selftests/bpf: Migrate sendmsg deny test cases
authorJordan Rife <jrife@google.com>
Fri, 10 May 2024 19:02:24 +0000 (14:02 -0500)
committerAlexei Starovoitov <ast@kernel.org>
Mon, 13 May 2024 00:10:41 +0000 (17:10 -0700)
This set of tests checks that sendmsg calls are rejected (return -EPERM)
when the sendmsg* hook returns 0. Replace those in bpf/test_sock_addr.c
with corresponding tests in prog_tests/sock_addr.c.

Signed-off-by: Jordan Rife <jrife@google.com>
Link: https://lore.kernel.org/r/20240510190246.3247730-8-jrife@google.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
tools/testing/selftests/bpf/prog_tests/sock_addr.c
tools/testing/selftests/bpf/progs/sendmsg4_prog.c
tools/testing/selftests/bpf/progs/sendmsg6_prog.c
tools/testing/selftests/bpf/test_sock_addr.c

index 37e9ef5a5ae16a492ddd9d83a9de9085ff6a0f9a..634f7a31b35db7184d175c9ee612f3a088c9bd7f 100644 (file)
@@ -443,7 +443,9 @@ BPF_SKEL_FUNCS(connect4_prog, connect_v4_prog);
 BPF_SKEL_FUNCS(connect6_prog, connect_v6_prog);
 BPF_SKEL_FUNCS(connect_unix_prog, connect_unix_prog);
 BPF_SKEL_FUNCS(sendmsg4_prog, sendmsg_v4_prog);
+BPF_SKEL_FUNCS(sendmsg4_prog, sendmsg_v4_deny_prog);
 BPF_SKEL_FUNCS(sendmsg6_prog, sendmsg_v6_prog);
+BPF_SKEL_FUNCS(sendmsg6_prog, sendmsg_v6_deny_prog);
 BPF_SKEL_FUNCS(sendmsg6_prog, sendmsg_v6_preserve_dst_prog);
 BPF_SKEL_FUNCS(sendmsg_unix_prog, sendmsg_unix_prog);
 BPF_SKEL_FUNCS(recvmsg4_prog, recvmsg4_prog);
@@ -766,6 +768,22 @@ static struct sock_addr_test tests[] = {
                SRC4_REWRITE_IP,
                SUCCESS,
        },
+       {
+               SOCK_ADDR_TEST_SENDMSG,
+               "sendmsg4: sendmsg deny (dgram)",
+               sendmsg_v4_deny_prog_load,
+               sendmsg_v4_deny_prog_destroy,
+               BPF_CGROUP_UDP4_SENDMSG,
+               &user_ops,
+               AF_INET,
+               SOCK_DGRAM,
+               SERV4_IP,
+               SERV4_PORT,
+               SERV4_REWRITE_IP,
+               SERV4_REWRITE_PORT,
+               SRC4_REWRITE_IP,
+               SYSCALL_EPERM,
+       },
        {
                SOCK_ADDR_TEST_SENDMSG,
                "sendmsg6: sendmsg (dgram)",
@@ -798,6 +816,22 @@ static struct sock_addr_test tests[] = {
                SRC6_IP,
                SUCCESS,
        },
+       {
+               SOCK_ADDR_TEST_SENDMSG,
+               "sendmsg6: sendmsg deny (dgram)",
+               sendmsg_v6_deny_prog_load,
+               sendmsg_v6_deny_prog_destroy,
+               BPF_CGROUP_UDP6_SENDMSG,
+               &user_ops,
+               AF_INET6,
+               SOCK_DGRAM,
+               SERV6_IP,
+               SERV6_PORT,
+               SERV6_REWRITE_IP,
+               SERV6_REWRITE_PORT,
+               SRC6_REWRITE_IP,
+               SYSCALL_EPERM,
+       },
        {
                SOCK_ADDR_TEST_SENDMSG,
                "sendmsg_unix: sendmsg (dgram)",
@@ -832,6 +866,22 @@ static struct sock_addr_test tests[] = {
                SRC4_REWRITE_IP,
                SUCCESS,
        },
+       {
+               SOCK_ADDR_TEST_SENDMSG,
