xref: /freebsd-12.1/tests/sys/kern/ptrace_test.c (revision 80311a9e)
1 /*-
2  * Copyright (c) 2015 John Baldwin <[email protected]>
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  *
14  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
15  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
18  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
19  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
20  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
22  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
23  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
24  * SUCH DAMAGE.
25  */
26 
27 #include <sys/cdefs.h>
28 __FBSDID("$FreeBSD$");
29 
30 #include <sys/types.h>
31 #include <sys/cpuset.h>
32 #include <sys/event.h>
33 #include <sys/file.h>
34 #include <sys/time.h>
35 #include <sys/procctl.h>
36 #define	_WANT_MIPS_REGNUM
37 #include <sys/procdesc.h>
38 #include <sys/ptrace.h>
39 #include <sys/queue.h>
40 #include <sys/runq.h>
41 #include <sys/syscall.h>
42 #include <sys/sysctl.h>
43 #include <sys/user.h>
44 #include <sys/wait.h>
45 #include <errno.h>
46 #include <machine/cpufunc.h>
47 #include <pthread.h>
48 #include <sched.h>
49 #include <semaphore.h>
50 #include <signal.h>
51 #include <stdio.h>
52 #include <stdlib.h>
53 #include <unistd.h>
54 #include <atf-c.h>
55 
56 /*
57  * Architectures with a user-visible breakpoint().
58  */
59 #if defined(__aarch64__) || defined(__amd64__) || defined(__arm__) ||	\
60     defined(__i386__) || defined(__mips__) || defined(__riscv) ||	\
61     defined(__sparc64__)
62 #define	HAVE_BREAKPOINT
63 #endif
64 
65 /*
66  * Adjust PC to skip over a breakpoint when stopped for a breakpoint trap.
67  */
68 #ifdef HAVE_BREAKPOINT
69 #if defined(__aarch64__)
70 #define	SKIP_BREAK(reg)	((reg)->elr += 4)
71 #elif defined(__amd64__) || defined(__i386__)
72 #define	SKIP_BREAK(reg)
73 #elif defined(__arm__)
74 #define	SKIP_BREAK(reg)	((reg)->r_pc += 4)
75 #elif defined(__mips__)
76 #define	SKIP_BREAK(reg)	((reg)->r_regs[PC] += 4)
77 #elif defined(__riscv)
78 #define	SKIP_BREAK(reg)	((reg)->sepc += 4)
79 #elif defined(__sparc64__)
80 #define	SKIP_BREAK(reg)	do {						\
81 	(reg)->r_tpc = (reg)->r_tnpc + 4;				\
82 	(reg)->r_tnpc += 8;						\
83 } while (0)
84 #endif
85 #endif
86 
87 /*
88  * A variant of ATF_REQUIRE that is suitable for use in child
89  * processes.  This only works if the parent process is tripped up by
90  * the early exit and fails some requirement itself.
91  */
92 #define	CHILD_REQUIRE(exp) do {						\
93 		if (!(exp))						\
94 			child_fail_require(__FILE__, __LINE__,		\
95 			    #exp " not met");				\
96 	} while (0)
97 
98 static __dead2 void
child_fail_require(const char * file,int line,const char * str)99 child_fail_require(const char *file, int line, const char *str)
100 {
101 	char buf[128];
102 
103 	snprintf(buf, sizeof(buf), "%s:%d: %s\n", file, line, str);
104 	write(2, buf, strlen(buf));
105 	_exit(32);
106 }
107 
108 static void
trace_me(void)109 trace_me(void)
110 {
111 
112 	/* Attach the parent process as a tracer of this process. */
113 	CHILD_REQUIRE(ptrace(PT_TRACE_ME, 0, NULL, 0) != -1);
114 
115 	/* Trigger a stop. */
116 	raise(SIGSTOP);
117 }
118 
119 static void
attach_child(pid_t pid)120 attach_child(pid_t pid)
121 {
122 	pid_t wpid;
123 	int status;
124 
125 	ATF_REQUIRE(ptrace(PT_ATTACH, pid, NULL, 0) == 0);
126 
127 	wpid = waitpid(pid, &status, 0);
128 	ATF_REQUIRE(wpid == pid);
129 	ATF_REQUIRE(WIFSTOPPED(status));
130 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
131 }
132 
133 static void
wait_for_zombie(pid_t pid)134 wait_for_zombie(pid_t pid)
135 {
136 
137 	/*
138 	 * Wait for a process to exit.  This is kind of gross, but
139 	 * there is not a better way.
140 	 *
141 	 * Prior to r325719, the kern.proc.pid.<pid> sysctl failed
142 	 * with ESRCH.  After that change, a valid struct kinfo_proc
143 	 * is returned for zombies with ki_stat set to SZOMB.
144 	 */
145 	for (;;) {
146 		struct kinfo_proc kp;
147 		size_t len;
148 		int mib[4];
149 
150 		mib[0] = CTL_KERN;
151 		mib[1] = KERN_PROC;
152 		mib[2] = KERN_PROC_PID;
153 		mib[3] = pid;
154 		len = sizeof(kp);
155 		if (sysctl(mib, nitems(mib), &kp, &len, NULL, 0) == -1) {
156 			ATF_REQUIRE(errno == ESRCH);
157 			break;
158 		}
159 		if (kp.ki_stat == SZOMB)
160 			break;
161 		usleep(5000);
162 	}
163 }
164 
165 /*
166  * Verify that a parent debugger process "sees" the exit of a debugged
167  * process exactly once when attached via PT_TRACE_ME.
168  */
169 ATF_TC_WITHOUT_HEAD(ptrace__parent_wait_after_trace_me);
ATF_TC_BODY(ptrace__parent_wait_after_trace_me,tc)170 ATF_TC_BODY(ptrace__parent_wait_after_trace_me, tc)
171 {
172 	pid_t child, wpid;
173 	int status;
174 
175 	ATF_REQUIRE((child = fork()) != -1);
176 	if (child == 0) {
177 		/* Child process. */
178 		trace_me();
179 
180 		_exit(1);
181 	}
182 
183 	/* Parent process. */
184 
185 	/* The first wait() should report the stop from SIGSTOP. */
186 	wpid = waitpid(child, &status, 0);
187 	ATF_REQUIRE(wpid == child);
188 	ATF_REQUIRE(WIFSTOPPED(status));
189 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
190 
191 	/* Continue the child ignoring the SIGSTOP. */
192 	ATF_REQUIRE(ptrace(PT_CONTINUE, child, (caddr_t)1, 0) != -1);
193 
194 	/* The second wait() should report the exit status. */
195 	wpid = waitpid(child, &status, 0);
196 	ATF_REQUIRE(wpid == child);
197 	ATF_REQUIRE(WIFEXITED(status));
198 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
199 
200 	/* The child should no longer exist. */
201 	wpid = waitpid(child, &status, 0);
202 	ATF_REQUIRE(wpid == -1);
203 	ATF_REQUIRE(errno == ECHILD);
204 }
205 
206 /*
207  * Verify that a parent debugger process "sees" the exit of a debugged
208  * process exactly once when attached via PT_ATTACH.
