1 /*
2  * Copyright (c) 2017 Richard Palethorpe <rpalethorpe@suse.com>
3  *
4  * This program is free software: you can redistribute it and/or modify
5  * it under the terms of the GNU General Public License as published by
6  * the Free Software Foundation, either version 2 of the License, or
7  * (at your option) any later version.
8  *
9  * This program is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12  * GNU General Public License for more details.
13  *
14  * You should have received a copy of the GNU General Public License
15  * along with this program. If not, see <http://www.gnu.org/licenses/>.
16  */
17 /* Check for CVE-2016-9604; that keys beginning with "." are disallowed.
18  *
19  * See commit ee8f844e3c5a73b999edf733df1c529d6503ec2f
20  */
21 
22 #include <errno.h>
23 #include "tst_test.h"
24 #include "lapi/keyctl.h"
25 
run(void)26 void run(void)
27 {
28 	if (keyctl_join_session_keyring(".builtin_trusted_keys") == -1) {
29 		if (errno != EPERM) {
30 			tst_brk(TBROK | TERRNO,
31 				"keyctl_join_sessoin_keyring(...)");
32 		}
33 
34 		tst_res(TPASS, "Denied access to .builtin_trusted_keys");
35 	} else {
36 		tst_res(TFAIL, "Allowed access to .builtin_trusted_keys");
37 	}
38 }
39 
40 static struct tst_test test = {
41 	.test_all = run,
42 	.needs_root = 1,
43 	.min_kver = "2.6.13",
44 };
45