+               "sendmsg4: sock_sendmsg deny (dgram)",
+               sendmsg_v4_deny_prog_load,
+               sendmsg_v4_deny_prog_destroy,
+               BPF_CGROUP_UDP4_SENDMSG,
+               &kern_ops_sock_sendmsg,
+               AF_INET,
+               SOCK_DGRAM,
+               SERV4_IP,
+               SERV4_PORT,
+               SERV4_REWRITE_IP,
+               SERV4_REWRITE_PORT,
+               SRC4_REWRITE_IP,
+               SYSCALL_EPERM,
+       },
        {
                SOCK_ADDR_TEST_SENDMSG,
                "sendmsg6: sock_sendmsg (dgram)",
@@ -864,6 +914,22 @@ static struct sock_addr_test tests[] = {
                SRC6_IP,
                SUCCESS,
        },
+       {
+               SOCK_ADDR_TEST_SENDMSG,
+               "sendmsg6: sock_sendmsg deny (dgram)",
+               sendmsg_v6_deny_prog_load,
+               sendmsg_v6_deny_prog_destroy,
+               BPF_CGROUP_UDP6_SENDMSG,
+               &kern_ops_sock_sendmsg,
+               AF_INET6,
+               SOCK_DGRAM,
+               SERV6_IP,
+               SERV6_PORT,
+               SERV6_REWRITE_IP,
+               SERV6_REWRITE_PORT,
+               SRC6_REWRITE_IP,
+               SYSCALL_EPERM,
+       },
        {
                SOCK_ADDR_TEST_SENDMSG,
                "sendmsg_unix: sock_sendmsg (dgram)",
@@ -898,6 +964,22 @@ static struct sock_addr_test tests[] = {
                SRC4_REWRITE_IP,
                SUCCESS,
        },
+       {
+               SOCK_ADDR_TEST_SENDMSG,
+               "sendmsg4: kernel_sendmsg deny (dgram)",
+               sendmsg_v4_deny_prog_load,
+               sendmsg_v4_deny_prog_destroy,
+               BPF_CGROUP_UDP4_SENDMSG,
+               &kern_ops_kernel_sendmsg,
+               AF_INET,
+               SOCK_DGRAM,
+               SERV4_IP,
+               SERV4_PORT,
+               SERV4_REWRITE_IP,
+               SERV4_REWRITE_PORT,
+               SRC4_REWRITE_IP,
+               SYSCALL_EPERM,
+       },
        {
                SOCK_ADDR_TEST_SENDMSG,
                "sendmsg6: kernel_sendmsg (dgram)",
@@ -930,6 +1012,22 @@ static struct sock_addr_test tests[] = {
                SRC6_IP,
                SUCCESS,
        },
+       {
+               SOCK_ADDR_TEST_SENDMSG,
+               "sendmsg6: kernel_sendmsg deny (dgram)",
+               sendmsg_v6_deny_prog_load,
+               sendmsg_v6_deny_prog_destroy,
+               BPF_CGROUP_UDP6_SENDMSG,
+               &kern_ops_kernel_sendmsg,
+               AF_INET6,
+               SOCK_DGRAM,
+               SERV6_IP,
+               SERV6_PORT,
+               SERV6_REWRITE_IP,
+               SERV6_REWRITE_PORT,
+               SRC6_REWRITE_IP,
+               SYSCALL_EPERM,
+       },
        {
                SOCK_ADDR_TEST_SENDMSG,
                "sendmsg_unix: sock_sendmsg (dgram)",
index 351e79aef2fae1e19994cb4c8a5a6cfa394e7705..edc159598a0ef957ac54a9c03d846b1a51b0701d 100644 (file)
@@ -49,4 +49,10 @@ int sendmsg_v4_prog(struct bpf_sock_addr *ctx)
        return 1;
 }
 