209  */
210 ATF_TC_WITHOUT_HEAD(ptrace__parent_wait_after_attach);
ATF_TC_BODY(ptrace__parent_wait_after_attach,tc)211 ATF_TC_BODY(ptrace__parent_wait_after_attach, tc)
212 {
213 	pid_t child, wpid;
214 	int cpipe[2], status;
215 	char c;
216 
217 	ATF_REQUIRE(pipe(cpipe) == 0);
218 	ATF_REQUIRE((child = fork()) != -1);
219 	if (child == 0) {
220 		/* Child process. */
221 		close(cpipe[0]);
222 
223 		/* Wait for the parent to attach. */
224 		CHILD_REQUIRE(read(cpipe[1], &c, sizeof(c)) == 0);
225 
226 		_exit(1);
227 	}
228 	close(cpipe[1]);
229 
230 	/* Parent process. */
231 
232 	/* Attach to the child process. */
233 	attach_child(child);
234 
235 	/* Continue the child ignoring the SIGSTOP. */
236 	ATF_REQUIRE(ptrace(PT_CONTINUE, child, (caddr_t)1, 0) != -1);
237 
238 	/* Signal the child to exit. */
239 	close(cpipe[0]);
240 
241 	/* The second wait() should report the exit status. */
242 	wpid = waitpid(child, &status, 0);
243 	ATF_REQUIRE(wpid == child);
244 	ATF_REQUIRE(WIFEXITED(status));
245 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
246 
247 	/* The child should no longer exist. */
248 	wpid = waitpid(child, &status, 0);
249 	ATF_REQUIRE(wpid == -1);
250 	ATF_REQUIRE(errno == ECHILD);
251 }
252 
253 /*
254  * Verify that a parent process "sees" the exit of a debugged process only
255  * after the debugger has seen it.
256  */
257 ATF_TC_WITHOUT_HEAD(ptrace__parent_sees_exit_after_child_debugger);
ATF_TC_BODY(ptrace__parent_sees_exit_after_child_debugger,tc)258 ATF_TC_BODY(ptrace__parent_sees_exit_after_child_debugger, tc)
259 {
260 	pid_t child, debugger, wpid;
261 	int cpipe[2], dpipe[2], status;
262 	char c;
263 
264 	ATF_REQUIRE(pipe(cpipe) == 0);
265 	ATF_REQUIRE((child = fork()) != -1);
266 
267 	if (child == 0) {
268 		/* Child process. */
269 		close(cpipe[0]);
270 
271 		/* Wait for parent to be ready. */
272 		CHILD_REQUIRE(read(cpipe[1], &c, sizeof(c)) == sizeof(c));
273 
274 		_exit(1);
275 	}
276 	close(cpipe[1]);
277 
278 	ATF_REQUIRE(pipe(dpipe) == 0);
279 	ATF_REQUIRE((debugger = fork()) != -1);
280 
281 	if (debugger == 0) {
282 		/* Debugger process. */
283 		close(dpipe[0]);
284 
285 		CHILD_REQUIRE(ptrace(PT_ATTACH, child, NULL, 0) != -1);
286 
287 		wpid = waitpid(child, &status, 0);
288 		CHILD_REQUIRE(wpid == child);
289 		CHILD_REQUIRE(WIFSTOPPED(status));
290 		CHILD_REQUIRE(WSTOPSIG(status) == SIGSTOP);
291 
292 		CHILD_REQUIRE(ptrace(PT_CONTINUE, child, (caddr_t)1, 0) != -1);
293 
294 		/* Signal parent that debugger is attached. */
295 		CHILD_REQUIRE(write(dpipe[1], &c, sizeof(c)) == sizeof(c));
296 
297 		/* Wait for parent's failed wait. */
298 		CHILD_REQUIRE(read(dpipe[1], &c, sizeof(c)) == 0);
299 
300 		wpid = waitpid(child, &status, 0);
301 		CHILD_REQUIRE(wpid == child);
302 		CHILD_REQUIRE(WIFEXITED(status));
303 		CHILD_REQUIRE(WEXITSTATUS(status) == 1);
304 
305 		_exit(0);
306 	}
307 	close(dpipe[1]);
308 
309 	/* Parent process. */
310 
311 	/* Wait for the debugger to attach to the child. */
312 	ATF_REQUIRE(read(dpipe[0], &c, sizeof(c)) == sizeof(c));
313 
314 	/* Release the child. */
315 	ATF_REQUIRE(write(cpipe[0], &c, sizeof(c)) == sizeof(c));
316 	ATF_REQUIRE(read(cpipe[0], &c, sizeof(c)) == 0);
317 	close(cpipe[0]);
318 
319 	wait_for_zombie(child);
320 
321 	/*
322 	 * This wait should return a pid of 0 to indicate no status to
323 	 * report.  The parent should see the child as non-exited
324 	 * until the debugger sees the exit.
325 	 */
326 	wpid = waitpid(child, &status, WNOHANG);
327 	ATF_REQUIRE(wpid == 0);
328 
329 	/* Signal the debugger to wait for the child. */
330 	close(dpipe[0]);
331 
332 	/* Wait for the debugger. */
333 	wpid = waitpid(debugger, &status, 0);
334 	ATF_REQUIRE(wpid == debugger);
335 	ATF_REQUIRE(WIFEXITED(status));
336 	ATF_REQUIRE(WEXITSTATUS(status) == 0);
337 
338 	/* The child process should now be ready. */
339 	wpid = waitpid(child, &status, WNOHANG);
340 	ATF_REQUIRE(wpid == child);
341 	ATF_REQUIRE(WIFEXITED(status));
342 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
343 }
344 
345 /*
346  * Verify that a parent process "sees" the exit of a debugged process
347  * only after a non-direct-child debugger has seen it.  In particular,
348  * various wait() calls in the parent must avoid failing with ESRCH by
349  * checking the parent's orphan list for the debugee.
350  */
351 ATF_TC_WITHOUT_HEAD(ptrace__parent_sees_exit_after_unrelated_debugger);
ATF_TC_BODY(ptrace__parent_sees_exit_after_unrelated_debugger,tc)352 ATF_TC_BODY(ptrace__parent_sees_exit_after_unrelated_debugger, tc)
353 {
354 	pid_t child, debugger, fpid, wpid;
355 	int cpipe[2], dpipe[2], status;
356 	char c;
357 
358 	ATF_REQUIRE(pipe(cpipe) == 0);
359 	ATF_REQUIRE((child = fork()) != -1);
360 
361 	if (child == 0) {
362 		/* Child process. */
363 		close(cpipe[0]);
364 
365 		/* Wait for parent to be ready. */
366 		CHILD_REQUIRE(read(cpipe[1], &c, sizeof(c)) == sizeof(c));
367 
368 		_exit(1);
369 	}
370 	close(cpipe[1]);
371 
372 	ATF_REQUIRE(pipe(dpipe) == 0);
373 	ATF_REQUIRE((debugger = fork()) != -1);
374 
375 	if (debugger == 0) {
376 		/* Debugger parent. */
377 
378 		/*
379 		 * Fork again and drop the debugger parent so that the
380 		 * debugger is not a child of the main parent.
