey Dobriyan if (pid == 0) {
328e483b020SAlexey Dobriyan sys_execveat(exec_fd, "", NULL, NULL, AT_EMPTY_PATH);
329e483b020SAlexey Dobriyan return 1;
330e483b020SAlexey Dobriyan }
331e483b020SAlexey Dobriyan
332e483b020SAlexey Dobriyan char _;
333e483b020SAlexey Dobriyan if (read(pipefd[0], &_, 1) != 1) {
334e483b020SAlexey Dobriyan return 1;
335e483b020SAlexey Dobriyan }
336e483b020SAlexey Dobriyan
337e483b020SAlexey Dobriyan struct stat st;
338e483b020SAlexey Dobriyan if (fstat(exec_fd, &st) == -1) {
339e483b020SAlexey Dobriyan return 1;
340e483b020SAlexey Dobriyan }
341e483b020SAlexey Dobriyan
342e483b020SAlexey Dobriyan /* Generate "head -n1 /proc/$PID/maps" */
343e483b020SAlexey Dobriyan char buf0[256];
344e483b020SAlexey Dobriyan memset(buf0, ' ', sizeof(buf0));
345e483b020SAlexey Dobriyan int len = snprintf(buf0, sizeof(buf0),
346e483b020SAlexey Dobriyan "%08lx-%08lx r-xp 00000000 %02lx:%02lx %llu",
347e483b020SAlexey Dobriyan VADDR, VADDR + PAGE_SIZE,
348e483b020SAlexey Dobriyan MAJOR(st.st_dev), MINOR(st.st_dev),
349e483b020SAlexey Dobriyan (unsigned long long)st.st_ino);
350e483b020SAlexey Dobriyan buf0[len] = ' ';
351e483b020SAlexey Dobriyan snprintf(buf0 + MAPS_OFFSET, sizeof(buf0) - MAPS_OFFSET,
352e483b020SAlexey Dobriyan "/tmp/#%llu (deleted)\n", (unsigned long long)st.st_ino);
353e483b020SAlexey Dobriyan
354e483b020SAlexey Dobriyan /* Test /proc/$PID/maps */
355e483b020SAlexey Dobriyan {
3563adb2d87SAlexey Dobriyan const size_t len = strlen(buf0) + strlen(str_vsyscall);
357e483b020SAlexey Dobriyan char buf[256];
358e483b020SAlexey Dobriyan ssize_t rv;
359e483b020SAlexey Dobriyan int fd;
360e483b020SAlexey Dobriyan
361e483b020SAlexey Dobriyan snprintf(buf, sizeof(buf), "/proc/%u/maps", pid);
362e483b020SAlexey Dobriyan fd = open(buf, O_RDONLY);
363e483b020SAlexey Dobriyan if (fd == -1) {
364e483b020SAlexey Dobriyan return 1;
365e483b020SAlexey Dobriyan }
366e483b020SAlexey Dobriyan rv = read(fd, buf, sizeof(buf));
36717415606SAlexey Dobriyan assert(rv == len);
368e483b020SAlexey Dobriyan assert(memcmp(buf, buf0, strlen(buf0)) == 0);
3693adb2d87SAlexey Dobriyan if (g_vsyscall > 0) {
37017415606SAlexey Dobriyan assert(memcmp(buf + strlen(buf0), str_vsyscall, strlen(str_vsyscall)) == 0);
37117415606SAlexey Dobriyan }
372e483b020SAlexey Dobriyan }
373e483b020SAlexey Dobriyan
374e483b020SAlexey Dobriyan /* Test /proc/$PID/smaps */
375e483b020SAlexey Dobriyan {
37617415606SAlexey Dobriyan char buf[4096];
377e483b020SAlexey Dobriyan ssize_t rv;
378e483b020SAlexey Dobriyan int fd;
379e483b020SAlexey Dobriyan
380e483b020SAlexey Dobriyan snprintf(buf, sizeof(buf), "/proc/%u/smaps", pid);
381e483b020SAlexey Dobriyan fd = open(buf, O_RDONLY);