+SEC("cgroup/sendmsg4")
+int sendmsg_v4_deny_prog(struct bpf_sock_addr *ctx)
+{
+       return 0;
+}
+
 char _license[] SEC("license") = "GPL";
index 03956a654ce585c9b11a700babcfa79b52d16b69..0c1825cb994d66559da0875dc3457ab10447318d 100644 (file)
@@ -65,4 +65,10 @@ int sendmsg_v6_preserve_dst_prog(struct bpf_sock_addr *ctx)
        return 1;
 }
 
+SEC("cgroup/sendmsg6")
+int sendmsg_v6_deny_prog(struct bpf_sock_addr *ctx)
+{
+       return 0;
+}
+
 char _license[] SEC("license") = "GPL";
index ab8ef02c9c556923b7fb132bb92374d4f1b19aa5..91d88358090ebf0ab852b4def67bf4504e42589d 100644 (file)
@@ -92,7 +92,6 @@ static int bind4_prog_load(const struct sock_addr_test *test);
 static int bind6_prog_load(const struct sock_addr_test *test);
 static int connect4_prog_load(const struct sock_addr_test *test);
 static int connect6_prog_load(const struct sock_addr_test *test);
-static int sendmsg_deny_prog_load(const struct sock_addr_test *test);
 static int sendmsg4_rw_asm_prog_load(const struct sock_addr_test *test);
 static int sendmsg6_rw_asm_prog_load(const struct sock_addr_test *test);
 static int sendmsg6_rw_v4mapped_prog_load(const struct sock_addr_test *test);
@@ -258,20 +257,6 @@ static struct sock_addr_test tests[] = {
                SRC4_REWRITE_IP,
                SUCCESS,
        },
-       {
-               "sendmsg4: deny call",
-               sendmsg_deny_prog_load,
-               BPF_CGROUP_UDP4_SENDMSG,
-               BPF_CGROUP_UDP4_SENDMSG,
-               AF_INET,
-               SOCK_DGRAM,
-               SERV4_IP,
-               SERV4_PORT,
-               SERV4_REWRITE_IP,
-               SERV4_REWRITE_PORT,
-               SRC4_REWRITE_IP,
-               SYSCALL_EPERM,
-       },
        {
                "sendmsg6: load prog with wrong expected attach type",
                sendmsg6_rw_asm_prog_load,
@@ -342,20 +327,6 @@ static struct sock_addr_test tests[] = {
                SRC6_REWRITE_IP,
                SUCCESS,
        },
-       {
-               "sendmsg6: deny call",
-               sendmsg_deny_prog_load,
-               BPF_CGROUP_UDP6_SENDMSG,
-               BPF_CGROUP_UDP6_SENDMSG,
-               AF_INET6,
-               SOCK_DGRAM,
-               SERV6_IP,
-               SERV6_PORT,
-               SERV6_REWRITE_IP,
-               SERV6_REWRITE_PORT,
-               SRC6_REWRITE_IP,
-               SYSCALL_EPERM,
-       },
 };
 
 static int load_insns(const struct sock_addr_test *test,
@@ -431,22 +402,6 @@ static int connect6_prog_load(const struct sock_addr_test *test)
        return load_path(test, CONNECT6_PROG_PATH);
 }
 
-static int xmsg_ret_only_prog_load(const struct sock_addr_test *test,
-                                  int32_t rc)
-{
-       struct bpf_insn insns[] = {
-               /* return rc */
-               BPF_MOV64_IMM(BPF_REG_0, rc),
-               BPF_EXIT_INSN(),
-       };
-       return load_insns(test, insns, ARRAY_SIZE(insns));
-}
-
-static int sendmsg_deny_prog_load(const struct sock_addr_test *test)
-{
-       return xmsg_ret_only_prog_load(test, /*rc*/ 0);
-}
-
 static int sendmsg4_rw_asm_prog_load(const struct sock_addr_test *test)
 {
        struct sockaddr_in dst4_rw_addr;