381 		 */
382 		CHILD_REQUIRE((fpid = fork()) != -1);
383 		if (fpid != 0)
384 			_exit(2);
385 
386 		/* Debugger process. */
387 		close(dpipe[0]);
388 
389 		CHILD_REQUIRE(ptrace(PT_ATTACH, child, NULL, 0) != -1);
390 
391 		wpid = waitpid(child, &status, 0);
392 		CHILD_REQUIRE(wpid == child);
393 		CHILD_REQUIRE(WIFSTOPPED(status));
394 		CHILD_REQUIRE(WSTOPSIG(status) == SIGSTOP);
395 
396 		CHILD_REQUIRE(ptrace(PT_CONTINUE, child, (caddr_t)1, 0) != -1);
397 
398 		/* Signal parent that debugger is attached. */
399 		CHILD_REQUIRE(write(dpipe[1], &c, sizeof(c)) == sizeof(c));
400 
401 		/* Wait for parent's failed wait. */
402 		CHILD_REQUIRE(read(dpipe[1], &c, sizeof(c)) == sizeof(c));
403 
404 		wpid = waitpid(child, &status, 0);
405 		CHILD_REQUIRE(wpid == child);
406 		CHILD_REQUIRE(WIFEXITED(status));
407 		CHILD_REQUIRE(WEXITSTATUS(status) == 1);
408 
409 		_exit(0);
410 	}
411 	close(dpipe[1]);
412 
413 	/* Parent process. */
414 
415 	/* Wait for the debugger parent process to exit. */
416 	wpid = waitpid(debugger, &status, 0);
417 	ATF_REQUIRE(wpid == debugger);
418 	ATF_REQUIRE(WIFEXITED(status));
419 	ATF_REQUIRE(WEXITSTATUS(status) == 2);
420 
421 	/* A WNOHANG wait here should see the non-exited child. */
422 	wpid = waitpid(child, &status, WNOHANG);
423 	ATF_REQUIRE(wpid == 0);
424 
425 	/* Wait for the debugger to attach to the child. */
426 	ATF_REQUIRE(read(dpipe[0], &c, sizeof(c)) == sizeof(c));
427 
428 	/* Release the child. */
429 	ATF_REQUIRE(write(cpipe[0], &c, sizeof(c)) == sizeof(c));
430 	ATF_REQUIRE(read(cpipe[0], &c, sizeof(c)) == 0);
431 	close(cpipe[0]);
432 
433 	wait_for_zombie(child);
434 
435 	/*
436 	 * This wait should return a pid of 0 to indicate no status to
437 	 * report.  The parent should see the child as non-exited
438 	 * until the debugger sees the exit.
439 	 */
440 	wpid = waitpid(child, &status, WNOHANG);
441 	ATF_REQUIRE(wpid == 0);
442 
443 	/* Signal the debugger to wait for the child. */
444 	ATF_REQUIRE(write(dpipe[0], &c, sizeof(c)) == sizeof(c));
445 
446 	/* Wait for the debugger. */
447 	ATF_REQUIRE(read(dpipe[0], &c, sizeof(c)) == 0);
448 	close(dpipe[0]);
449 
450 	/* The child process should now be ready. */
451 	wpid = waitpid(child, &status, WNOHANG);
452 	ATF_REQUIRE(wpid == child);
453 	ATF_REQUIRE(WIFEXITED(status));
454 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
455 }
456 
457 /*
458  * Make sure that we can collect the exit status of an orphaned process.
459  */
460 ATF_TC_WITHOUT_HEAD(ptrace__parent_exits_before_child);
ATF_TC_BODY(ptrace__parent_exits_before_child,tc)461 ATF_TC_BODY(ptrace__parent_exits_before_child, tc)
462 {
463 	ssize_t n;
464 	int cpipe1[2], cpipe2[2], gcpipe[2], status;
465 	pid_t child, gchild;
466 
467 	ATF_REQUIRE(pipe(cpipe1) == 0);
468 	ATF_REQUIRE(pipe(cpipe2) == 0);
469 	ATF_REQUIRE(pipe(gcpipe) == 0);
470 
471 	ATF_REQUIRE(procctl(P_PID, getpid(), PROC_REAP_ACQUIRE, NULL) == 0);
472 
473 	ATF_REQUIRE((child = fork()) != -1);
474 	if (child == 0) {
475 		CHILD_REQUIRE((gchild = fork()) != -1);
476 		if (gchild == 0) {
477 			status = 1;
478 			do {
479 				n = read(gcpipe[0], &status, sizeof(status));
480 			} while (n == -1 && errno == EINTR);
481 			_exit(status);
482 		}
483 
484 		CHILD_REQUIRE(write(cpipe1[1], &gchild, sizeof(gchild)) ==
485 		    sizeof(gchild));
486 		CHILD_REQUIRE(read(cpipe2[0], &status, sizeof(status)) ==
487 		    sizeof(status));
488 		_exit(status);
489 	}
490 
491 	ATF_REQUIRE(read(cpipe1[0], &gchild, sizeof(gchild)) == sizeof(gchild));
492 
493 	ATF_REQUIRE(ptrace(PT_ATTACH, gchild, NULL, 0) == 0);
494 
495 	status = 0;
496 	ATF_REQUIRE(write(cpipe2[1], &status, sizeof(status)) ==
497 	    sizeof(status));
498 	ATF_REQUIRE(waitpid(child, &status, 0) == child);
499 	ATF_REQUIRE(WIFEXITED(status) && WEXITSTATUS(status) == 0);
500 
501 	status = 0;
502 	ATF_REQUIRE(write(gcpipe[1], &status, sizeof(status)) ==
503 	    sizeof(status));
504 	ATF_REQUIRE(waitpid(gchild, &status, 0) == gchild);
505 	ATF_REQUIRE(WIFSTOPPED(status));
506 	ATF_REQUIRE(ptrace(PT_DETACH, gchild, (caddr_t)1, 0) == 0);
507 	ATF_REQUIRE(waitpid(gchild, &status, 0) == gchild);
508 	ATF_REQUIRE(WIFEXITED(status) && WEXITSTATUS(status) == 0);
509 
510 	ATF_REQUIRE(close(cpipe1[0]) == 0);
511 	ATF_REQUIRE(close(cpipe1[1]) == 0);
512 	ATF_REQUIRE(close(cpipe2[0]) == 0);
513 	ATF_REQUIRE(close(cpipe2[1]) == 0);
514 	ATF_REQUIRE(close(gcpipe[0]) == 0);
515 	ATF_REQUIRE(close(gcpipe[1]) == 0);
516 }
517 
518 /*
519  * The parent process should always act the same regardless of how the
520  * debugger is attached to it.
521  */
522 static __dead2 void
follow_fork_parent(bool use_vfork)523 follow_fork_parent(bool use_vfork)
524 {
525 	pid_t fpid, wpid;
526 	int status;
527 
528 	if (use_vfork)
529 		CHILD_REQUIRE((fpid = vfork()) != -1);
530 	else
531 		CHILD_REQUIRE((fpid = fork()) != -1);
532 
533 	if (fpid == 0)
534 		/* Child */
535 		_exit(2);
536 
537 	wpid = waitpid(fpid, &status, 0);
538 	CHILD_REQUIRE(wpid == fpid);
539 	CHILD_REQUIRE(WIFEXITED(status));
540 	CHILD_REQUIRE(WEXITSTATUS(status) == 2);
541 
542 	_exit(1);
543 }
544 
545 /*
546  * Helper routine for follow fork tests.  This waits for two stops
547  * that report both "sides" of a fork.  It returns the pid of the new
548  * child process.
549  */
550 static pid_t
handle_fork_events(pid_t parent,struct ptrace_lwpinfo * ppl)551 handle_fork_events(pid_t parent, struct ptrace_lwpinfo *ppl)
552 {
553 	struct ptrace_lwpinfo pl;
554 	bool fork_reported[2];
555 	pid_t child, wpid;
556 	int i, status;
557 
558 	fork_reported[0] = false;
559 	fork_reported[1] = false;
560 	child = -1;
561 
562 	/*
563 	 * Each process should report a fork event.  The parent should
564 	 * report a PL_FLAG_FORKED event, and the child should report
565 	 * a PL_FLAG_CHILD event.
