2 # SPDX-License-Identifier: GPL-2.0
3 # Copyright 2018 Google LLC
5 # FS QA Test generic/572
7 # This is a basic fs-verity test which verifies:
9 # - conditions for enabling verity
10 # - verity files have correct contents and size
11 # - can't change contents of verity files, but can change metadata
12 # - can retrieve a verity file's measurement via FS_IOC_MEASURE_VERITY
15 _begin_fstest auto quick verity
17 # Override the default cleanup function.
21 _restore_fsverity_signatures
25 # Import common functions.
29 # real QA test starts here
31 _require_scratch_verity
32 _disable_fsverity_signatures
34 _scratch_mkfs_verity &>> $seqres.full
36 fsv_orig_file=$SCRATCH_MNT/file
37 fsv_file=$SCRATCH_MNT/file.fsv
39 verify_data_readable()
43 md5sum $file > /dev/null
46 verify_data_unreadable()
50 # try both reading just the first data block, and reading until EOF
51 head -c $FSV_BLOCK_SIZE $file 2>&1 >/dev/null | _filter_scratch
52 md5sum $file |& _filter_scratch
55 _fsv_scratch_begin_subtest "Enabling verity on file with verity already enabled fails with EEXIST"
56 _fsv_create_enable_file $fsv_file
58 _fsv_enable $fsv_file |& _filter_scratch
60 _fsv_scratch_begin_subtest "Enabling verity with invalid hash algorithm fails with EINVAL"
61 _fsv_create_enable_file $fsv_file --hash-alg=257 |& _filter_scratch
62 verify_data_readable $fsv_file
64 _fsv_scratch_begin_subtest "Enabling verity with invalid block size fails with EINVAL"
65 _fsv_create_enable_file $fsv_file --block-size=1 |& _filter_scratch
66 verify_data_readable $fsv_file
68 _fsv_scratch_begin_subtest "Enabling verity on directory fails with EISDIR"
69 mkdir $SCRATCH_MNT/dir
70 _fsv_enable $SCRATCH_MNT/dir |& _filter_scratch
72 _fsv_scratch_begin_subtest "Enabling verity with too-long salt fails with EMSGSIZE"
73 _fsv_create_enable_file $fsv_file --salt=$(perl -e 'print "A" x 1000') |& _filter_scratch
74 verify_data_readable $fsv_file
76 _fsv_scratch_begin_subtest "Enabling verity on file on read-only filesystem fails with EROFS"
79 _fsv_enable $fsv_file |& _filter_scratch
82 _fsv_scratch_begin_subtest "Enabling verity on file open for writing fails with ETXTBSY"
85 _fsv_enable $fsv_file |& _filter_scratch
87 verify_data_readable $fsv_file
89 _fsv_scratch_begin_subtest "Enabling verity can be interrupted"
90 dd if=/dev/zero of=$fsv_file bs=1 count=0 seek=$((1 << 34)) status=none
91 start_time=$(date +%s)
92 $FSVERITY_PROG enable $fsv_file &
96 elapsed=$(( $(date +%s) - start_time ))
97 if (( elapsed > 5 )); then
98 echo "Failed to interrupt FS_IOC_ENABLE_VERITY ($elapsed seconds elapsed)"
101 _fsv_scratch_begin_subtest "Enabling verity on file with verity already being enabled fails with EBUSY"
102 dd if=/dev/zero of=$fsv_file bs=1 count=0 seek=$((1 << 34)) status=none
103 start_time=$(date +%s)
104 $FSVERITY_PROG enable $fsv_file &
106 _fsv_enable $fsv_file |& _filter_scratch
110 _fsv_scratch_begin_subtest "verity file can't be opened for writing"
111 _fsv_create_enable_file $fsv_file >> $seqres.full
113 $XFS_IO_PROG -r $fsv_file -c ''
114 echo "* xfs_io writing, should be O_RDWR"
115 $XFS_IO_PROG $fsv_file -c '' |& _filter_scratch
116 echo "* bash >>, should be O_APPEND"
117 bash -c "echo >> $fsv_file" |& _filter_scratch
118 echo "* bash >, should be O_WRONLY|O_CREAT|O_TRUNC"
119 bash -c "echo > $fsv_file" |& _filter_scratch
121 _fsv_scratch_begin_subtest "verity file can be read"
122 _fsv_create_enable_file $fsv_file >> $seqres.full
123 verify_data_readable $fsv_file
125 _fsv_scratch_begin_subtest "verity file can be measured"
126 _fsv_create_enable_file $fsv_file >> $seqres.full
127 _fsv_measure $fsv_file
129 _fsv_scratch_begin_subtest "verity file can be renamed"
130 _fsv_create_enable_file $fsv_file
131 mv $fsv_file $fsv_file.newname
133 _fsv_scratch_begin_subtest "verity file can be unlinked"
134 _fsv_create_enable_file $fsv_file
137 _fsv_scratch_begin_subtest "verity file can be linked to"
138 _fsv_create_enable_file $fsv_file
139 ln $fsv_file $fsv_file.newname
141 _fsv_scratch_begin_subtest "verity file can be chmodded"
142 _fsv_create_enable_file $fsv_file
146 _fsv_scratch_begin_subtest "verity file can be chowned"
147 _fsv_create_enable_file $fsv_file
151 _fsv_scratch_begin_subtest "verity file has correct contents and size"
152 head -c 100000 /dev/urandom > $fsv_orig_file
153 cp $fsv_orig_file $fsv_file
154 _fsv_enable $fsv_file >> $seqres.full
155 cmp $fsv_file $fsv_orig_file
156 _get_filesize $fsv_file
158 cmp $fsv_file $fsv_orig_file
159 _get_filesize $fsv_file
161 _fsv_scratch_begin_subtest "Trying to measure non-verity file fails with ENODATA"
163 _fsv_measure $fsv_file |& _filter_scratch
164 verify_data_readable $fsv_file
166 # Test files <= 1 block in size. These are a bit of a special case since there
167 # are no hash blocks; the root hash is calculated directly over the data block.
168 for size in 1 $((FSV_BLOCK_SIZE - 1)) $FSV_BLOCK_SIZE; do
169 _fsv_scratch_begin_subtest "verity on $size-byte file"
170 head -c $size /dev/urandom > $fsv_orig_file
171 cp $fsv_orig_file $fsv_file
172 _fsv_enable $fsv_file
173 cmp $fsv_orig_file $fsv_file && echo "Files matched"
177 _fsv_scratch_begin_subtest "verity on 100M file (multiple levels in hash tree)"
178 head -c 100000000 /dev/urandom > $fsv_orig_file
179 cp $fsv_orig_file $fsv_file
180 _fsv_enable $fsv_file
181 cmp $fsv_orig_file $fsv_file && echo "Files matched"
183 _fsv_scratch_begin_subtest "verity on sparse file"
184 dd if=/dev/zero of=$fsv_orig_file bs=1 count=1 seek=1000000 status=none
185 cp $fsv_orig_file $fsv_file
186 _fsv_enable $fsv_file
187 cmp $fsv_orig_file $fsv_file && echo "Files matched"