From nobody Thu Apr 2 11:20:46 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4fmfYB3Mr5z6YGtp for ; Thu, 02 Apr 2026 11:20:46 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4fmfYB1lvrz3JYn for ; Thu, 02 Apr 2026 11:20:46 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1775128846; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=O4g0jc5ORWJdf7+1pPv0RFbREkpOL13HBas34Imkg4s=; b=JQ3FLosA3adGrcA9X+AyLqCs5Go6KyKFnF6hIlxdKB1ATk3dUQUKUfYh1k9Yeqam301qg7 +CjrTKgXKfqrGt6HRcx40L3ani3r2TsyRq92VGON4Aqs/ZDQCYwNsSmqCV36toGIctPWw3 qmvxa0FZfiP8iejpifu+npnrkFkMv910FP7AgZ7BCN7isydzbLktbNIwycyD22MKRRMKgJ TVOATAvDzUj/BpezmaJIi1k/bHbbq5hIHleAEzATYX0J1koxSC2u8eNj83srWLxewZdBoR xKFzpoO+sz3FVmUZV9t4ey9hdeOjdPSx4/V2AofXHzazRb/zuM6yXhcG2cinow== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1775128846; a=rsa-sha256; cv=none; b=jFC46AjwF1jHXes8AKyxFSc5srtCIcBtXShQAET4ow8h4Y8Kpo6aiB5eldm0ccxyNtMh6w FHKQ0lZdmEpsEZXC9EmqpDpEMhC+6Pa6U0RWfj+AcCnAz07oe5UEHHGOFBZ21c+//ghkh+ BOiU5AO5WX6uOyKqVSKBHNCT9yFTNfszpQEsfD0hRJWwqLCncPDVF6QzKEXn9GJRTrRGjK C0nad0nwAuf/SqgyAoc/VLClLiKSKdGALllBvH38yyDSUFT0MrnL1MdPwum0801vfE4Wq+ CJg62w6XkErhWHAqfzIT9bqXXrihpw3FSEpBwpsf0dnfGBln9pdH9UTSFYfzlg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1775128846; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=O4g0jc5ORWJdf7+1pPv0RFbREkpOL13HBas34Imkg4s=; b=nd7iOM3uDMRTN6Bee6NhqDK0rGBcO8cWAdXpgzWk6qhVV6krKKdhVlNefwXn/ScYAF2QBz 66aBiYA8i+iZlAQA5pKpdjALOmR8qVnArJHxJYhaMFsM0C9kVLKzoYtgxioFeS5E9tC/OX VFuD4Pxmd5ID6oW12NV8zNNk4gLxh9vUsZgaJRzg0+SavTrPx25jAVCfdNOBQhkcRnmiRf dnWNaj8ImbaMvBBF6TEVjj0iyeBtdsoDZFiwUAhGYkNmfktuR1d2kyqh5P0dVbX591uHjR 5naVwRvfjnnN0xBGDUStS8tRULEQCjLMRIv8RmOa7QIkMkq1F3VC0Uc2oHS0ug== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4fmfYB1Jzsz10Vx for ; Thu, 02 Apr 2026 11:20:46 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 1e259 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Thu, 02 Apr 2026 11:20:46 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Dag-Erling=?utf-8?Q? Sm=C3=B8rg?=rav Subject: git: cb991fa12e6e - stable/14 - tzcode: Add a test case for plain issetugid case List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: des X-Git-Repository: src X-Git-Refname: refs/heads/stable/14 X-Git-Reftype: branch X-Git-Commit: cb991fa12e6e22e9d6d50980ad52c4ca92c3649e Auto-Submitted: auto-generated Date: Thu, 02 Apr 2026 11:20:46 +0000 Message-Id: <69ce510e.1e259.30409fae@gitrepo.freebsd.org> The branch stable/14 has been updated by des: URL: https://cgit.FreeBSD.org/src/commit/?id=cb991fa12e6e22e9d6d50980ad52c4ca92c3649e commit cb991fa12e6e22e9d6d50980ad52c4ca92c3649e Author: Dag-Erling Smørgrav AuthorDate: 2025-09-01 06:33:37 +0000 Commit: Dag-Erling Smørgrav CommitDate: 2026-04-02 11:16:00 +0000 tzcode: Add a test case for plain issetugid case This catches a bug in tzcode which incorrectly considers TZDEFAULT as unsafe as if it came from the environment. Also deduplicate some repeated code, and fix a missing mode in an open(2) call with O_CREAT set. Event: Oslo Hackathon 202508 Reviewed by: philip Differential Revision: https://reviews.freebsd.org/D52241 (cherry picked from commit 016d3ec239b39895cf19aa62552fc316d7d98045) --- lib/libc/tests/stdtime/detect_tz_changes_test.c | 60 ++++++++++++++++++------- 1 file