1 /*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
4 This file is part of systemd.
6 Copyright 2014 Daniel Mack
8 systemd is free software; you can redistribute it and/or modify it
9 under the terms of the GNU Lesser General Public License as published by
10 the Free Software Foundation; either version 2.1 of the License, or
11 (at your option) any later version.
13 systemd is distributed in the hope that it will be useful, but
14 WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 Lesser General Public License for more details.
18 You should have received a copy of the GNU Lesser General Public License
19 along with systemd; If not, see <http://www.gnu.org/licenses/>.
22 #include <sys/socket.h>
24 #include <sys/types.h>
36 #include "bus-internal.h"
37 #include "bus-message.h"
42 #include "capability.h"
44 #include <bus-proxyd/bus-policy.h>
46 static int test_policy_load(Policy *p, const char *name)
48 _cleanup_free_ char *path = NULL;
51 path = strjoin(TEST_DIR, "/bus-policy/", name, NULL);
54 if (access(path, R_OK) == 0)
55 policy_load(p, STRV_MAKE(path));
62 int main(int argc, char *argv[]) {
65 struct ucred ucred = {};
68 assert_se(test_policy_load(&p, "ownerships.conf") == 0);
71 assert_se(policy_check_own(&p, &ucred, "org.test.test1") == true);
73 assert_se(policy_check_own(&p, &ucred, "org.test.test1") == true);
76 assert_se(policy_check_own(&p, &ucred, "org.test.test2") == true);
78 assert_se(policy_check_own(&p, &ucred, "org.test.test2") == false);
81 assert_se(policy_check_own(&p, &ucred, "org.test.test3") == false);
83 assert_se(policy_check_own(&p, &ucred, "org.test.test3") == false);
86 assert_se(policy_check_own(&p, &ucred, "org.test.test4") == false);
88 assert_se(policy_check_own(&p, &ucred, "org.test.test4") == true);
93 assert_se(test_policy_load(&p, "signals.conf") == 0);
96 assert_se(policy_check_send(&p, &ucred, SD_BUS_MESSAGE_SIGNAL, "bli.bla.blubb", NULL, "/an/object/path", NULL) == true);
99 assert_se(policy_check_send(&p, &ucred, SD_BUS_MESSAGE_SIGNAL, "bli.bla.blubb", NULL, "/an/object/path", NULL) == false);
104 assert_se(test_policy_load(&p, "methods.conf") == 0);
109 assert_se(policy_check_send(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.test.test1", "/an/object/path", "bli.bla.blubb", "Member") == false);
110 assert_se(policy_check_send(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.test.test1", "/an/object/path", "bli.bla.blubb", "Member") == false);
111 assert_se(policy_check_send(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.test.test1", "/an/object/path", "org.test.int1", "Member") == true);
112 assert_se(policy_check_send(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.test.test1", "/an/object/path", "org.test.int2", "Member") == true);
114 assert_se(policy_check_recv(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.test.test3", "/an/object/path", "org.test.int3", "Member111") == true);
118 /* User and groups */
119 assert_se(test_policy_load(&p, "hello.conf") == 0);
123 assert_se(policy_check_hello(&p, &ucred) == true);
126 assert_se(policy_check_hello(&p, &ucred) == false);
130 assert_se(policy_check_hello(&p, &ucred) == false);
134 /* dbus1 test file: ownership */
136 assert_se(test_policy_load(&p, "check-own-rules.conf") >= 0);
139 assert_se(policy_check_own(&p, &ucred, "org.freedesktop") == false);
140 assert_se(policy_check_own(&p, &ucred, "org.freedesktop.ManySystem") == false);
141 assert_se(policy_check_own(&p, &ucred, "org.freedesktop.ManySystems") == true);
142 assert_se(policy_check_own(&p, &ucred, "org.freedesktop.ManySystems.foo") == true);
143 assert_se(policy_check_own(&p, &ucred, "org.freedesktop.ManySystems.foo.bar") == true);
144 assert_se(policy_check_own(&p, &ucred, "org.freedesktop.ManySystems2") == false);
145 assert_se(policy_check_own(&p, &ucred, "org.freedesktop.ManySystems2.foo") == false);
146 assert_se(policy_check_own(&p, &ucred, "org.freedesktop.ManySystems2.foo.bar") == false);
150 /* dbus1 test file: many rules */
152 assert_se(test_policy_load(&p, "many-rules.conf") >= 0);
156 /* dbus1 test file: generic test */
158 assert_se(test_policy_load(&p, "test.conf") >= 0);
162 assert_se(policy_check_own(&p, &ucred, "org.foo.FooService") == true);
163 assert_se(policy_check_own(&p, &ucred, "org.foo.FooService2") == false);
164 assert_se(policy_check_send(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.test.test1", "/an/object/path", "org.test.int2", "Member") == false);
165 assert_se(policy_check_send(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.test.test1", "/an/object/path", "org.foo.FooBroadcastInterface", "Member") == true);
166 assert_se(policy_check_recv(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.foo.FooService", "/an/object/path", "org.foo.FooBroadcastInterface", "Member") == true);
167 assert_se(policy_check_recv(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.foo.FooService", "/an/object/path", "org.foo.FooBroadcastInterface2", "Member") == false);
168 assert_se(policy_check_recv(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.foo.FooService2", "/an/object/path", "org.foo.FooBroadcastInterface", "Member") == false);
171 assert_se(policy_check_own(&p, &ucred, "org.foo.FooService") == false);
172 assert_se(policy_check_own(&p, &ucred, "org.foo.FooService2") == false);
173 assert_se(policy_check_send(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.test.test1", "/an/object/path", "org.test.int2", "Member") == false);
174 assert_se(policy_check_send(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.test.test1", "/an/object/path", "org.foo.FooBroadcastInterface", "Member") == false);
175 assert_se(policy_check_recv(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.foo.FooService", "/an/object/path", "org.foo.FooBroadcastInterface", "Member") == true);
176 assert_se(policy_check_recv(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.foo.FooService", "/an/object/path", "org.foo.FooBroadcastInterface2", "Member") == false);
177 assert_se(policy_check_recv(&p, &ucred, SD_BUS_MESSAGE_METHOD_CALL, "org.foo.FooService2", "/an/object/path", "org.foo.FooBroadcastInterface", "Member") == false);