1 /*
2 * Copyright (C) 2012 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17 #include <gtest/gtest.h>
18
19 // Below are the header files we want to test.
20 #include <grp.h>
21 #include <pwd.h>
22
23 #include <errno.h>
24 #include <limits.h>
25 #include <sys/cdefs.h>
26 #include <sys/types.h>
27 #include <unistd.h>
28
29 #include <set>
30 #include <vector>
31
32 #include <android-base/file.h>
33 #include <android-base/strings.h>
34 #include <private/android_filesystem_config.h>
35
36 #if defined(__BIONIC__)
37 #include <android/api-level.h>
38 #include <android-base/properties.h>
39 #endif
40
41 // Generated android_ids array
42 #include "generated_android_ids.h"
43
44 using android::base::Join;
45 using android::base::ReadFileToString;
46 using android::base::Split;
47 using android::base::StartsWith;
48
49 using namespace std::literals;
50
51 enum uid_type_t {
52 TYPE_APP,
53 TYPE_SYSTEM,
54 TYPE_VENDOR,
55 };
56
57 #if defined(__BIONIC__)
58
check_passwd(const passwd * pwd,const char * username,uid_t uid,uid_type_t uid_type,bool check_username)59 static void check_passwd(const passwd* pwd, const char* username, uid_t uid, uid_type_t uid_type,
60 bool check_username) {
61 ASSERT_TRUE(pwd != nullptr);
62 if (check_username) {
63 EXPECT_STREQ(username, pwd->pw_name);
64 }
65 EXPECT_EQ(uid, pwd->pw_uid);
66 EXPECT_EQ(uid, pwd->pw_gid);
67 EXPECT_EQ(nullptr, pwd->pw_passwd);
68 #ifdef __LP64__
69 EXPECT_EQ(nullptr, pwd->pw_gecos);
70 #endif
71
72 if (uid_type == TYPE_APP) {
73 EXPECT_STREQ("/data", pwd->pw_dir);
74 } else {
75 EXPECT_STREQ("/", pwd->pw_dir);
76 }
77
78 // This has changed over time and that causes new GSI + old vendor images testing to fail.
79 // This parameter doesn't matter on Android, so simply ignore its value for older vendor images.
80 if (android::base::GetIntProperty("ro.product.first_api_level", 0) >= 30) {
81 EXPECT_STREQ("/bin/sh", pwd->pw_shell);
82 }
83 }
84
check_getpwuid(const char * username,uid_t uid,uid_type_t uid_type,bool check_username)85 static void check_getpwuid(const char* username, uid_t uid, uid_type_t uid_type,
86 bool check_username) {
87 errno = 0;
88 passwd* pwd = getpwuid(uid);
89 ASSERT_EQ(0, errno);
90 SCOPED_TRACE("getpwuid");
91 check_passwd(pwd, username, uid, uid_type, check_username);
92 }
93
check_getpwnam(const char * username,uid_t uid,uid_type_t uid_type,bool check_username)94 static void check_getpwnam(const char* username, uid_t uid, uid_type_t uid_type,
95 bool check_username) {
96 errno = 0;
97 passwd* pwd = getpwnam(username);
98 ASSERT_EQ(0, errno);
99 SCOPED_TRACE("getpwnam");
100 check_passwd(pwd, username, uid, uid_type, check_username);
101 }
102
check_getpwuid_r(const char * username,uid_t uid,uid_type_t uid_type,bool check_username)103 static void check_getpwuid_r(const char* username, uid_t uid, uid_type_t uid_type,
104 bool check_username) {
105 passwd pwd_storage;
106 char buf[512];
107 int result;
108
109 errno = 0;
110 passwd* pwd = nullptr;
111 result = getpwuid_r(uid, &pwd_storage, buf, sizeof(buf), &pwd);
112 ASSERT_EQ(0, result);
113 ASSERT_EQ(0, errno);
114 SCOPED_TRACE("getpwuid_r");
115 check_passwd(pwd, username, uid, uid_type, check_username);
116 }
117
check_getpwnam_r(const char * username,uid_t uid,uid_type_t uid_type,bool check_username)118 static void check_getpwnam_r(const char* username, uid_t uid, uid_type_t uid_type,
119 bool check_username) {
120 passwd pwd_storage;
121 char buf[512];
122 int result;
123
124 errno = 0;
125 passwd* pwd = nullptr;
126 result = getpwnam_r(username, &pwd_storage, buf, sizeof(buf), &pwd);
127 ASSERT_EQ(0, result);
128 ASSERT_EQ(0, errno);
129 SCOPED_TRACE("getpwnam_r");
130 check_passwd(pwd, username, uid, uid_type, check_username);
131 }
132
