selftests/landlock: Check full ioctl commands in audit records
The ioctl audit test uses FIONREAD, whose command value fits in 16 bits.
It therefore cannot detect truncation of encoded direction and size
bits.
Use an architecture-independent unknown command with set upper bits and
require its complete value in the audit record. Landlock rejects the
command before the device handles it, and the existing ioctl enforcement
test already exercises the same request. The new expectation fails with
ioctlcmd=0xfeee on an unfixed kernel and passes with ioctlcmd=0xc00ffeee
after the shared audit field is widened.
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Reviewed-by: Günther Noack <gnoack@google.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
1 file changed