382e483b020SAlexey Dobriyan if (fd == -1) {
383e483b020SAlexey Dobriyan return 1;
384e483b020SAlexey Dobriyan }
385e483b020SAlexey Dobriyan rv = read(fd, buf, sizeof(buf));
386e483b020SAlexey Dobriyan assert(0 <= rv && rv <= sizeof(buf));
387e483b020SAlexey Dobriyan
388e483b020SAlexey Dobriyan assert(rv >= strlen(buf0));
389e483b020SAlexey Dobriyan assert(memcmp(buf, buf0, strlen(buf0)) == 0);
390e483b020SAlexey Dobriyan
391e483b020SAlexey Dobriyan #define RSS1 "Rss: 4 kB\n"
392e483b020SAlexey Dobriyan #define RSS2 "Rss: 0 kB\n"
393e483b020SAlexey Dobriyan #define PSS1 "Pss: 4 kB\n"
394e483b020SAlexey Dobriyan #define PSS2 "Pss: 0 kB\n"
395e483b020SAlexey Dobriyan assert(memmem(buf, rv, RSS1, strlen(RSS1)) ||
396e483b020SAlexey Dobriyan memmem(buf, rv, RSS2, strlen(RSS2)));
397e483b020SAlexey Dobriyan assert(memmem(buf, rv, PSS1, strlen(PSS1)) ||
398e483b020SAlexey Dobriyan memmem(buf, rv, PSS2, strlen(PSS2)));
399e483b020SAlexey Dobriyan
400e483b020SAlexey Dobriyan static const char *S[] = {
401e483b020SAlexey Dobriyan "Size: 4 kB\n",
402e483b020SAlexey Dobriyan "KernelPageSize: 4 kB\n",
403e483b020SAlexey Dobriyan "MMUPageSize: 4 kB\n",
404e483b020SAlexey Dobriyan "Anonymous: 0 kB\n",
405e483b020SAlexey Dobriyan "AnonHugePages: 0 kB\n",
406e483b020SAlexey Dobriyan "Shared_Hugetlb: 0 kB\n",
407e483b020SAlexey Dobriyan "Private_Hugetlb: 0 kB\n",
408e483b020SAlexey Dobriyan "Locked: 0 kB\n",
409e483b020SAlexey Dobriyan };
410e483b020SAlexey Dobriyan int i;
411e483b020SAlexey Dobriyan
4121585b1b5SGuo Zhengkui for (i = 0; i < ARRAY_SIZE(S); i++) {
413e483b020SAlexey Dobriyan assert(memmem(buf, rv, S[i], strlen(S[i])));
414e483b020SAlexey Dobriyan }
41517415606SAlexey Dobriyan
4163adb2d87SAlexey Dobriyan if (g_vsyscall > 0) {
41717415606SAlexey Dobriyan assert(memmem(buf, rv, str_vsyscall, strlen(str_vsyscall)));
41817415606SAlexey Dobriyan }
419e483b020SAlexey Dobriyan }
420e483b020SAlexey Dobriyan
421e483b020SAlexey Dobriyan /* Test /proc/$PID/smaps_rollup */
422e483b020SAlexey Dobriyan {
423e483b020SAlexey Dobriyan char bufr[256];
424e483b020SAlexey Dobriyan memset(bufr, ' ', sizeof(bufr));
425e483b020SAlexey Dobriyan len = snprintf(bufr, sizeof(bufr),
426e483b020SAlexey Dobriyan "%08lx-%08lx ---p 00000000 00:00 0",
427e483b020SAlexey Dobriyan VADDR, VADDR + PAGE_SIZE);
428e483b020SAlexey Dobriyan bufr[len] = ' ';
429e483b020SAlexey Dobriyan snprintf(bufr + MAPS_OFFSET, sizeof(bufr) - MAPS_OFFSET,
430e483b020SAlexey Dobriyan "[rollup]\n");
431e483b020SAlexey Dobriyan
432e483b020SAlexey Dobriyan char buf[1024];
433e483b020SAlexey Dobriyan ssize_t rv;
434e483b020SAlexey Dobriyan int fd;
435e483b020SAlexey Dobriyan