check_get_passwd(const char * username,uid_t uid,uid_type_t uid_type,bool check_username=true)133 static void check_get_passwd(const char* username, uid_t uid, uid_type_t uid_type,
134 bool check_username = true) {
135 SCOPED_TRACE("username '"s + username + "'");
136 check_getpwuid(username, uid, uid_type, check_username);
137 check_getpwnam(username, uid, uid_type, check_username);
138 check_getpwuid_r(username, uid, uid_type, check_username);
139 check_getpwnam_r(username, uid, uid_type, check_username);
140 }
141
expect_no_passwd_id(uid_t uid)142 static void expect_no_passwd_id(uid_t uid) {
143 SCOPED_TRACE("uid '" + std::to_string(uid) + "'");
144 errno = 0;
145 passwd* passwd = nullptr;
146 passwd = getpwuid(uid);
147 EXPECT_EQ(nullptr, passwd) << "name = '" << passwd->pw_name << "'";
148 EXPECT_EQ(ENOENT, errno);
149
150 struct passwd passwd_storage;
151 char buf[512];
152 EXPECT_EQ(ENOENT, getpwuid_r(uid, &passwd_storage, buf, sizeof(buf), &passwd));
153 EXPECT_EQ(nullptr, passwd) << "name = '" << passwd->pw_name << "'";
154 }
155
expect_no_passwd_name(const char * username)156 static void expect_no_passwd_name(const char* username) {
157 SCOPED_TRACE("username '"s + username + "'");
158 errno = 0;
159 passwd* passwd = nullptr;
160 passwd = getpwnam(username);
161 EXPECT_EQ(nullptr, passwd) << "name = '" << passwd->pw_name << "'";
162 EXPECT_EQ(ENOENT, errno);
163
164 struct passwd passwd_storage;
165 char buf[512];
166 EXPECT_EQ(ENOENT, getpwnam_r(username, &passwd_storage, buf, sizeof(buf), &passwd));
167 EXPECT_EQ(nullptr, passwd) << "name = '" << passwd->pw_name << "'";
168 }
169
170 #else // !defined(__BIONIC__)
171
check_get_passwd(const char *,uid_t,uid_type_t,bool)172 static void check_get_passwd(const char* /* username */, uid_t /* uid */, uid_type_t /* uid_type */,
173 bool /* check_username */) {
174 GTEST_SKIP() << "bionic-only test";
175 }
176
check_get_passwd(const char *,uid_t,uid_type_t)177 static void check_get_passwd(const char* /* username */, uid_t /* uid */, uid_type_t /* uid_type */) {
178 GTEST_SKIP() << "bionic-only test";
179 }
180
expect_no_passwd_id(uid_t)181 static void expect_no_passwd_id(uid_t /* uid */) {
182 GTEST_SKIP() << "bionic-only test";
183 }
184
expect_no_passwd_name(const char *)185 static void expect_no_passwd_name(const char* /* username */) {
186 GTEST_SKIP() << "bionic-only test";
187 }
188
189 #endif
190
TEST(pwd,getpwnam_platform_ids)191 TEST(pwd, getpwnam_platform_ids) {
192 check_get_passwd("root", 0, TYPE_SYSTEM);
193 check_get_passwd("daemon", 1, TYPE_SYSTEM);
194 check_get_passwd("bin", 2, TYPE_SYSTEM);
195
196 check_get_passwd("system", 1000, TYPE_SYSTEM);
197 check_get_passwd("radio", 1001, TYPE_SYSTEM);
198
199 check_get_passwd("shell", 2000, TYPE_SYSTEM);
200
201 check_get_passwd("nobody", 9999, TYPE_SYSTEM);
202 }
203
TEST(pwd,getpwnam_oem_ids)204 TEST(pwd, getpwnam_oem_ids) {
205 check_get_passwd("oem_2900", 2900, TYPE_VENDOR, false);
206 check_get_passwd("oem_2945", 2945, TYPE_VENDOR, false);
207 check_get_passwd("oem_2999", 2999, TYPE_VENDOR, false);
208 check_get_passwd("oem_5000", 5000, TYPE_VENDOR, false);
209 check_get_passwd("oem_5454", 5454, TYPE_VENDOR, false);
210 check_get_passwd("oem_5999", 5999, TYPE_VENDOR, false);
211 }
212
TEST(pwd,getpwnam_non_exist)213 TEST(pwd, getpwnam_non_exist) {
214 expect_no_passwd_id(999); // End of the system reserved range, unallocated.
215 expect_no_passwd_id(1999); // End of the system reserved range, unallocated.
216 expect_no_passwd_id(2899); // End of the system reserved range, unallocated.
217
218 // These ranges are for GIDs only.
219 expect_no_passwd_id(20000);
220 expect_no_passwd_id(30000);
221 expect_no_passwd_id(40000);
222 expect_no_passwd_id(50000);
223
224 // These should not be parsed as users, only as groups.
