Blame stdlib/test-bz22786.c

Packit 6c4009
/* Bug 22786: test for buffer overflow in realpath.
Packit 6c4009
   Copyright (C) 2018 Free Software Foundation, Inc.
Packit 6c4009
   This file is part of the GNU C Library.
Packit 6c4009
Packit 6c4009
   The GNU C Library is free software; you can redistribute it and/or
Packit 6c4009
   modify it under the terms of the GNU Lesser General Public
Packit 6c4009
   License as published by the Free Software Foundation; either
Packit 6c4009
   version 2.1 of the License, or (at your option) any later version.
Packit 6c4009
Packit 6c4009
   The GNU C Library is distributed in the hope that it will be useful,
Packit 6c4009
   but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit 6c4009
   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
Packit 6c4009
   Lesser General Public License for more details.
Packit 6c4009
Packit 6c4009
   You should have received a copy of the GNU Lesser General Public
Packit 6c4009
   License along with the GNU C Library; if not, see
Packit 6c4009
   <http://www.gnu.org/licenses/>.  */
Packit 6c4009
Packit 6c4009
/* This file must be run from within a directory called "stdlib".  */
Packit 6c4009
Packit 6c4009
#include <errno.h>
Packit 6c4009
#include <limits.h>
Packit 6c4009
#include <stdio.h>
Packit 6c4009
#include <stdlib.h>
Packit 6c4009
#include <string.h>
Packit 6c4009
#include <unistd.h>
Packit 6c4009
#include <sys/stat.h>
Packit 6c4009
#include <sys/types.h>
Packit 6c4009
#include <support/test-driver.h>
Packit 6c4009
#include <libc-diag.h>
Packit 6c4009
Packit 6c4009
static int
Packit 6c4009
do_test (void)
Packit 6c4009
{
Packit Service 541783
  const char dir[] = "bz22786";
Packit Service 541783
  const char lnk[] = "bz22786/symlink";
Packit Service 541783
Packit Service 541783
  rmdir (dir);
Packit Service 541783
  if (mkdir (dir, 0755) != 0 && errno != EEXIST)
Packit Service 541783
    {
Packit Service 541783
      printf ("mkdir %s: %m\n", dir);
Packit Service 541783
      return EXIT_FAILURE;
Packit Service 541783
    }
Packit Service 541783
  if (symlink (".", lnk) != 0 && errno != EEXIST)
Packit Service 541783
    {
Packit Service 541783
      printf ("symlink (%s, %s): %m\n", dir, lnk);
Packit Service 541783
      return EXIT_FAILURE;
Packit Service 541783
    }
Packit Service 541783
Packit Service 541783
  const size_t path_len = (size_t) INT_MAX + 1;
Packit Service 541783
Packit Service 541783
  DIAG_PUSH_NEEDS_COMMENT;
Packit Service 541783
#if __GNUC_PREREQ (7, 0)
Packit Service 541783
  /* GCC 7 warns about too-large allocations; here we need such
Packit Service 541783
     allocation to succeed for the test to work.  */
Packit Service 541783
  DIAG_IGNORE_NEEDS_COMMENT (7, "-Walloc-size-larger-than=");
Packit Service 541783
#endif
Packit Service 541783
  char *path = malloc (path_len);
Packit Service 541783
  DIAG_POP_NEEDS_COMMENT;
Packit Service 562438
Packit Service 7e6f67
  if (path == NULL)
Packit Service 7e6f67
    {
Packit Service 541783
      printf ("malloc (%zu): %m\n", path_len);
Packit Service 7e6f67
      return EXIT_UNSUPPORTED;
Packit Service 7e6f67
    }
Packit Service 7e6f67
Packit Service 541783
  /* Construct very long path = "bz22786/symlink/aaaa....."  */
Packit Service 541783
  char *p = mempcpy (path, lnk, sizeof (lnk) - 1);
Packit 6c4009
  *(p++) = '/';
Packit Service 541783
  memset (p, 'a', path_len - (path - p) - 2);
Packit Service 541783
  p[path_len - (path - p) - 1] = '\0';
Packit 6c4009
Packit 6c4009
  /* This call crashes before the fix for bz22786 on 32-bit platforms.  */
Packit 6c4009
  p = realpath (path, NULL);
Packit 6c4009
Packit 6c4009
  if (p != NULL || errno != ENAMETOOLONG)
Packit 6c4009
    {
Packit 6c4009
      printf ("realpath: %s (%m)", p);
Packit 6c4009
      return EXIT_FAILURE;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  /* Cleanup.  */
Packit 6c4009
  unlink (lnk);
Packit Service 541783
  rmdir (dir);
Packit 6c4009
Packit 6c4009
  return 0;
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
#define TEST_FUNCTION do_test
Packit 6c4009
#include <support/test-driver.c>