changed, 43 insertions(+), 17 deletions(-) diff --git a/lib/libc/tests/stdtime/detect_tz_changes_test.c b/lib/libc/tests/stdtime/detect_tz_changes_test.c index ad8c4818669d..6648d8498cc5 100644 --- a/lib/libc/tests/stdtime/detect_tz_changes_test.c +++ b/lib/libc/tests/stdtime/detect_tz_changes_test.c @@ -70,7 +70,7 @@ change_tz(const char *tzn) ATF_REQUIRE((zfd = open(zfn, O_DIRECTORY | O_SEARCH)) >= 0); ATF_REQUIRE((sfd = openat(zfd, tzn, O_RDONLY)) >= 0); - ATF_REQUIRE((dfd = open(tfn, O_CREAT | O_TRUNC | O_WRONLY)) >= 0); + ATF_REQUIRE((dfd = open(tfn, O_CREAT | O_TRUNC | O_WRONLY, 0644)) >= 0); do { clen = copy_file_range(sfd, NULL, dfd, NULL, SSIZE_MAX, 0); ATF_REQUIRE_MSG(clen != -1, "failed to copy %s/%s: %m", @@ -83,6 +83,19 @@ change_tz(const char *tzn) debug("time zone %s installed", tzn); } +static void +test_tz(const char *expect) +{ + char buf[128]; + struct tm *tm; + size_t len; + + ATF_REQUIRE((tm = localtime(&then)) != NULL); + len = strftime(buf, sizeof(buf), "%z (%Z)", tm); + ATF_REQUIRE(len > 0); + ATF_CHECK_STREQ(expect, buf); +} + ATF_TC(thin_jail); ATF_TC_HEAD(thin_jail, tc) { @@ -92,9 +105,6 @@ ATF_TC_HEAD(thin_jail, tc) ATF_TC_BODY(thin_jail, tc) { const struct tzcase *tzcase = tzcases; - char buf[128]; - struct tm *tm; - size_t len; /* prepare chroot */ ATF_REQUIRE_EQ(0, mkdir("root", 0755)); @@ -105,10 +115,7 @@ ATF_TC_BODY(thin_jail, tc) ATF_REQUIRE_EQ(0, chdir("/")); /* check timezone */ unsetenv("TZ"); - ATF_REQUIRE((tm = localtime(&then)) != NULL); - len = strftime(buf, sizeof(buf), "%z (%Z)", tm); - ATF_REQUIRE(len > 0); - ATF_CHECK_STREQ(tzcase->expect, buf); + test_tz(tzcase->expect); } #ifdef DETECT_TZ_CHANGES @@ -309,15 +316,8 @@ ATF_TC_BODY(detect_tz_changes, tc) static void test_tz_env(const char *tzval, const char *expect) { - char buf[128]; - struct tm *tm; - size_t len; - setenv("TZ", tzval, 1); - ATF_REQUIRE((tm = localtime(&then)) != NULL); - len = strftime(buf, sizeof(buf), "%z (%Z)", tm); - ATF_REQUIRE(len > 0); - ATF_CHECK_STREQ(expect, buf); + test_tz(expect); } ATF_TC(tz_env); @@ -333,6 +333,31 @@ ATF_TC_BODY(tz_env, tc) test_tz_env(tzcase->tzfn, tzcase->expect); } +ATF_TC(setugid); +ATF_TC_HEAD(setugid, tc) +{ + atf_tc_set_md_var(tc, "descr", "Test setugid process"); + atf_tc_set_md_var(tc, "require.user", "root"); +} +ATF_TC_BODY(setugid, tc) +{ + const struct tzcase *tzcase = tzcases; + + /* prepare chroot */ + ATF_REQUIRE_EQ(0, mkdir("root", 0755)); + ATF_REQUIRE_EQ(0, mkdir("root/etc", 0755)); + change_tz(tzcase->tzfn); + /* enter chroot */ + ATF_REQUIRE_EQ(0, chroot("root")); + ATF_REQUIRE_EQ(0, chdir("/")); + /* become setugid */ + ATF_REQUIRE_EQ(0, seteuid(UID_NOBODY)); + ATF_REQUIRE(issetugid()); + /* check timezone */ + unsetenv("TZ"); + test_tz(tzcases->expect); +} + ATF_TC(tz_env_setugid); ATF_TC_HEAD(tz_env_setugid, tc) { @@ -342,7 +367,7 @@ ATF_TC_HEAD(tz_env_setugid, tc) } ATF_TC_BODY(tz_env_setugid, tc) { - const struct tzcase *tzcase; + const struct tzcase *tzcase = tzcases; ATF_REQUIRE_EQ(0, seteuid(UID_NOBODY)); ATF_REQUIRE(issetugid()); @@ -359,6 +384,7 @@ ATF_TP_ADD_TCS(tp) ATF_TP_ADD_TC(tp, detect_tz_changes); #endif /* DETECT_TZ_CHANGES */ ATF_TP_ADD_TC(tp, tz_env); + ATF_TP_ADD_TC(tp, setugid); ATF_TP_ADD_TC(tp, tz_env_setugid); return (atf_no_error()); }