225 expect_no_passwd_name("u0_a9999_cache");
226 expect_no_passwd_name("u0_a9999_ext");
227 expect_no_passwd_name("u0_a9999_ext_cache");
228 expect_no_passwd_name("all_a9999");
229 }
230
TEST(pwd,getpwnam_u0_app_ids)231 TEST(pwd, getpwnam_u0_app_ids) {
232 check_get_passwd("u0_a0", 10000, TYPE_APP);
233 check_get_passwd("u0_a1234", 11234, TYPE_APP);
234 check_get_passwd("u0_a9999", 19999, TYPE_APP);
235
236 check_get_passwd("u0_i1", 90001, TYPE_APP);
237 check_get_passwd("u0_i4545", 94545, TYPE_APP);
238 check_get_passwd("u0_i9999", 99999, TYPE_APP);
239 }
240
TEST(pwd,getpwnam_app_id_u1_ids)241 TEST(pwd, getpwnam_app_id_u1_ids) {
242 check_get_passwd("u1_system", 101000, TYPE_SYSTEM);
243 check_get_passwd("u1_radio", 101001, TYPE_SYSTEM);
244
245 check_get_passwd("u1_a0", 110000, TYPE_APP);
246 check_get_passwd("u1_a1234", 111234, TYPE_APP);
247 check_get_passwd("u1_a9999", 119999, TYPE_APP);
248
249 check_get_passwd("u1_i1", 190001, TYPE_APP);
250 check_get_passwd("u1_i4545", 194545, TYPE_APP);
251 check_get_passwd("u1_i9999", 199999, TYPE_APP);
252 }
253
TEST(pwd,getpwnam_app_id_u31_ids)254 TEST(pwd, getpwnam_app_id_u31_ids) {
255 check_get_passwd("u31_system", 3101000, TYPE_SYSTEM);
256 check_get_passwd("u31_radio", 3101001, TYPE_SYSTEM);
257
258 check_get_passwd("u31_a0", 3110000, TYPE_APP);
259 check_get_passwd("u31_a1234", 3111234, TYPE_APP);
260 check_get_passwd("u31_a9999", 3119999, TYPE_APP);
261
262 check_get_passwd("u31_i1", 3190001, TYPE_APP);
263 check_get_passwd("u31_i4545", 3194545, TYPE_APP);
264 check_get_passwd("u31_i9999", 3199999, TYPE_APP);
265 }
266
TEST(pwd,getpwnam_app_id_not_allowed_platform)267 TEST(pwd, getpwnam_app_id_not_allowed_platform) {
268 expect_no_passwd_name("u1_root");
269 expect_no_passwd_name("u1_debuggerd");
270
271 expect_no_passwd_name("u31_root");
272 expect_no_passwd_name("u31_debuggerd");
273 }
274
TEST(pwd,getpwuid_app_id_u1_non_exist)275 TEST(pwd, getpwuid_app_id_u1_non_exist) {
276 expect_no_passwd_id(100000); // There is no 'root' for secondary users.
277 expect_no_passwd_id(101999); // End of the system reserved range, unallocated.
278 expect_no_passwd_id(102900); // The OEM ranges were never allocated to secondary users.
279 expect_no_passwd_id(105000); // The OEM ranges were never allocated to secondary users.
280
281 // These ranges are for GIDs only.
282 expect_no_passwd_id(120000);
283 expect_no_passwd_id(130000);
284 expect_no_passwd_id(140000);
285 expect_no_passwd_id(150000);
286 }
287
TEST(pwd,getpwuid_app_id_u31_non_exist)288 TEST(pwd, getpwuid_app_id_u31_non_exist) {
289 expect_no_passwd_id(3100000); // There is no 'root' for secondary users.
290 expect_no_passwd_id(3101999); // End of the system reserved range, unallocated.
291 expect_no_passwd_id(3102900); // The OEM ranges were never allocated to secondary users.
292 expect_no_passwd_id(3105000); // The OEM ranges were never allocated to secondary users.
293
294 // These ranges are for GIDs only.
295 expect_no_passwd_id(3120000);
296 expect_no_passwd_id(3130000);
297 expect_no_passwd_id(3140000);
298 expect_no_passwd_id(3150000);
299 }
300
TEST(pwd,getpwnam_r_alignment)301 TEST(pwd, getpwnam_r_alignment) {
302 #if defined(__BIONIC__)
303 passwd pwd_storage;
304 alignas(16) char buf[512];
305 passwd* pwd;
306 int result = getpwnam_r("root", &pwd_storage, buf + 1, sizeof(buf) - 1, &pwd);
307 ASSERT_EQ(0, result);
308 check_passwd(pwd, "root", 0, TYPE_SYSTEM, true);
309 #else
310 GTEST_SKIP() << "bionic-only test";
311 #endif
312 }
313
TEST(pwd,getpwuid_r_alignment)314 TEST(pwd, getpwuid_r_alignment) {
315 #if defined(__BIONIC__)
316 passwd pwd_storage;
317 alignas(16) char buf[512];
318 passwd* pwd;
319 int result = getpwuid_r(0, &pwd_storage, buf + 1, sizeof(buf) - 1, &pwd);
320 ASSERT_EQ(0, result);
321 check_passwd(pwd, "root", 0, TYPE_SYSTEM, true);
322 #else
323 GTEST_SKIP() << "bionic-only test";