566 	 */
567 	for (i = 0; i < 2; i++) {
568 		wpid = wait(&status);
569 		ATF_REQUIRE(wpid > 0);
570 		ATF_REQUIRE(WIFSTOPPED(status));
571 
572 		ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
573 		    sizeof(pl)) != -1);
574 		ATF_REQUIRE((pl.pl_flags & (PL_FLAG_FORKED | PL_FLAG_CHILD)) !=
575 		    0);
576 		ATF_REQUIRE((pl.pl_flags & (PL_FLAG_FORKED | PL_FLAG_CHILD)) !=
577 		    (PL_FLAG_FORKED | PL_FLAG_CHILD));
578 		if (pl.pl_flags & PL_FLAG_CHILD) {
579 			ATF_REQUIRE(wpid != parent);
580 			ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
581 			ATF_REQUIRE(!fork_reported[1]);
582 			if (child == -1)
583 				child = wpid;
584 			else
585 				ATF_REQUIRE(child == wpid);
586 			if (ppl != NULL)
587 				ppl[1] = pl;
588 			fork_reported[1] = true;
589 		} else {
590 			ATF_REQUIRE(wpid == parent);
591 			ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
592 			ATF_REQUIRE(!fork_reported[0]);
593 			if (child == -1)
594 				child = pl.pl_child_pid;
595 			else
596 				ATF_REQUIRE(child == pl.pl_child_pid);
597 			if (ppl != NULL)
598 				ppl[0] = pl;
599 			fork_reported[0] = true;
600 		}
601 	}
602 
603 	return (child);
604 }
605 
606 /*
607  * Verify that a new child process is stopped after a followed fork and
608  * that the traced parent sees the exit of the child after the debugger
609  * when both processes remain attached to the debugger.
610  */
611 ATF_TC_WITHOUT_HEAD(ptrace__follow_fork_both_attached);
ATF_TC_BODY(ptrace__follow_fork_both_attached,tc)612 ATF_TC_BODY(ptrace__follow_fork_both_attached, tc)
613 {
614 	pid_t children[2], fpid, wpid;
615 	int status;
616 
617 	ATF_REQUIRE((fpid = fork()) != -1);
618 	if (fpid == 0) {
619 		trace_me();
620 		follow_fork_parent(false);
621 	}
622 
623 	/* Parent process. */
624 	children[0] = fpid;
625 
626 	/* The first wait() should report the stop from SIGSTOP. */
627 	wpid = waitpid(children[0], &status, 0);
628 	ATF_REQUIRE(wpid == children[0]);
629 	ATF_REQUIRE(WIFSTOPPED(status));
630 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
631 
632 	ATF_REQUIRE(ptrace(PT_FOLLOW_FORK, children[0], NULL, 1) != -1);
633 
634 	/* Continue the child ignoring the SIGSTOP. */
635 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
636 
637 	children[1] = handle_fork_events(children[0], NULL);
638 	ATF_REQUIRE(children[1] > 0);
639 
640 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
641 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[1], (caddr_t)1, 0) != -1);
642 
643 	/*
644 	 * The child can't exit until the grandchild reports status, so the
645 	 * grandchild should report its exit first to the debugger.
646 	 */
647 	wpid = wait(&status);
648 	ATF_REQUIRE(wpid == children[1]);
649 	ATF_REQUIRE(WIFEXITED(status));
650 	ATF_REQUIRE(WEXITSTATUS(status) == 2);
651 
652 	wpid = wait(&status);
653 	ATF_REQUIRE(wpid == children[0]);
654 	ATF_REQUIRE(WIFEXITED(status));
655 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
656 
657 	wpid = wait(&status);
658 	ATF_REQUIRE(wpid == -1);
659 	ATF_REQUIRE(errno == ECHILD);
660 }
661 
662 /*
663  * Verify that a new child process is stopped after a followed fork
664  * and that the traced parent sees the exit of the child when the new
665  * child process is detached after it reports its fork.
666  */
667 ATF_TC_WITHOUT_HEAD(ptrace__follow_fork_child_detached);
ATF_TC_BODY(ptrace__follow_fork_child_detached,tc)668 ATF_TC_BODY(ptrace__follow_fork_child_detached, tc)
669 {
670 	pid_t children[2], fpid, wpid;
671 	int status;
672 
673 	ATF_REQUIRE((fpid = fork()) != -1);
674 	if (fpid == 0) {
675 		trace_me();
676 		follow_fork_parent(false);
677 	}
678 
679 	/* Parent process. */
680 	children[0] = fpid;
681 
682 	/* The first wait() should report the stop from SIGSTOP. */
683 	wpid = waitpid(children[0], &status, 0);
684 	ATF_REQUIRE(wpid == children[0]);
685 	ATF_REQUIRE(WIFSTOPPED(status));
686 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
687 
688 	ATF_REQUIRE(ptrace(PT_FOLLOW_FORK, children[0], NULL, 1) != -1);
689 
690 	/* Continue the child ignoring the SIGSTOP. */
691 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
692 
693 	children[1] = handle_fork_events(children[0], NULL);
694 	ATF_REQUIRE(children[1] > 0);
695 
696 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
697 	ATF_REQUIRE(ptrace(PT_DETACH, children[1], (caddr_t)1, 0) != -1);
698 
699 	/*
700 	 * Should not see any status from the grandchild now, only the
701 	 * child.
702 	 */
703 	wpid = wait(&status);
704 	ATF_REQUIRE(wpid == children[0]);
705 	ATF_REQUIRE(WIFEXITED(status));
706 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
707 
708 	wpid = wait(&status);
709 	ATF_REQUIRE(wpid == -1);
710 	ATF_REQUIRE(errno == ECHILD);
711 }
712 
713 /*
714  * Verify that a new child process is stopped after a followed fork
715  * and that the traced parent sees the exit of the child when the
716  * traced parent is detached after the fork.
717  */
718 ATF_TC_WITHOUT_HEAD(ptrace__follow_fork_parent_detached);
ATF_TC_BODY(ptrace__follow_fork_parent_detached,tc)719 ATF_TC_BODY(ptrace__follow_fork_parent_detached, tc)
720 {
721 	pid_t children[2], fpid, wpid;
722 	int status;
723 
724 	ATF_REQUIRE((fpid = fork()) != -1);
725 	if (fpid == 0) {
726 		trace_me();
727 		follow_fork_parent(false);
728 	}
729 
730 	/* Parent process. */
731 	children[0] = fpid;
732 
733 	/* The first wait() should report the stop from SIGSTOP. */
734 	wpid = waitpid(children[0], &status, 0);
735 	ATF_REQUIRE(wpid == children[0]);
736 	ATF_REQUIRE(WIFSTOPPED(status));
737 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
738 
739 	ATF_REQUIRE(ptrace(PT_FOLLOW_FORK, children[0], NULL, 1) != -1);
740 
741 	/* Continue the child ignoring the SIGSTOP. */
742 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
743 
744 	children[1] = handle_fork_events(children[0], NULL);
745 	ATF_REQUIRE(children[1] > 0);
746 
747 	ATF_REQUIRE(ptrace(PT_DETACH, children[0], (caddr_t)1, 0) != -1);
748 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[1], (caddr_t)1, 0) != -1);
749 
750 	/*
751 	 * The child can't exit until the grandchild reports status, so the
752 	 * grandchild should report its exit first to the debugger.
753 	 *
754 	 * Even though the child process is detached, it is still a
755 	 * child of the debugger, so it will still report it's exit
756 	 * after the grandchild.
