test: Finit against a real dbus-daemon

The other dbus-*.sh tests drive libink's own client, so the wire format
was only ever checked against the implementation that wrote it, and the
broker path had no coverage at all.  Every bug found in it so far was
found by hand on a target.

Let the dbus plugin bring up a real dbus-daemon, wait for Finit to
claim org.finit, then talk to Finit with dbus-send, which shares no
code with us.  The privileged call is the interesting one: it can only
be answered by parking the call and asking the broker who sent it.
The bus reads the policy Finit installs, so a malformed org.finit.conf
fails here rather than on a target.

Tests no longer build --with-libsystemd.  Our replacement carries the
real soname but only the sd_notify() symbols, so in the test root it
shadowed the libsystemd the host's libdbus-1 wants and dbus-daemon
died on a missing sd_is_socket.  Nothing under test needs the shared
library: serv is the only consumer and it compiles sd-daemon.c
straight in, which it now does regardless of the flag so notify.sh
keeps testing notify:systemd either way.

Staged from the host by lib/sysroot.mk like any other binary, and
skipped when the host has neither program.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
Joachim Wiberg
2026-08-13 10:15:19 +02:00
parent 2e0b1d6f8b
commit 127049d925
8 changed files with 125 additions and 8 deletions
+1 -1
View File
@@ -52,7 +52,7 @@ jobs:
run: |
./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc --localstatedir=/var \
--enable-x11-common-plugin --enable-testserv-plugin --with-watchdog \
--with-keventd --with-libsystemd \
--with-keventd \
CFLAGS="-fsanitize=address -ggdb"
make -j9 clean
make -j9 V=1
+6
View File
@@ -10,6 +10,7 @@ EXTRA_DIST = skel/bin/busybox-x86_64.sha256 skel/sbin/service.sh skel/etc/env
skel/etc/rcS.d/S01abc.sh skel/etc/rcS.d/S02def.sh \
skel/cdrom/.empty skel/dev/shm/.empty skel/dev/pts/.empty \
skel/etc/inittab skel/etc/hostname skel/etc/fstab \
skel/usr/share/dbus-1/system.conf skel/etc/machine-id \
skel/etc/passwd skel/etc/group skel/etc/ld.so.conf \
skel/etc/init.d/rcS skel/etc/init.d/rcK skel/tmp/.empty \
skel/etc/finit.d/.empty skel/etc/finit.d/available/.empty \
@@ -73,6 +74,7 @@ EXTRA_DIST += testserv.sh
EXTRA_DIST += unexpected-restart.sh
EXTRA_DIST += dbus-auth.sh
EXTRA_DIST += dbus-authz.sh
EXTRA_DIST += dbus-broker.sh
EXTRA_DIST += dbus-bus.sh
EXTRA_DIST += dbus-manager.sh
EXTRA_DIST += dbus-service.sh
@@ -143,6 +145,10 @@ TESTS += dbus-service.sh
TESTS += dbus-cond.sh
TESTS += dbus-initctl.sh
TESTS += dbus-introspect.sh
# Needs the plugin to bring up the bus, not just the built-in one
if BUILD_DBUS_PLUGIN
TESTS += dbus-broker.sh
endif
endif
check-recursive: setup-chroot
+1 -1
View File
@@ -26,7 +26,7 @@ fi
./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc --localstatedir=/var \
--enable-dbus --enable-x11-common-plugin --enable-testserv-plugin \
--with-watchdog --with-keventd --with-libsystemd \
--with-watchdog --with-keventd \
CFLAGS='-fsanitize=address -ggdb'
if [ "$run_make" -eq 1 ]; then
+61
View File
@@ -0,0 +1,61 @@
#!/bin/sh
# Finit against a real message bus.
#
# Every other dbus-*.sh test drives libink's own client, so the wire
# format is only ever checked against the implementation that produced
# it. Here the dbus plugin brings up a real dbus-daemon, Finit finds
# it and claims org.finit, and then dbus-send talks to Finit: a client
# that shares no code with us.
#
# It also covers the only path the brokerless bus cannot reach, where
# one connection carries every caller and Finit has to ask the broker
# who sent each privileged call.
#
# Skipped when the host has no dbus-daemon or dbus-send to stage.
set -eu
TEST_DIR=$(dirname "$0")
# shellcheck source=/dev/null
. "$TEST_DIR/lib/setup.sh"
# Staged by lib/sysroot.mk from the host, when it has them.
for prog in dbus-daemon dbus-send; do
texec sh -c "command -v $prog >/dev/null" \
|| skip "no $prog in the test root, need it on the host"
done
say 'The dbus plugin started a system bus'
retry 'assert_file_exists /var/run/dbus/system_bus_socket'
say 'Finit claims org.finit on the system bus'
retry "texec dbus-send --system --print-reply --dest=org.freedesktop.DBus \
/org/freedesktop/DBus org.freedesktop.DBus.GetNameOwner string:org.finit" 60 0.5
say 'A read-only method answers through the broker'
list=$(texec dbus-send --system --print-reply --dest=org.finit \
/org/finit/manager org.finit.Manager1.ListServices)
assert "ListServices returned the dbus service" \
"$(printf '%s' "$list" | grep -c '"dbus"')" -ge 1