324 #endif
325 }
326
TEST(pwd,getpwnam_r_reentrancy)327 TEST(pwd, getpwnam_r_reentrancy) {
328 #if defined(__BIONIC__)
329 passwd pwd_storage[2];
330 char buf[2][512];
331 passwd* pwd[3];
332 int result = getpwnam_r("root", &pwd_storage[0], buf[0], sizeof(buf[0]), &pwd[0]);
333 ASSERT_EQ(0, result);
334 check_passwd(pwd[0], "root", 0, TYPE_SYSTEM, true);
335 pwd[1] = getpwnam("system");
336 ASSERT_NE(nullptr, pwd[1]);
337 check_passwd(pwd[1], "system", 1000, TYPE_SYSTEM, true);
338 result = getpwnam_r("radio", &pwd_storage[1], buf[1], sizeof(buf[1]), &pwd[2]);
339 ASSERT_EQ(0, result);
340 check_passwd(pwd[2], "radio", 1001, TYPE_SYSTEM, true);
341 check_passwd(pwd[0], "root", 0, TYPE_SYSTEM, true);
342 check_passwd(pwd[1], "system", 1000, TYPE_SYSTEM, true);
343 #else
344 GTEST_SKIP() << "bionic-only test";
345 #endif
346 }
347
TEST(pwd,getpwuid_r_reentrancy)348 TEST(pwd, getpwuid_r_reentrancy) {
349 #if defined(__BIONIC__)
350 passwd pwd_storage[2];
351 char buf[2][512];
352 passwd* pwd[3];
353 int result = getpwuid_r(0, &pwd_storage[0], buf[0], sizeof(buf[0]), &pwd[0]);
354 ASSERT_EQ(0, result);
355 check_passwd(pwd[0], "root", 0, TYPE_SYSTEM, true);
356 pwd[1] = getpwuid(1000);
357 ASSERT_NE(nullptr, pwd[1]);
358 check_passwd(pwd[1], "system", 1000, TYPE_SYSTEM, true);
359 result = getpwuid_r(1001, &pwd_storage[1], buf[1], sizeof(buf[1]), &pwd[2]);
360 ASSERT_EQ(0, result);
361 check_passwd(pwd[2], "radio", 1001, TYPE_SYSTEM, true);
362 check_passwd(pwd[0], "root", 0, TYPE_SYSTEM, true);
363 check_passwd(pwd[1], "system", 1000, TYPE_SYSTEM, true);
364 #else
365 GTEST_SKIP() << "bionic-only test";
366 #endif
367 }
368
TEST(pwd,getpwnam_r_large_enough_suggested_buffer_size)369 TEST(pwd, getpwnam_r_large_enough_suggested_buffer_size) {
370 #if defined(__BIONIC__)
371 long size = sysconf(_SC_GETPW_R_SIZE_MAX);
372 ASSERT_GT(size, 0);
373 char buf[size];
374 passwd pwd_storage;
375 passwd* pwd;
376 ASSERT_EQ(0, getpwnam_r("root", &pwd_storage, buf, size, &pwd));
377 check_passwd(pwd, "root", 0, TYPE_SYSTEM, true);
378 #else
379 GTEST_SKIP() << "bionic-only test";
380 #endif
381 }
382
383 #if defined(__BIONIC__)
384 template <typename T>
expect_ids(T ids,bool is_group)385 static void expect_ids(T ids, bool is_group) {
386 std::set<typename T::key_type> expected_ids;
387 // Ensure that all android_ids are iterated through.
388 for (size_t n = 0; n < android_id_count; ++n) {
389 EXPECT_EQ(1U, ids.count(android_ids[n].aid)) << "android_ids[n].aid: " << android_ids[n].aid;
390 expected_ids.emplace(android_ids[n].aid);
391 }
392
393 auto expect_range = [&ids, &expected_ids](uid_t start, uid_t end) {
394 for (size_t n = start; n <= end; ++n) {
395 EXPECT_EQ(1U, ids.count(n)) << "n: " << n;
396 expected_ids.emplace(n);
397 }
398 };
399
400 // Ensure that all reserved ranges are iterated through.
401 expect_range(AID_OEM_RESERVED_START, AID_OEM_RESERVED_END);
402 expect_range(AID_OEM_RESERVED_2_START, AID_OEM_RESERVED_2_END);
403 expect_range(AID_APP_START, AID_APP_END);
404 if (is_group) {
405 expect_range(AID_CACHE_GID_START, AID_CACHE_GID_END);
406 expect_range(AID_EXT_GID_START, AID_EXT_GID_END);
407 expect_range(AID_EXT_CACHE_GID_START, AID_EXT_CACHE_GID_END);
408 expect_range(AID_SHARED_GID_START, AID_SHARED_GID_END);
409 }
410 expect_range(AID_ISOLATED_START, AID_ISOLATED_END);
411
412 // TODO(73062966): We still don't have a good way to create vendor AIDs in the system or other
413 // non-vendor partitions, therefore we keep this check disabled.
414 if (android::base::GetIntProperty("ro.product.first_api_level", 0) <= 29) {
415 return;
416 }
417
418 auto allow_range = [&ids](uid_t start, uid_t end) {
419 for (size_t n = start; n <= end; ++n) {
420 ids.erase(n);
421 }
422 };
423
424 allow_range(AID_SYSTEM_RESERVED_START, AID_SYSTEM_EXT_RESERVED_END);
425
426 // Ensure that no other ids were returned.