436e483b020SAlexey Dobriyan snprintf(buf, sizeof(buf), "/proc/%u/smaps_rollup", pid);
437e483b020SAlexey Dobriyan fd = open(buf, O_RDONLY);
438e483b020SAlexey Dobriyan if (fd == -1) {
439e483b020SAlexey Dobriyan return 1;
440e483b020SAlexey Dobriyan }
441e483b020SAlexey Dobriyan rv = read(fd, buf, sizeof(buf));
442e483b020SAlexey Dobriyan assert(0 <= rv && rv <= sizeof(buf));
443e483b020SAlexey Dobriyan
444e483b020SAlexey Dobriyan assert(rv >= strlen(bufr));
445e483b020SAlexey Dobriyan assert(memcmp(buf, bufr, strlen(bufr)) == 0);
446e483b020SAlexey Dobriyan
447e483b020SAlexey Dobriyan assert(memmem(buf, rv, RSS1, strlen(RSS1)) ||
448e483b020SAlexey Dobriyan memmem(buf, rv, RSS2, strlen(RSS2)));
449e483b020SAlexey Dobriyan assert(memmem(buf, rv, PSS1, strlen(PSS1)) ||
450e483b020SAlexey Dobriyan memmem(buf, rv, PSS2, strlen(PSS2)));
451e483b020SAlexey Dobriyan
452e483b020SAlexey Dobriyan static const char *S[] = {
453e483b020SAlexey Dobriyan "Anonymous: 0 kB\n",
454e483b020SAlexey Dobriyan "AnonHugePages: 0 kB\n",
455e483b020SAlexey Dobriyan "Shared_Hugetlb: 0 kB\n",
456e483b020SAlexey Dobriyan "Private_Hugetlb: 0 kB\n",
457e483b020SAlexey Dobriyan "Locked: 0 kB\n",
458e483b020SAlexey Dobriyan };
459e483b020SAlexey Dobriyan int i;
460e483b020SAlexey Dobriyan
4611585b1b5SGuo Zhengkui for (i = 0; i < ARRAY_SIZE(S); i++) {
462e483b020SAlexey Dobriyan assert(memmem(buf, rv, S[i], strlen(S[i])));
463e483b020SAlexey Dobriyan }
464e483b020SAlexey Dobriyan }
465e483b020SAlexey Dobriyan
466e483b020SAlexey Dobriyan /* Test /proc/$PID/statm */
467e483b020SAlexey Dobriyan {
468e483b020SAlexey Dobriyan char buf[64];
469e483b020SAlexey Dobriyan ssize_t rv;
470e483b020SAlexey Dobriyan int fd;
471e483b020SAlexey Dobriyan
472e483b020SAlexey Dobriyan snprintf(buf, sizeof(buf), "/proc/%u/statm", pid);
473e483b020SAlexey Dobriyan fd = open(buf, O_RDONLY);
474e483b020SAlexey Dobriyan if (fd == -1) {
475e483b020SAlexey Dobriyan return 1;
476e483b020SAlexey Dobriyan }
477e483b020SAlexey Dobriyan rv = read(fd, buf, sizeof(buf));
478e483b020SAlexey Dobriyan assert(rv == 7 * 2);
479e483b020SAlexey Dobriyan
480e483b020SAlexey Dobriyan assert(buf[0] == '1'); /* ->total_vm */
481e483b020SAlexey Dobriyan assert(buf[1] == ' ');
482e483b020SAlexey Dobriyan assert(buf[2] == '0' || buf[2] == '1'); /* rss */
483e483b020SAlexey Dobriyan assert(buf[3] == ' ');
484e483b020SAlexey Dobriyan assert(buf[4] == '0' || buf[2] == '1'); /* file rss */
485e483b020SAlexey Dobriyan assert(buf[5] == ' ');
486e483b020SAlexey Dobriyan assert(buf[6] == '1'); /* ELF executable segments */
487e483b020SAlexey Dobriyan assert(buf[7] == ' ');
488e483b020SAlexey Dobriyan assert(buf[8] == '0');
