diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-11-16 03:34:05 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-11-16 03:34:05 +0900 |
| commit | 38b5ff0cec266c7c5e423b68e8626f4a4a63d3ee (patch) | |
| tree | 77d33091b0348c5a57cf328fa682ebb35aeaa99e /internal/wayland/wayland_test.go | |
| parent | 3c204b9b40373d1f404b1a16e95fdfebb7d58832 (diff) | |
internal/wayland: check pathname size
This avoids passing a truncated pathname to the kernel.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal/wayland/wayland_test.go')
| -rw-r--r-- | internal/wayland/wayland_test.go | 95 |
1 files changed, 60 insertions, 35 deletions
diff --git a/internal/wayland/wayland_test.go b/internal/wayland/wayland_test.go index 16ab22a6..c5e6c558 100644 --- a/internal/wayland/wayland_test.go +++ b/internal/wayland/wayland_test.go @@ -1,12 +1,13 @@ -package wayland_test +package wayland import ( + "errors" "os" + "reflect" "syscall" "testing" "hakurei.app/container/stub" - "hakurei.app/internal/wayland" ) func TestError(t *testing.T) { @@ -14,88 +15,88 @@ func TestError(t *testing.T) { testCases := []struct { name string - err wayland.Error + err Error want string }{ - {"success", wayland.Error{ - Cause: wayland.RSuccess, + {"success", Error{ + Cause: RSuccess, }, "success"}, - {"success errno", wayland.Error{ - Cause: wayland.RSuccess, + {"success errno", Error{ + Cause: RSuccess, Errno: stub.UniqueError(0), }, "unique error 0 injected by the test suite"}, - {"wl_display_connect_to_fd", wayland.Error{ - Cause: wayland.RConnect, + {"wl_display_connect_to_fd", Error{ + Cause: RConnect, Errno: stub.UniqueError(1), }, "wl_display_connect_to_fd failed: unique error 1 injected by the test suite"}, - {"wl_registry_add_listener", wayland.Error{ - Cause: wayland.RListener, + {"wl_registry_add_listener", Error{ + Cause: RListener, Errno: stub.UniqueError(2), }, "wl_registry_add_listener failed: unique error 2 injected by the test suite"}, - {"wl_display_roundtrip", wayland.Error{ - Cause: wayland.RRoundtrip, + {"wl_display_roundtrip", Error{ + Cause: RRoundtrip, Errno: stub.UniqueError(3), }, "wl_display_roundtrip failed: unique error 3 injected by the test suite"}, - {"not available", wayland.Error{ - Cause: wayland.RNotAvail, + {"not available", Error{ + Cause: RNotAvail, }, "compositor does not implement security_context_v1"}, - {"not available errno", wayland.Error{ - Cause: wayland.RNotAvail, + {"not available errno", Error{ + Cause: RNotAvail, Errno: syscall.EAGAIN, }, "compositor does not implement security_context_v1"}, - {"socket", wayland.Error{ - Cause: wayland.RSocket, + {"socket", Error{ + Cause: RSocket, Errno: stub.UniqueError(4), }, "socket: unique error 4 injected by the test suite"}, - {"bind", wayland.Error{ - Cause: wayland.RBind, + {"bind", Error{ + Cause: RBind, Path: "/hakurei.0/18783d07791f2460dbbcffb76c24c9e6/wayland", Errno: stub.UniqueError(5), }, "cannot bind /hakurei.0/18783d07791f2460dbbcffb76c24c9e6/wayland: unique error 5 injected by the test suite"}, - {"listen", wayland.Error{ - Cause: wayland.RListen, + {"listen", Error{ + Cause: RListen, Path: "/hakurei.0/18783d07791f2460dbbcffb76c24c9e6/wayland", Errno: stub.UniqueError(6), }, "cannot listen on /hakurei.0/18783d07791f2460dbbcffb76c24c9e6/wayland: unique error 6 injected by the test suite"}, - {"socket invalid", wayland.Error{ - Cause: wayland.RSocket, + {"socket invalid", Error{ + Cause: RSocket, }, "socket operation failed"}, - {"create", wayland.Error{ - Cause: wayland.RCreate, + {"create", Error{ + Cause: RCreate, }, "cannot ensure wayland pathname socket"}, - {"create path", wayland.Error{ - Cause: wayland.RCreate, + {"create path", Error{ + Cause: RCreate, Errno: &os.PathError{Op: "create", Path: "/proc/nonexistent", Err: syscall.EEXIST}, }, "create /proc/nonexistent: file exists"}, - {"host socket", wayland.Error{ - Cause: wayland.RHostSocket, + {"host socket", Error{ + Cause: RHostSocket, Errno: stub.UniqueError(7), }, "socket: unique error 7 injected by the test suite"}, - {"host connect", wayland.Error{ - Cause: wayland.RHostConnect, + {"host connect", Error{ + Cause: RHostConnect, Host: "/run/user/1971/wayland-1", Errno: stub.UniqueError(8), }, "cannot connect to /run/user/1971/wayland-1: unique error 8 injected by the test suite"}, - {"invalid", wayland.Error{ + {"invalid", Error{ Cause: 0xbad, }, "impossible outcome"}, - {"invalid errno", wayland.Error{ + {"invalid errno", Error{ Cause: 0xbad, Errno: stub.UniqueError(9), }, "impossible outcome: unique error 9 injected by the test suite"}, @@ -110,3 +111,27 @@ func TestError(t *testing.T) { }) } } + +func TestSecurityContextBindValidate(t *testing.T) { + t.Parallel() + + t.Run("NUL", func(t *testing.T) { + t.Parallel() + + want := &Error{Cause: RBind, Path: "\x00", Errno: errors.New("argument contains NUL character")} + if got := securityContextBind("\x00", -1, "\x00", "\x00", -1); !reflect.DeepEqual(got, want) { + t.Fatalf("securityContextBind: error = %#v, want %#v", got, want) + } + }) + + t.Run("long", func(t *testing.T) { + t.Parallel() + // 256 bytes + const oversizedPath = "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" + + want := &Error{Cause: RBind, Path: oversizedPath, Errno: errors.New("socket pathname too long")} + if got := securityContextBind(oversizedPath, -1, "", "", -1); !reflect.DeepEqual(got, want) { + t.Fatalf("securityContextBind: error = %#v, want %#v", got, want) + } + }) +} |