427 auto return_differences = [&ids, &expected_ids] {
428 std::vector<typename T::key_type> missing_from_ids;
429 std::set_difference(expected_ids.begin(), expected_ids.end(), ids.begin(), ids.end(),
430 std::inserter(missing_from_ids, missing_from_ids.begin()));
431 std::vector<typename T::key_type> extra_in_ids;
432 std::set_difference(ids.begin(), ids.end(), expected_ids.begin(), expected_ids.end(),
433 std::inserter(extra_in_ids, extra_in_ids.begin()));
434 std::string result;
435 if (!missing_from_ids.empty()) {
436 result += "Missing ids from results: " + Join(missing_from_ids, " ");
437 }
438 if (!extra_in_ids.empty()) {
439 if (!result.empty()) result += ", ";
440 result += "Extra ids in results: " + Join(extra_in_ids, " ");
441 }
442 return result;
443 };
444 EXPECT_EQ(expected_ids, ids) << return_differences();
445 }
446 #endif
447
TEST(pwd,getpwent_iterate)448 TEST(pwd, getpwent_iterate) {
449 #if defined(__BIONIC__)
450 passwd* pwd;
451 std::set<uid_t> uids;
452
453 setpwent();
454 while ((pwd = getpwent()) != nullptr) {
455 ASSERT_TRUE(nullptr != pwd->pw_name);
456
457 EXPECT_EQ(pwd->pw_gid, pwd->pw_uid) << "pwd->pw_uid: " << pwd->pw_uid;
458 EXPECT_EQ(nullptr, pwd->pw_passwd) << "pwd->pw_uid: " << pwd->pw_uid;
459 #ifdef __LP64__
460 EXPECT_TRUE(nullptr == pwd->pw_gecos) << "pwd->pw_uid: " << pwd->pw_uid;
461 #endif
462 EXPECT_TRUE(nullptr != pwd->pw_shell);
463 if (pwd->pw_uid < AID_APP_START || pwd->pw_uid == AID_OVERFLOWUID) {
464 EXPECT_STREQ("/", pwd->pw_dir) << "pwd->pw_uid: " << pwd->pw_uid;
465 } else {
466 EXPECT_STREQ("/data", pwd->pw_dir) << "pwd->pw_uid: " << pwd->pw_uid;
467 }
468
469 // TODO(b/27999086): fix this check with the OEM range
470 // If OEMs add their own AIDs to private/android_filesystem_config.h, this check will fail.
471 // Long term we want to create a better solution for OEMs adding AIDs, but we're not there
472 // yet, so therefore we do not check for uid's in the OEM range.
473 if (!(pwd->pw_uid >= 2900 && pwd->pw_uid <= 2999) &&
474 !(pwd->pw_uid >= 5000 && pwd->pw_uid <= 5999)) {
475 EXPECT_EQ(0U, uids.count(pwd->pw_uid)) << "pwd->pw_uid: " << pwd->pw_uid;
476 }
477 uids.emplace(pwd->pw_uid);
478 }
479 endpwent();
480
481 expect_ids(uids, false);
482 #else
483 GTEST_SKIP() << "bionic-only test";
484 #endif
485 }
486
check_group(const group * grp,const char * group_name,gid_t gid,bool check_groupname=true)487 static void check_group(const group* grp, const char* group_name, gid_t gid,
488 bool check_groupname = true) {
489 ASSERT_TRUE(grp != nullptr);
490 if (check_groupname) {
491 EXPECT_STREQ(group_name, grp->gr_name);
492 }
493 EXPECT_EQ(gid, grp->gr_gid);
494 ASSERT_TRUE(grp->gr_mem != nullptr);
495 if (check_groupname) {
496 EXPECT_STREQ(group_name, grp->gr_mem[0]);
497 }
498 EXPECT_TRUE(grp->gr_mem[1] == nullptr);
499 }
500
501 #if defined(__BIONIC__)
502
check_getgrgid(const char * group_name,gid_t gid,bool check_groupname)503 static void check_getgrgid(const char* group_name, gid_t gid, bool check_groupname) {
504 errno = 0;
505 group* grp = getgrgid(gid);
506 ASSERT_EQ(0, errno);
507 SCOPED_TRACE("getgrgid");
508 check_group(grp, group_name, gid, check_groupname);
509 }
510
check_getgrnam(const char * group_name,gid_t gid,bool check_groupname)511 static void check_getgrnam(const char* group_name, gid_t gid, bool check_groupname) {
512 errno = 0;
513 group* grp = getgrnam(group_name);
514 ASSERT_EQ(0, errno);
515 SCOPED_TRACE("getgrnam");
516 check_group(grp, group_name, gid, check_groupname);
517 }
518
check_getgrgid_r(const char * group_name,gid_t gid,bool check_groupname)519 static void check_getgrgid_r(const char* group_name, gid_t gid, bool check_groupname) {
520 group grp_storage;
521 char buf[512];
522 group* grp;
523
524 errno = 0;