757 	 */
758 	wpid = wait(&status);
759 	ATF_REQUIRE(wpid == children[1]);
760 	ATF_REQUIRE(WIFEXITED(status));
761 	ATF_REQUIRE(WEXITSTATUS(status) == 2);
762 
763 	wpid = wait(&status);
764 	ATF_REQUIRE(wpid == children[0]);
765 	ATF_REQUIRE(WIFEXITED(status));
766 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
767 
768 	wpid = wait(&status);
769 	ATF_REQUIRE(wpid == -1);
770 	ATF_REQUIRE(errno == ECHILD);
771 }
772 
773 static void
attach_fork_parent(int cpipe[2])774 attach_fork_parent(int cpipe[2])
775 {
776 	pid_t fpid;
777 
778 	close(cpipe[0]);
779 
780 	/* Double-fork to disassociate from the debugger. */
781 	CHILD_REQUIRE((fpid = fork()) != -1);
782 	if (fpid != 0)
783 		_exit(3);
784 
785 	/* Send the pid of the disassociated child to the debugger. */
786 	fpid = getpid();
787 	CHILD_REQUIRE(write(cpipe[1], &fpid, sizeof(fpid)) == sizeof(fpid));
788 
789 	/* Wait for the debugger to attach. */
790 	CHILD_REQUIRE(read(cpipe[1], &fpid, sizeof(fpid)) == 0);
791 }
792 
793 /*
794  * Verify that a new child process is stopped after a followed fork and
795  * that the traced parent sees the exit of the child after the debugger
796  * when both processes remain attached to the debugger.  In this test
797  * the parent that forks is not a direct child of the debugger.
798  */
799 ATF_TC_WITHOUT_HEAD(ptrace__follow_fork_both_attached_unrelated_debugger);
ATF_TC_BODY(ptrace__follow_fork_both_attached_unrelated_debugger,tc)800 ATF_TC_BODY(ptrace__follow_fork_both_attached_unrelated_debugger, tc)
801 {
802 	pid_t children[2], fpid, wpid;
803 	int cpipe[2], status;
804 
805 	ATF_REQUIRE(pipe(cpipe) == 0);
806 	ATF_REQUIRE((fpid = fork()) != -1);
807 	if (fpid == 0) {
808 		attach_fork_parent(cpipe);
809 		follow_fork_parent(false);
810 	}
811 
812 	/* Parent process. */
813 	close(cpipe[1]);
814 
815 	/* Wait for the direct child to exit. */
816 	wpid = waitpid(fpid, &status, 0);
817 	ATF_REQUIRE(wpid == fpid);
818 	ATF_REQUIRE(WIFEXITED(status));
819 	ATF_REQUIRE(WEXITSTATUS(status) == 3);
820 
821 	/* Read the pid of the fork parent. */
822 	ATF_REQUIRE(read(cpipe[0], &children[0], sizeof(children[0])) ==
823 	    sizeof(children[0]));
824 
825 	/* Attach to the fork parent. */
826 	attach_child(children[0]);
827 
828 	ATF_REQUIRE(ptrace(PT_FOLLOW_FORK, children[0], NULL, 1) != -1);
829 
830 	/* Continue the fork parent ignoring the SIGSTOP. */
831 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
832 
833 	/* Signal the fork parent to continue. */
834 	close(cpipe[0]);
835 
836 	children[1] = handle_fork_events(children[0], NULL);
837 	ATF_REQUIRE(children[1] > 0);
838 
839 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
840 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[1], (caddr_t)1, 0) != -1);
841 
842 	/*
843 	 * The fork parent can't exit until the child reports status,
844 	 * so the child should report its exit first to the debugger.
845 	 */
846 	wpid = wait(&status);
847 	ATF_REQUIRE(wpid == children[1]);
848 	ATF_REQUIRE(WIFEXITED(status));
849 	ATF_REQUIRE(WEXITSTATUS(status) == 2);
850 
851 	wpid = wait(&status);
852 	ATF_REQUIRE(wpid == children[0]);
853 	ATF_REQUIRE(WIFEXITED(status));
854 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
855 
856 	wpid = wait(&status);
857 	ATF_REQUIRE(wpid == -1);
858 	ATF_REQUIRE(errno == ECHILD);
859 }
860 
861 /*
862  * Verify that a new child process is stopped after a followed fork
863  * and that the traced parent sees the exit of the child when the new
864  * child process is detached after it reports its fork.  In this test
865  * the parent that forks is not a direct child of the debugger.
866  */
867 ATF_TC_WITHOUT_HEAD(ptrace__follow_fork_child_detached_unrelated_debugger);
ATF_TC_BODY(ptrace__follow_fork_child_detached_unrelated_debugger,tc)868 ATF_TC_BODY(ptrace__follow_fork_child_detached_unrelated_debugger, tc)
869 {
870 	pid_t children[2], fpid, wpid;
871 	int cpipe[2], status;
872 
873 	ATF_REQUIRE(pipe(cpipe) == 0);
874 	ATF_REQUIRE((fpid = fork()) != -1);
875 	if (fpid == 0) {
876 		attach_fork_parent(cpipe);
877 		follow_fork_parent(false);
878 	}
879 
880 	/* Parent process. */
881 	close(cpipe[1]);
882 
883 	/* Wait for the direct child to exit. */
884 	wpid = waitpid(fpid, &status, 0);
885 	ATF_REQUIRE(wpid == fpid);
886 	ATF_REQUIRE(WIFEXITED(status));
887 	ATF_REQUIRE(WEXITSTATUS(status) == 3);
888 
889 	/* Read the pid of the fork parent. */
890 	ATF_REQUIRE(read(cpipe[0], &children[0], sizeof(children[0])) ==
891 	    sizeof(children[0]));
892 
893 	/* Attach to the fork parent. */
894 	attach_child(children[0]);
895 
896 	ATF_REQUIRE(ptrace(PT_FOLLOW_FORK, children[0], NULL, 1) != -1);
897 
898 	/* Continue the fork parent ignoring the SIGSTOP. */
899 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
900 
901 	/* Signal the fork parent to continue. */
902 	close(cpipe[0]);
903 
904 	children[1] = handle_fork_events(children[0], NULL);
905 	ATF_REQUIRE(children[1] > 0);
906 
907 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
908 	ATF_REQUIRE(ptrace(PT_DETACH, children[1], (caddr_t)1, 0) != -1);
909 
910 	/*
911 	 * Should not see any status from the child now, only the fork
912 	 * parent.
913 	 */
914 	wpid = wait(&status);
915 	ATF_REQUIRE(wpid == children[0]);
916 	ATF_REQUIRE(WIFEXITED(status));
917 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
918 
919 	wpid = wait(&status);
920 	ATF_REQUIRE(wpid == -1);
921 	ATF_REQUIRE(errno == ECHILD);
922 }
923 
924 /*
925  * Verify that a new child process is stopped after a followed fork
926  * and that the traced parent sees the exit of the child when the
927  * traced parent is detached after the fork.  In this test the parent
928  * that forks is not a direct child of the debugger.