489e483b020SAlexey Dobriyan assert(buf[9] == ' ');
490e483b020SAlexey Dobriyan assert(buf[10] == '0'); /* ->data_vm + ->stack_vm */
491e483b020SAlexey Dobriyan assert(buf[11] == ' ');
492e483b020SAlexey Dobriyan assert(buf[12] == '0');
493e483b020SAlexey Dobriyan assert(buf[13] == '\n');
494e483b020SAlexey Dobriyan }
495e483b020SAlexey Dobriyan
496*81510a0eSAndrii Nakryiko /* Test PROCMAP_QUERY ioctl() for /proc/$PID/maps */
497*81510a0eSAndrii Nakryiko {
498*81510a0eSAndrii Nakryiko char path_buf[256], exp_path_buf[256];
499*81510a0eSAndrii Nakryiko struct procmap_query q;
500*81510a0eSAndrii Nakryiko int fd, err;
501*81510a0eSAndrii Nakryiko
502*81510a0eSAndrii Nakryiko snprintf(path_buf, sizeof(path_buf), "/proc/%u/maps", pid);
503*81510a0eSAndrii Nakryiko fd = open(path_buf, O_RDONLY);
504*81510a0eSAndrii Nakryiko if (fd == -1)
505*81510a0eSAndrii Nakryiko return 1;
506*81510a0eSAndrii Nakryiko
507*81510a0eSAndrii Nakryiko /* CASE 1: exact MATCH at VADDR */
508*81510a0eSAndrii Nakryiko memset(&q, 0, sizeof(q));
509*81510a0eSAndrii Nakryiko q.size = sizeof(q);
510*81510a0eSAndrii Nakryiko q.query_addr = VADDR;
511*81510a0eSAndrii Nakryiko q.query_flags = 0;
512*81510a0eSAndrii Nakryiko q.vma_name_addr = (__u64)(unsigned long)path_buf;
513*81510a0eSAndrii Nakryiko q.vma_name_size = sizeof(path_buf);
514*81510a0eSAndrii Nakryiko
515*81510a0eSAndrii Nakryiko err = ioctl(fd, PROCMAP_QUERY, &q);
516*81510a0eSAndrii Nakryiko assert(err == 0);
517*81510a0eSAndrii Nakryiko
518*81510a0eSAndrii Nakryiko assert(q.query_addr == VADDR);
519*81510a0eSAndrii Nakryiko assert(q.query_flags == 0);
520*81510a0eSAndrii Nakryiko
521*81510a0eSAndrii Nakryiko assert(q.vma_flags == (PROCMAP_QUERY_VMA_READABLE | PROCMAP_QUERY_VMA_EXECUTABLE));
522*81510a0eSAndrii Nakryiko assert(q.vma_start == VADDR);
523*81510a0eSAndrii Nakryiko assert(q.vma_end == VADDR + PAGE_SIZE);
524*81510a0eSAndrii Nakryiko assert(q.vma_page_size == PAGE_SIZE);
525*81510a0eSAndrii Nakryiko
526*81510a0eSAndrii Nakryiko assert(q.vma_offset == 0);
527*81510a0eSAndrii Nakryiko assert(q.inode == st.st_ino);
528*81510a0eSAndrii Nakryiko assert(q.dev_major == MAJOR(st.st_dev));
529*81510a0eSAndrii Nakryiko assert(q.dev_minor == MINOR(st.st_dev));
530*81510a0eSAndrii Nakryiko
531*81510a0eSAndrii Nakryiko snprintf(exp_path_buf, sizeof(exp_path_buf),
532*81510a0eSAndrii Nakryiko "/tmp/#%llu (deleted)", (unsigned long long)st.st_ino);
533*81510a0eSAndrii Nakryiko assert(q.vma_name_size == strlen(exp_path_buf) + 1);
534*81510a0eSAndrii Nakryiko assert(strcmp(path_buf, exp_path_buf) == 0);
535*81510a0eSAndrii Nakryiko
536*81510a0eSAndrii Nakryiko /* CASE 2: NO MATCH at VADDR-1 */