525 int result = getgrgid_r(gid, &grp_storage, buf, sizeof(buf), &grp);
526 ASSERT_EQ(0, result);
527 ASSERT_EQ(0, errno);
528 SCOPED_TRACE("getgrgid_r");
529 check_group(grp, group_name, gid, check_groupname);
530 }
531
check_getgrnam_r(const char * group_name,gid_t gid,bool check_groupname)532 static void check_getgrnam_r(const char* group_name, gid_t gid, bool check_groupname) {
533 group grp_storage;
534 char buf[512];
535 group* grp;
536
537 errno = 0;
538 int result = getgrnam_r(group_name, &grp_storage, buf, sizeof(buf), &grp);
539 ASSERT_EQ(0, result);
540 ASSERT_EQ(0, errno);
541 SCOPED_TRACE("getgrnam_r");
542 check_group(grp, group_name, gid, check_groupname);
543 }
544
check_get_group(const char * group_name,gid_t gid,bool check_groupname=true)545 static void check_get_group(const char* group_name, gid_t gid, bool check_groupname = true) {
546 SCOPED_TRACE("groupname '"s + group_name + "'");
547 check_getgrgid(group_name, gid, check_groupname);
548 check_getgrnam(group_name, gid, check_groupname);
549 check_getgrgid_r(group_name, gid, check_groupname);
550 check_getgrnam_r(group_name, gid, check_groupname);
551 }
552
expect_no_group_id(gid_t gid)553 static void expect_no_group_id(gid_t gid) {
554 SCOPED_TRACE("gid '" + std::to_string(gid) + "'");
555 errno = 0;
556 group* group = nullptr;
557 group = getgrgid(gid);
558 EXPECT_EQ(nullptr, group) << "name = '" << group->gr_name << "'";
559 EXPECT_EQ(ENOENT, errno);
560
561 struct group group_storage;
562 char buf[512];
563 EXPECT_EQ(ENOENT, getgrgid_r(gid, &group_storage, buf, sizeof(buf), &group));
564 EXPECT_EQ(nullptr, group) << "name = '" << group->gr_name << "'";
565 }
566
expect_no_group_name(const char * groupname)567 static void expect_no_group_name(const char* groupname) {
568 SCOPED_TRACE("groupname '"s + groupname + "'");
569 errno = 0;
570 group* group = nullptr;
571 group = getgrnam(groupname);
572 EXPECT_EQ(nullptr, group) << "name = '" << group->gr_name << "'";
573 EXPECT_EQ(ENOENT, errno);
574
575 struct group group_storage;
576 char buf[512];
577 EXPECT_EQ(ENOENT, getgrnam_r(groupname, &group_storage, buf, sizeof(buf), &group));
578 EXPECT_EQ(nullptr, group) << "name = '" << group->gr_name << "'";
579 }
580
581 #else // !defined(__BIONIC__)
582
check_get_group(const char *,gid_t,bool)583 static void check_get_group(const char*, gid_t, bool) {
584 GTEST_SKIP() << "bionic-only test";
585 }
586
check_get_group(const char *,gid_t)587 static void check_get_group(const char*, gid_t) {
588 GTEST_SKIP() << "bionic-only test";
589 }
590
expect_no_group_id(gid_t)591 static void expect_no_group_id(gid_t /* gid */) {
592 GTEST_SKIP() << "bionic-only test";
593 }
594
expect_no_group_name(const char *)595 static void expect_no_group_name(const char* /* groupname */) {
596 GTEST_SKIP() << "bionic-only test";
597 }
598
599 #endif
600
TEST(grp,getgrnam_platform_ids)601 TEST(grp, getgrnam_platform_ids) {
602 check_get_group("root", 0);
603 check_get_group("daemon", 1);
604 check_get_group("bin", 2);
605
606 check_get_group("system", 1000);
607 check_get_group("radio", 1001);
608
609 check_get_group("shell", 2000);
610
611 check_get_group("nobody", 9999);
612 }
613
TEST(grp,getgrnam_oem_ids)614 TEST(grp, getgrnam_oem_ids) {
615 check_get_group("oem_2900", 2900, false);
616 check_get_group("oem_2945", 2945, false);
617 check_get_group("oem_2999", 2999, false);
618 check_get_group("oem_5000", 5000, false);
619 check_get_group("oem_5454", 5454, false);
620 check_get_group("oem_5999", 5999, false);
621 }
622
TEST(grp,getgrnam_non_exist)623 TEST(grp, getgrnam_non_exist) {
624 expect_no_passwd_id(999); // End of the system reserved range, unallocated.
625 expect_no_passwd_id(1999); // End of the system reserved range, unallocated.
626 expect_no_passwd_id(2899); // End of the system reserved range, unallocated.