929  */
930 ATF_TC_WITHOUT_HEAD(ptrace__follow_fork_parent_detached_unrelated_debugger);
ATF_TC_BODY(ptrace__follow_fork_parent_detached_unrelated_debugger,tc)931 ATF_TC_BODY(ptrace__follow_fork_parent_detached_unrelated_debugger, tc)
932 {
933 	pid_t children[2], fpid, wpid;
934 	int cpipe[2], status;
935 
936 	ATF_REQUIRE(pipe(cpipe) == 0);
937 	ATF_REQUIRE((fpid = fork()) != -1);
938 	if (fpid == 0) {
939 		attach_fork_parent(cpipe);
940 		follow_fork_parent(false);
941 	}
942 
943 	/* Parent process. */
944 	close(cpipe[1]);
945 
946 	/* Wait for the direct child to exit. */
947 	wpid = waitpid(fpid, &status, 0);
948 	ATF_REQUIRE(wpid == fpid);
949 	ATF_REQUIRE(WIFEXITED(status));
950 	ATF_REQUIRE(WEXITSTATUS(status) == 3);
951 
952 	/* Read the pid of the fork parent. */
953 	ATF_REQUIRE(read(cpipe[0], &children[0], sizeof(children[0])) ==
954 	    sizeof(children[0]));
955 
956 	/* Attach to the fork parent. */
957 	attach_child(children[0]);
958 
959 	ATF_REQUIRE(ptrace(PT_FOLLOW_FORK, children[0], NULL, 1) != -1);
960 
961 	/* Continue the fork parent ignoring the SIGSTOP. */
962 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
963 
964 	/* Signal the fork parent to continue. */
965 	close(cpipe[0]);
966 
967 	children[1] = handle_fork_events(children[0], NULL);
968 	ATF_REQUIRE(children[1] > 0);
969 
970 	ATF_REQUIRE(ptrace(PT_DETACH, children[0], (caddr_t)1, 0) != -1);
971 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[1], (caddr_t)1, 0) != -1);
972 
973 	/*
974 	 * Should not see any status from the fork parent now, only
975 	 * the child.
976 	 */
977 	wpid = wait(&status);
978 	ATF_REQUIRE(wpid == children[1]);
979 	ATF_REQUIRE(WIFEXITED(status));
980 	ATF_REQUIRE(WEXITSTATUS(status) == 2);
981 
982 	wpid = wait(&status);
983 	ATF_REQUIRE(wpid == -1);
984 	ATF_REQUIRE(errno == ECHILD);
985 }
986 
987 /*
988  * Verify that a child process does not see an unrelated debugger as its
989  * parent but sees its original parent process.
990  */
991 ATF_TC_WITHOUT_HEAD(ptrace__getppid);
ATF_TC_BODY(ptrace__getppid,tc)992 ATF_TC_BODY(ptrace__getppid, tc)
993 {
994 	pid_t child, debugger, ppid, wpid;
995 	int cpipe[2], dpipe[2], status;
996 	char c;
997 
998 	ATF_REQUIRE(pipe(cpipe) == 0);
999 	ATF_REQUIRE((child = fork()) != -1);
1000 
1001 	if (child == 0) {
1002 		/* Child process. */
1003 		close(cpipe[0]);
1004 
1005 		/* Wait for parent to be ready. */
1006 		CHILD_REQUIRE(read(cpipe[1], &c, sizeof(c)) == sizeof(c));
1007 
1008 		/* Report the parent PID to the parent. */
1009 		ppid = getppid();
1010 		CHILD_REQUIRE(write(cpipe[1], &ppid, sizeof(ppid)) ==
1011 		    sizeof(ppid));
1012 
1013 		_exit(1);
1014 	}
1015 	close(cpipe[1]);
1016 
1017 	ATF_REQUIRE(pipe(dpipe) == 0);
1018 	ATF_REQUIRE((debugger = fork()) != -1);
1019 
1020 	if (debugger == 0) {
1021 		/* Debugger process. */
1022 		close(dpipe[0]);
1023 
1024 		CHILD_REQUIRE(ptrace(PT_ATTACH, child, NULL, 0) != -1);
1025 
1026 		wpid = waitpid(child, &status, 0);
1027 		CHILD_REQUIRE(wpid == child);
1028 		CHILD_REQUIRE(WIFSTOPPED(status));
1029 		CHILD_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1030 
1031 		CHILD_REQUIRE(ptrace(PT_CONTINUE, child, (caddr_t)1, 0) != -1);
1032 
1033 		/* Signal parent that debugger is attached. */
1034 		CHILD_REQUIRE(write(dpipe[1], &c, sizeof(c)) == sizeof(c));
1035 
1036 		/* Wait for traced child to exit. */
1037 		wpid = waitpid(child, &status, 0);
1038 		CHILD_REQUIRE(wpid == child);
1039 		CHILD_REQUIRE(WIFEXITED(status));
1040 		CHILD_REQUIRE(WEXITSTATUS(status) == 1);
1041 
1042 		_exit(0);
1043 	}
1044 	close(dpipe[1]);
1045 
1046 	/* Parent process. */
1047 
1048 	/* Wait for the debugger to attach to the child. */
1049 	ATF_REQUIRE(read(dpipe[0], &c, sizeof(c)) == sizeof(c));
1050 
1051 	/* Release the child. */
1052 	ATF_REQUIRE(write(cpipe[0], &c, sizeof(c)) == sizeof(c));
1053 
1054 	/* Read the parent PID from the child. */
1055 	ATF_REQUIRE(read(cpipe[0], &ppid, sizeof(ppid)) == sizeof(ppid));
1056 	close(cpipe[0]);
1057 
1058 	ATF_REQUIRE(ppid == getpid());
1059 
1060 	/* Wait for the debugger. */
1061 	wpid = waitpid(debugger, &status, 0);
1062 	ATF_REQUIRE(wpid == debugger);
1063 	ATF_REQUIRE(WIFEXITED(status));
1064 	ATF_REQUIRE(WEXITSTATUS(status) == 0);
1065 
1066 	/* The child process should now be ready. */
1067 	wpid = waitpid(child, &status, WNOHANG);
1068 	ATF_REQUIRE(wpid == child);
1069 	ATF_REQUIRE(WIFEXITED(status));
1070 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
1071 }
1072 
1073 /*
1074  * Verify that pl_syscall_code in struct ptrace_lwpinfo for a new
1075  * child process created via fork() reports the correct value.
1076  */
1077 ATF_TC_WITHOUT_HEAD(ptrace__new_child_pl_syscall_code_fork);
ATF_TC_BODY(ptrace__new_child_pl_syscall_code_fork,tc)1078 ATF_TC_BODY(ptrace__new_child_pl_syscall_code_fork, tc)
1079 {
1080 	struct ptrace_lwpinfo pl[2];
1081 	pid_t children[2], fpid, wpid;
1082 	int status;
1083 
1084 	ATF_REQUIRE((fpid = fork()) != -1);
1085 	if (fpid == 0) {
1086 		trace_me();
1087 		follow_fork_parent(false);
1088 	}
1089 
1090 	/* Parent process. */
1091 	children[0] = fpid;
1092 
1093 	/* The first wait() should report the stop from SIGSTOP. */
1094 	wpid = waitpid(children[0], &status, 0);
1095 	ATF_REQUIRE(wpid == children[0]);
1096 	ATF_REQUIRE(WIFSTOPPED(status));
1097 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1098 
1099 	ATF_REQUIRE(ptrace(PT_FOLLOW_FORK, children[0], NULL, 1) != -1);
1100 
1101 	/* Continue the child ignoring the SIGSTOP. */
1102 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
1103 
1104 	/* Wait for both halves of the fork event to get reported. */
1105 	children[1] = handle_fork_events(children[0], pl);
1106 	ATF_REQUIRE(children[1] > 0);
1107 
1108 	ATF_REQUIRE((pl[0].pl_flags & PL_FLAG_SCX) != 0);
1109 	ATF_REQUIRE((pl[1].pl_flags & PL_FLAG_SCX) != 0);
1110 	ATF_REQUIRE(pl[0].pl_syscall_code == SYS_fork);
1111 	ATF_REQUIRE(pl[0].pl_syscall_code == pl[1].pl_syscall_code);
1112 	ATF_REQUIRE(pl[0].pl_syscall_narg == pl[1].pl_syscall_narg);
1113 
1114 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
1115 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[1], (caddr_t)1, 0) != -1);
1116 
1117 	/*
1118 	 * The child can't exit until the grandchild reports status, so the
1119 	 * grandchild should report its exit first to the debugger.