537*81510a0eSAndrii Nakryiko memset(&q, 0, sizeof(q));
538*81510a0eSAndrii Nakryiko q.size = sizeof(q);
539*81510a0eSAndrii Nakryiko q.query_addr = VADDR - 1;
540*81510a0eSAndrii Nakryiko q.query_flags = 0; /* exact match */
541*81510a0eSAndrii Nakryiko
542*81510a0eSAndrii Nakryiko err = ioctl(fd, PROCMAP_QUERY, &q);
543*81510a0eSAndrii Nakryiko err = err < 0 ? -errno : 0;
544*81510a0eSAndrii Nakryiko assert(err == -ENOENT);
545*81510a0eSAndrii Nakryiko
546*81510a0eSAndrii Nakryiko /* CASE 3: MATCH COVERING_OR_NEXT_VMA at VADDR - 1 */
547*81510a0eSAndrii Nakryiko memset(&q, 0, sizeof(q));
548*81510a0eSAndrii Nakryiko q.size = sizeof(q);
549*81510a0eSAndrii Nakryiko q.query_addr = VADDR - 1;
550*81510a0eSAndrii Nakryiko q.query_flags = PROCMAP_QUERY_COVERING_OR_NEXT_VMA;
551*81510a0eSAndrii Nakryiko
552*81510a0eSAndrii Nakryiko err = ioctl(fd, PROCMAP_QUERY, &q);
553*81510a0eSAndrii Nakryiko assert(err == 0);
554*81510a0eSAndrii Nakryiko
555*81510a0eSAndrii Nakryiko assert(q.query_addr == VADDR - 1);
556*81510a0eSAndrii Nakryiko assert(q.query_flags == PROCMAP_QUERY_COVERING_OR_NEXT_VMA);
557*81510a0eSAndrii Nakryiko assert(q.vma_start == VADDR);
558*81510a0eSAndrii Nakryiko assert(q.vma_end == VADDR + PAGE_SIZE);
559*81510a0eSAndrii Nakryiko
560*81510a0eSAndrii Nakryiko /* CASE 4: NO MATCH at VADDR + PAGE_SIZE */
561*81510a0eSAndrii Nakryiko memset(&q, 0, sizeof(q));
562*81510a0eSAndrii Nakryiko q.size = sizeof(q);
563*81510a0eSAndrii Nakryiko q.query_addr = VADDR + PAGE_SIZE; /* point right after the VMA */
564*81510a0eSAndrii Nakryiko q.query_flags = PROCMAP_QUERY_COVERING_OR_NEXT_VMA;
565*81510a0eSAndrii Nakryiko
566*81510a0eSAndrii Nakryiko err = ioctl(fd, PROCMAP_QUERY, &q);
567*81510a0eSAndrii Nakryiko err = err < 0 ? -errno : 0;
568*81510a0eSAndrii Nakryiko assert(err == -ENOENT);
569*81510a0eSAndrii Nakryiko
570*81510a0eSAndrii Nakryiko /* CASE 5: NO MATCH WRITABLE at VADDR */
571*81510a0eSAndrii Nakryiko memset(&q, 0, sizeof(q));
572*81510a0eSAndrii Nakryiko q.size = sizeof(q);
573*81510a0eSAndrii Nakryiko q.query_addr = VADDR;
574*81510a0eSAndrii Nakryiko q.query_flags = PROCMAP_QUERY_VMA_WRITABLE;
575*81510a0eSAndrii Nakryiko
576*81510a0eSAndrii Nakryiko err = ioctl(fd, PROCMAP_QUERY, &q);
577*81510a0eSAndrii Nakryiko err = err < 0 ? -errno : 0;
578*81510a0eSAndrii Nakryiko assert(err == -ENOENT);
579*81510a0eSAndrii Nakryiko }
580*81510a0eSAndrii Nakryiko
581e483b020SAlexey Dobriyan return 0;
582e483b020SAlexey Dobriyan }
583e483b020SAlexey Dobriyan #else
main(void)584e483b020SAlexey Dobriyan int main(void)
585e483b020SAlexey Dobriyan {
586e483b020SAlexey Dobriyan return 4;
587e483b020SAlexey Dobriyan }
588e483b020SAlexey Dobriyan #endif
589