627 }
628
TEST(grp,getgrnam_u0_app_ids)629 TEST(grp, getgrnam_u0_app_ids) {
630 check_get_group("u0_a0", 10000);
631 check_get_group("u0_a1234", 11234);
632 check_get_group("u0_a9999", 19999);
633
634 check_get_group("u0_a0_cache", 20000);
635 check_get_group("u0_a1234_cache", 21234);
636 check_get_group("u0_a9999_cache", 29999);
637
638 check_get_group("u0_a0_ext", 30000);
639 check_get_group("u0_a4545_ext", 34545);
640 check_get_group("u0_a9999_ext", 39999);
641
642 check_get_group("u0_a0_ext_cache", 40000);
643 check_get_group("u0_a4545_ext_cache", 44545);
644 check_get_group("u0_a9999_ext_cache", 49999);
645
646 check_get_group("all_a0", 50000);
647 check_get_group("all_a4545", 54545);
648 check_get_group("all_a9999", 59999);
649
650 check_get_group("u0_i1", 90001);
651 }
652
TEST(grp,getgrnam_u1_app_ids)653 TEST(grp, getgrnam_u1_app_ids) {
654 check_get_group("u1_system", 101000);
655 check_get_group("u1_radio", 101001);
656
657 check_get_group("u1_a0", 110000);
658 check_get_group("u1_a1234", 111234);
659 check_get_group("u1_a9999", 119999);
660
661 check_get_group("u1_a0_cache", 120000);
662 check_get_group("u1_a1234_cache", 121234);
663 check_get_group("u1_a9999_cache", 129999);
664
665 check_get_group("u1_a0_ext", 130000);
666 check_get_group("u1_a4545_ext", 134545);
667 check_get_group("u1_a9999_ext", 139999);
668
669 check_get_group("u1_a0_ext_cache", 140000);
670 check_get_group("u1_a4545_ext_cache", 144545);
671 check_get_group("u1_a9999_ext_cache", 149999);
672
673 check_get_group("u1_i1", 190001);
674 }
675
TEST(grp,getgrnam_u31_app_ids)676 TEST(grp, getgrnam_u31_app_ids) {
677 check_get_group("u31_system", 3101000);
678 check_get_group("u31_radio", 3101001);
679
680 check_get_group("u31_a0", 3110000);
681 check_get_group("u31_a1234", 3111234);
682 check_get_group("u31_a9999", 3119999);
683
684 check_get_group("u31_a0_cache", 3120000);
685 check_get_group("u31_a1234_cache", 3121234);
686 check_get_group("u31_a9999_cache", 3129999);
687
688 check_get_group("u31_a0_cache", 3120000);
689 check_get_group("u31_a1234_cache", 3121234);
690 check_get_group("u31_a9999_cache", 3129999);
691
692 check_get_group("u31_a0_ext", 3130000);
693 check_get_group("u31_a4545_ext", 3134545);
694 check_get_group("u31_a9999_ext", 3139999);
695
696 check_get_group("u31_a0_ext_cache", 3140000);
697 check_get_group("u31_a4545_ext_cache", 3144545);
698 check_get_group("u31_a9999_ext_cache", 3149999);
699
700 check_get_group("u31_i1", 3190001);
701 }
702
TEST(grp,getpgram_app_id_not_allowed_platform)703 TEST(grp, getpgram_app_id_not_allowed_platform) {
704 expect_no_group_name("u1_root");
705 expect_no_group_name("u1_debuggerd");
706
707 expect_no_group_name("u31_root");
708 expect_no_group_name("u31_debuggerd");
709 }
710
TEST(grp,getgrgid_app_id_u1_non_exist)711 TEST(grp, getgrgid_app_id_u1_non_exist) {
712 expect_no_group_id(100000); // There is no 'root' for secondary users.
713 expect_no_group_id(101999); // End of the system reserved range, unallocated.
714 expect_no_group_id(102900); // The OEM ranges were never allocated to secondary users.
715 expect_no_group_id(105000); // The OEM ranges were never allocated to secondary users.
716
717 // The shared range is shared among users, and therefore doesn't exist for secondary users.
718 expect_no_group_id(150000);
719 }
720
TEST(grp,getgrgid_app_id_u31_non_exist)721 TEST(grp, getgrgid_app_id_u31_non_exist) {
722 expect_no_group_id(3100000); // There is no 'root' for secondary users.
723 expect_no_group_id(3101999); // End of the system reserved range, unallocated.
724 expect_no_group_id(3102900); // The OEM ranges were never allocated to secondary users.
725 expect_no_group_id(3105000); // The OEM ranges were never allocated to secondary users.
726
727 // The shared range is shared among users, and therefore doesn't exist for secondary users.