say 'Properties.Get answers through the broker'
rl=$(texec dbus-send --system --print-reply --dest=org.finit \
/org/finit/manager org.freedesktop.DBus.Properties.Get \
string:org.finit.Manager1 string:Runlevel)
assert "Runlevel property is 2" "$(printf '%s' "$rl" | grep -c '"2"')" -eq 1
# The point of the exercise: a privileged call over the broker means
# Finit parks it, asks the driver who the sender is, and dispatches on
# the answer. Root is allowed, so reaching NoSuchService proves the
# whole round trip worked rather than a blanket denial. The repeat
# call goes the same way, only answered from the sender cache.
for pass in first repeat; do
say "A privileged method resolves the caller, $pass call"
priv=$(texec dbus-send --system --print-reply --dest=org.finit \
/org/finit/manager org.finit.Manager1.Restart string:nosuchservice 2>&1 || true)
case "$priv" in
*NoSuchService*) assert "Caller identified on the $pass call" 0 -eq 0 ;;
*) fail "Unexpected reply to the $pass privileged call: $priv" ;;
esac
done
+15 -3
View File
@@ -36,11 +36,23 @@ BBURL ?= $(BBHOME)/$(BBVER)/$(BBBIN)
# glibc dlopen()s NSS modules at runtime, so ldd does not list them, but
# without libnss_files getpwnam() cannot resolve users inside the chroot
_libs_nss = $(firstword $(wildcard /lib/$(ARCH)-linux-gnu/libnss_files.so.2 \
_libs_nss := $(firstword $(wildcard /lib/$(ARCH)-linux-gnu/libnss_files.so.2 \
/usr/lib/$(ARCH)-linux-gnu/libnss_files.so.2 \
/lib64/libnss_files.so.2 /lib/libnss_files.so.2))
_libs_src = $(shell ldd $(FINITBIN) | grep -Eo '/[^ ]+') $(_libs_nss)
libs = $(foreach path,$(_libs_src),$(abspath $(DEST))$(path))
# A real broker and a real client, staged when the host has them, so
# one test can check Finit against dbus-daemon instead of only against
# libink's own client. Absent is fine, dbus-broker.sh skips.
dbus_bins := $(foreach b,dbus-daemon dbus-send,$(firstword $(wildcard /usr/bin/$(b) /bin/$(b))))
# Given several binaries ldd prefixes each with a 'path:' header, and
# that trailing colon would land in a make target. Excluding it here
# is enough, no need for one ldd per binary.
_libs_dbus := $(if $(dbus_bins),$(shell ldd $(dbus_bins) | grep -Eo '/[^ :]+'))
# The binaries stage exactly like the libraries: same host path, same
# path under DEST, copied by the rule below.
_libs_src := $(shell ldd $(FINITBIN) | grep -Eo '/[^ ]+') $(_libs_nss) \
$(_libs_dbus) $(dbus_bins)
libs := $(foreach path,$(sort $(_libs_src)),$(abspath $(DEST))$(path))
all: $(libs) $(DEST)/bin/$(BBBIN)
@(cd $(DEST); \
+1
View File
@@ -0,0 +1 @@
0123456789abcdef0123456789abcdef
+36
View File
@@ -0,0 +1,36 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE busconfig PUBLIC
"-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN"
"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
<!--
The system bus configuration for the test namespace, deliberately
permissive. It lives where a stock system bus daemon looks for its
configuration, so the dbus plugin's own invocation finds it.
What is under test is Finit attaching to a broker and serving calls
routed through it, not dbus policy, so nothing here should be able
to refuse a message and make a Finit bug look like a policy denial.
Everything runs as root inside the namespace, hence no <user>.
-->
<busconfig>
<type>system</type>
<!-- Pick up the policy Finit itself ships, so a malformed
org.finit.conf fails the test rather than a target. -->
<includedir>/etc/dbus-1/system.d</includedir>
<listen>unix:path=/var/run/dbus/system_bus_socket</listen>
<auth>EXTERNAL</auth>
<policy context="default">
<allow user="*"/>
<allow own="*"/>
<allow send_type="method_call"/>
<allow send_type="signal"/>
<allow send_type="method_return"/>
<allow send_type="error"/>
<allow receive_type="method_call"/>
<allow receive_type="signal"/>
<allow receive_type="method_return"/>
<allow receive_type="error"/>
</policy>
</busconfig>
+4 -3
View File
@@ -2,11 +2,12 @@ noinst_PROGRAMS = serv
serv_SOURCES = serv.c
serv_CPPFLAGS = -D_XOPEN_SOURCE=600 -D_BSD_SOURCE -D_GNU_SOURCE -D_DEFAULT_SOURCE -I$(top_builddir)
if LIBSYSTEMD
serv_CPPFLAGS += -I$(top_srcdir)/libsystemd $(lite_CFLAGS)
# serv is what notify.sh drives to test notify:systemd, so it always
# needs sd_notify(). The source is in-tree and it links straight in,
# unrelated to whether --with-libsystemd installs the shared library.
serv_CPPFLAGS += -DHAVE_LIBSYSTEMD=1 -I$(top_srcdir)/libsystemd $(lite_CFLAGS)
serv_SOURCES += $(top_srcdir)/libsystemd/sd-daemon.c
serv_LDADD = $(lite_LIBS)
endif
if DBUS
noinst_PROGRAMS += dbus-auth-client