1120 	 */
1121 	wpid = wait(&status);
1122 	ATF_REQUIRE(wpid == children[1]);
1123 	ATF_REQUIRE(WIFEXITED(status));
1124 	ATF_REQUIRE(WEXITSTATUS(status) == 2);
1125 
1126 	wpid = wait(&status);
1127 	ATF_REQUIRE(wpid == children[0]);
1128 	ATF_REQUIRE(WIFEXITED(status));
1129 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
1130 
1131 	wpid = wait(&status);
1132 	ATF_REQUIRE(wpid == -1);
1133 	ATF_REQUIRE(errno == ECHILD);
1134 }
1135 
1136 /*
1137  * Verify that pl_syscall_code in struct ptrace_lwpinfo for a new
1138  * child process created via vfork() reports the correct value.
1139  */
1140 ATF_TC_WITHOUT_HEAD(ptrace__new_child_pl_syscall_code_vfork);
ATF_TC_BODY(ptrace__new_child_pl_syscall_code_vfork,tc)1141 ATF_TC_BODY(ptrace__new_child_pl_syscall_code_vfork, tc)
1142 {
1143 	struct ptrace_lwpinfo pl[2];
1144 	pid_t children[2], fpid, wpid;
1145 	int status;
1146 
1147 	ATF_REQUIRE((fpid = fork()) != -1);
1148 	if (fpid == 0) {
1149 		trace_me();
1150 		follow_fork_parent(true);
1151 	}
1152 
1153 	/* Parent process. */
1154 	children[0] = fpid;
1155 
1156 	/* The first wait() should report the stop from SIGSTOP. */
1157 	wpid = waitpid(children[0], &status, 0);
1158 	ATF_REQUIRE(wpid == children[0]);
1159 	ATF_REQUIRE(WIFSTOPPED(status));
1160 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1161 
1162 	ATF_REQUIRE(ptrace(PT_FOLLOW_FORK, children[0], NULL, 1) != -1);
1163 
1164 	/* Continue the child ignoring the SIGSTOP. */
1165 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
1166 
1167 	/* Wait for both halves of the fork event to get reported. */
1168 	children[1] = handle_fork_events(children[0], pl);
1169 	ATF_REQUIRE(children[1] > 0);
1170 
1171 	ATF_REQUIRE((pl[0].pl_flags & PL_FLAG_SCX) != 0);
1172 	ATF_REQUIRE((pl[1].pl_flags & PL_FLAG_SCX) != 0);
1173 	ATF_REQUIRE(pl[0].pl_syscall_code == SYS_vfork);
1174 	ATF_REQUIRE(pl[0].pl_syscall_code == pl[1].pl_syscall_code);
1175 	ATF_REQUIRE(pl[0].pl_syscall_narg == pl[1].pl_syscall_narg);
1176 
1177 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
1178 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[1], (caddr_t)1, 0) != -1);
1179 
1180 	/*
1181 	 * The child can't exit until the grandchild reports status, so the
1182 	 * grandchild should report its exit first to the debugger.
1183 	 */
1184 	wpid = wait(&status);
1185 	ATF_REQUIRE(wpid == children[1]);
1186 	ATF_REQUIRE(WIFEXITED(status));
1187 	ATF_REQUIRE(WEXITSTATUS(status) == 2);
1188 
1189 	wpid = wait(&status);
1190 	ATF_REQUIRE(wpid == children[0]);
1191 	ATF_REQUIRE(WIFEXITED(status));
1192 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
1193 
1194 	wpid = wait(&status);
1195 	ATF_REQUIRE(wpid == -1);
1196 	ATF_REQUIRE(errno == ECHILD);
1197 }
1198 
1199 static void *
simple_thread(void * arg __unused)1200 simple_thread(void *arg __unused)
1201 {
1202 
1203 	pthread_exit(NULL);
1204 }
1205 
1206 static __dead2 void
simple_thread_main(void)1207 simple_thread_main(void)
1208 {
1209 	pthread_t thread;
1210 
1211 	CHILD_REQUIRE(pthread_create(&thread, NULL, simple_thread, NULL) == 0);
1212 	CHILD_REQUIRE(pthread_join(thread, NULL) == 0);
1213 	exit(1);
1214 }
1215 
1216 /*
1217  * Verify that pl_syscall_code in struct ptrace_lwpinfo for a new
1218  * thread reports the correct value.
1219  */
1220 ATF_TC_WITHOUT_HEAD(ptrace__new_child_pl_syscall_code_thread);
ATF_TC_BODY(ptrace__new_child_pl_syscall_code_thread,tc)1221 ATF_TC_BODY(ptrace__new_child_pl_syscall_code_thread, tc)
1222 {
1223 	struct ptrace_lwpinfo pl;
1224 	pid_t fpid, wpid;
1225 	lwpid_t mainlwp;
1226 	int status;
1227 
1228 	ATF_REQUIRE((fpid = fork()) != -1);
1229 	if (fpid == 0) {
1230 		trace_me();
1231 		simple_thread_main();
1232 	}
1233 
1234 	/* The first wait() should report the stop from SIGSTOP. */
1235 	wpid = waitpid(fpid, &status, 0);
1236 	ATF_REQUIRE(wpid == fpid);
1237 	ATF_REQUIRE(WIFSTOPPED(status));
1238 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1239 
1240 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
1241 	    sizeof(pl)) != -1);
1242 	mainlwp = pl.pl_lwpid;
1243 
1244 	/*
1245 	 * Continue the child ignoring the SIGSTOP and tracing all
1246 	 * system call exits.
1247 	 */
1248 	ATF_REQUIRE(ptrace(PT_TO_SCX, fpid, (caddr_t)1, 0) != -1);
1249 
1250 	/*
1251 	 * Wait for the new thread to arrive.  pthread_create() might
1252 	 * invoke any number of system calls.  For now we just wait
1253 	 * for the new thread to arrive and make sure it reports a
1254 	 * valid system call code.  If ptrace grows thread event
1255 	 * reporting then this test can be made more precise.
1256 	 */
1257 	for (;;) {
1258 		wpid = waitpid(fpid, &status, 0);
1259 		ATF_REQUIRE(wpid == fpid);
1260 		ATF_REQUIRE(WIFSTOPPED(status));
1261 		ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1262 
1263 		ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
1264 		    sizeof(pl)) != -1);
1265 		ATF_REQUIRE((pl.pl_flags & PL_FLAG_SCX) != 0);
1266 		ATF_REQUIRE(pl.pl_syscall_code != 0);
1267 		if (pl.pl_lwpid != mainlwp)
1268 			/* New thread seen. */
1269 			break;
1270 
1271 		ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1272 	}
1273 
1274 	/* Wait for the child to exit. */
1275 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1276 	for (;;) {
1277 		wpid = waitpid(fpid, &status, 0);
1278 		ATF_REQUIRE(wpid == fpid);
1279 		if (WIFEXITED(status))
1280 			break;
1281 
1282 		ATF_REQUIRE(WIFSTOPPED(status));
1283 		ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1284 		ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1285 	}
1286 
1287 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
1288 
1289 	wpid = wait(&status);
1290 	ATF_REQUIRE(wpid == -1);
1291 	ATF_REQUIRE(errno == ECHILD);
1292 }
1293 
1294 /*
1295  * Verify that the expected LWP events are reported for a child thread.