728 expect_no_group_id(3150000);
729 }
730
TEST(grp,getgrnam_r_alignment)731 TEST(grp, getgrnam_r_alignment) {
732 #if defined(__BIONIC__)
733 group grp_storage;
734 alignas(16) char buf[512];
735 group* grp;
736 int result = getgrnam_r("root", &grp_storage, buf + 1, sizeof(buf) - 1, &grp);
737 ASSERT_EQ(0, result);
738 check_group(grp, "root", 0);
739 #else
740 GTEST_SKIP() << "bionic-only test";
741 #endif
742 }
743
TEST(grp,getgrgid_r_alignment)744 TEST(grp, getgrgid_r_alignment) {
745 #if defined(__BIONIC__)
746 group grp_storage;
747 alignas(16) char buf[512];
748 group* grp;
749 int result = getgrgid_r(0, &grp_storage, buf + 1, sizeof(buf) - 1, &grp);
750 ASSERT_EQ(0, result);
751 check_group(grp, "root", 0);
752 #else
753 GTEST_SKIP() << "bionic-only test";
754 #endif
755 }
756
TEST(grp,getgrnam_r_reentrancy)757 TEST(grp, getgrnam_r_reentrancy) {
758 #if defined(__BIONIC__)
759 group grp_storage[2];
760 char buf[2][512];
761 group* grp[3];
762 int result = getgrnam_r("root", &grp_storage[0], buf[0], sizeof(buf[0]), &grp[0]);
763 ASSERT_EQ(0, result);
764 check_group(grp[0], "root", 0);
765 grp[1] = getgrnam("system");
766 check_group(grp[1], "system", 1000);
767 result = getgrnam_r("radio", &grp_storage[1], buf[1], sizeof(buf[1]), &grp[2]);
768 ASSERT_EQ(0, result);
769 check_group(grp[2], "radio", 1001);
770 check_group(grp[0], "root", 0);
771 check_group(grp[1], "system", 1000);
772 #else
773 GTEST_SKIP() << "bionic-only test";
774 #endif
775 }
776
TEST(grp,getgrgid_r_reentrancy)777 TEST(grp, getgrgid_r_reentrancy) {
778 #if defined(__BIONIC__)
779 group grp_storage[2];
780 char buf[2][512];
781 group* grp[3];
782 int result = getgrgid_r(0, &grp_storage[0], buf[0], sizeof(buf[0]), &grp[0]);
783 ASSERT_EQ(0, result);
784 check_group(grp[0], "root", 0);
785 grp[1] = getgrgid(1000);
786 check_group(grp[1], "system", 1000);
787 result = getgrgid_r(1001, &grp_storage[1], buf[1], sizeof(buf[1]), &grp[2]);
788 ASSERT_EQ(0, result);
789 check_group(grp[2], "radio", 1001);
790 check_group(grp[0], "root", 0);
791 check_group(grp[1], "system", 1000);
792 #else
793 GTEST_SKIP() << "bionic-only test";
794 #endif
795 }
796
TEST(grp,getgrnam_r_large_enough_suggested_buffer_size)797 TEST(grp, getgrnam_r_large_enough_suggested_buffer_size) {
798 long size = sysconf(_SC_GETGR_R_SIZE_MAX);
799 ASSERT_GT(size, 0);
800 char buf[size];
801 group grp_storage;
802 group* grp;
803 ASSERT_EQ(0, getgrnam_r("root", &grp_storage, buf, size, &grp));
804 check_group(grp, "root", 0);
805 }
806
TEST(grp,getgrent_iterate)807 TEST(grp, getgrent_iterate) {
808 #if defined(__BIONIC__)
809 group* grp;
810 std::set<gid_t> gids;
811
812 setgrent();
813 while ((grp = getgrent()) != nullptr) {
814 ASSERT_TRUE(grp->gr_name != nullptr) << "grp->gr_gid: " << grp->gr_gid;
815 ASSERT_TRUE(grp->gr_mem != nullptr) << "grp->gr_gid: " << grp->gr_gid;
816 EXPECT_STREQ(grp->gr_name, grp->gr_mem[0]) << "grp->gr_gid: " << grp->gr_gid;
817 EXPECT_TRUE(grp->gr_mem[1] == nullptr) << "grp->gr_gid: " << grp->gr_gid;
818
819 // TODO(b/27999086): fix this check with the OEM range
820 // If OEMs add their own AIDs to private/android_filesystem_config.h, this check will fail.
821 // Long term we want to create a better solution for OEMs adding AIDs, but we're not there
822 // yet, so therefore we do not check for gid's in the OEM range.
823 if (!(grp->gr_gid >= 2900 && grp->gr_gid <= 2999) &&
824 !(grp->gr_gid >= 5000 && grp->gr_gid <= 5999)) {
825 EXPECT_EQ(0U, gids.count(grp->gr_gid)) << "grp->gr_gid: " << grp->gr_gid;
826 }
827 gids.emplace(grp->gr_gid);
828 }
829 endgrent();
830
831 expect_ids(gids, true);
832 #else
833 GTEST_SKIP() << "bionic-only test";
834 #endif
835 }
836
837 #if defined(__BIONIC__)
TestAidNamePrefix(const std::string & file_path)838 static void TestAidNamePrefix(const std::string& file_path) {
839 std::string file_contents;
840 if (!ReadFileToString(file_path, &file_contents)) {
841 // If we cannot read this file, then there are no vendor defind AID names, in which case this
842 // test passes by default.
843 return;
844 }
845 auto lines = Split(file_contents, "\n");
846 for (const auto& line : lines) {
847 if (line.empty()) continue;
848 auto name = Split(line, ":")[0];
849 EXPECT_TRUE(StartsWith(name, "vendor_"));
850 }
851 }
852 #endif
853
TEST(pwd,vendor_prefix_users)854 TEST(pwd, vendor_prefix_users) {
855 #if defined(__BIONIC__)
856 if (android::base::GetIntProperty("ro.product.first_api_level", 0) <= 28) {
857 return;
858 }
859
860 TestAidNamePrefix("/vendor/etc/passwd");
861 #else
862 GTEST_SKIP() << "bionic-only test";
863 #endif
864 }
865
TEST(pwd,vendor_prefix_groups)866 TEST(pwd, vendor_prefix_groups) {
867 #if defined(__BIONIC__)
868 if (android::base::GetIntProperty("ro.product.first_api_level", 0) <= 28) {
869 return;
870 }
871
872 TestAidNamePrefix("/vendor/etc/group");
873 #else
874 GTEST_SKIP() << "bionic-only test";
875 #endif
876 }
877