1296  */
1297 ATF_TC_WITHOUT_HEAD(ptrace__lwp_events);
ATF_TC_BODY(ptrace__lwp_events,tc)1298 ATF_TC_BODY(ptrace__lwp_events, tc)
1299 {
1300 	struct ptrace_lwpinfo pl;
1301 	pid_t fpid, wpid;
1302 	lwpid_t lwps[2];
1303 	int status;
1304 
1305 	ATF_REQUIRE((fpid = fork()) != -1);
1306 	if (fpid == 0) {
1307 		trace_me();
1308 		simple_thread_main();
1309 	}
1310 
1311 	/* The first wait() should report the stop from SIGSTOP. */
1312 	wpid = waitpid(fpid, &status, 0);
1313 	ATF_REQUIRE(wpid == fpid);
1314 	ATF_REQUIRE(WIFSTOPPED(status));
1315 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1316 
1317 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
1318 	    sizeof(pl)) != -1);
1319 	lwps[0] = pl.pl_lwpid;
1320 
1321 	ATF_REQUIRE(ptrace(PT_LWP_EVENTS, wpid, NULL, 1) == 0);
1322 
1323 	/* Continue the child ignoring the SIGSTOP. */
1324 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1325 
1326 	/* The first event should be for the child thread's birth. */
1327 	wpid = waitpid(fpid, &status, 0);
1328 	ATF_REQUIRE(wpid == fpid);
1329 	ATF_REQUIRE(WIFSTOPPED(status));
1330 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1331 
1332 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
1333 	ATF_REQUIRE((pl.pl_flags & (PL_FLAG_BORN | PL_FLAG_SCX)) ==
1334 	    (PL_FLAG_BORN | PL_FLAG_SCX));
1335 	ATF_REQUIRE(pl.pl_lwpid != lwps[0]);
1336 	lwps[1] = pl.pl_lwpid;
1337 
1338 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1339 
1340 	/* The next event should be for the child thread's death. */
1341 	wpid = waitpid(fpid, &status, 0);
1342 	ATF_REQUIRE(wpid == fpid);
1343 	ATF_REQUIRE(WIFSTOPPED(status));
1344 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1345 
1346 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
1347 	ATF_REQUIRE((pl.pl_flags & (PL_FLAG_EXITED | PL_FLAG_SCE)) ==
1348 	    (PL_FLAG_EXITED | PL_FLAG_SCE));
1349 	ATF_REQUIRE(pl.pl_lwpid == lwps[1]);
1350 
1351 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1352 
1353 	/* The last event should be for the child process's exit. */
1354 	wpid = waitpid(fpid, &status, 0);
1355 	ATF_REQUIRE(WIFEXITED(status));
1356 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
1357 
1358 	wpid = wait(&status);
1359 	ATF_REQUIRE(wpid == -1);
1360 	ATF_REQUIRE(errno == ECHILD);
1361 }
1362 
1363 static void *
exec_thread(void * arg __unused)1364 exec_thread(void *arg __unused)
1365 {
1366 
1367 	execl("/usr/bin/true", "true", NULL);
1368 	exit(127);
1369 }
1370 
1371 static __dead2 void
exec_thread_main(void)1372 exec_thread_main(void)
1373 {
1374 	pthread_t thread;
1375 
1376 	CHILD_REQUIRE(pthread_create(&thread, NULL, exec_thread, NULL) == 0);
1377 	for (;;)
1378 		sleep(60);
1379 	exit(1);
1380 }
1381 
1382 /*
1383  * Verify that the expected LWP events are reported for a multithreaded
1384  * process that calls execve(2).
1385  */
1386 ATF_TC_WITHOUT_HEAD(ptrace__lwp_events_exec);
ATF_TC_BODY(ptrace__lwp_events_exec,tc)1387 ATF_TC_BODY(ptrace__lwp_events_exec, tc)
1388 {
1389 	struct ptrace_lwpinfo pl;
1390 	pid_t fpid, wpid;
1391 	lwpid_t lwps[2];
1392 	int status;
1393 
1394 	ATF_REQUIRE((fpid = fork()) != -1);
1395 	if (fpid == 0) {
1396 		trace_me();
1397 		exec_thread_main();
1398 	}
1399 
1400 	/* The first wait() should report the stop from SIGSTOP. */
1401 	wpid = waitpid(fpid, &status, 0);
1402 	ATF_REQUIRE(wpid == fpid);
1403 	ATF_REQUIRE(WIFSTOPPED(status));
1404 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1405 
1406 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
1407 	    sizeof(pl)) != -1);
1408 	lwps[0] = pl.pl_lwpid;
1409 
1410 	ATF_REQUIRE(ptrace(PT_LWP_EVENTS, wpid, NULL, 1) == 0);
1411 
1412 	/* Continue the child ignoring the SIGSTOP. */
1413 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1414 
1415 	/* The first event should be for the child thread's birth. */
1416 	wpid = waitpid(fpid, &status, 0);
1417 	ATF_REQUIRE(wpid == fpid);
1418 	ATF_REQUIRE(WIFSTOPPED(status));
1419 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1420 
1421 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
1422 	ATF_REQUIRE((pl.pl_flags & (PL_FLAG_BORN | PL_FLAG_SCX)) ==
1423 	    (PL_FLAG_BORN | PL_FLAG_SCX));
1424 	ATF_REQUIRE(pl.pl_lwpid != lwps[0]);
1425 	lwps[1] = pl.pl_lwpid;
1426 
1427 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1428 
1429 	/*
1430 	 * The next event should be for the main thread's death due to
1431 	 * single threading from execve().
1432 	 */
1433 	wpid = waitpid(fpid, &status, 0);
1434 	ATF_REQUIRE(wpid == fpid);
1435 	ATF_REQUIRE(WIFSTOPPED(status));
1436 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1437 
1438 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
1439 	ATF_REQUIRE((pl.pl_flags & (PL_FLAG_EXITED | PL_FLAG_SCE)) ==
1440 	    (PL_FLAG_EXITED));
1441 	ATF_REQUIRE(pl.pl_lwpid == lwps[0]);
1442 
1443 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1444 
1445 	/* The next event should be for the child process's exec. */
1446 	wpid = waitpid(fpid, &status, 0);
1447 	ATF_REQUIRE(WIFSTOPPED(status));
1448 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1449 
1450 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
1451 	ATF_REQUIRE((pl.pl_flags & (PL_FLAG_EXEC | PL_FLAG_SCX)) ==
1452 	    (PL_FLAG_EXEC | PL_FLAG_SCX));
1453 	ATF_REQUIRE(pl.pl_lwpid == lwps[1]);
1454 
1455 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1456 
1457 	/* The last event should be for the child process's exit. */
1458 	wpid = waitpid(fpid, &status, 0);
1459 	ATF_REQUIRE(WIFEXITED(status));
1460 	ATF_REQUIRE(WEXITSTATUS(status) == 0);
1461 
1462 	wpid = wait(&status);
1463 	ATF_REQUIRE(wpid == -1);
1464 	ATF_REQUIRE(errno == ECHILD);
1465 }
1466 
1467 static void
handler(int sig __unused)1468 handler(int sig __unused)
1469 {
1470 }
1471 
1472 static void
signal_main(void)1473 signal_main(void)
1474 {
1475 
1476 	signal(SIGINFO, handler);
1477 	raise(SIGINFO);
1478 	exit(0);
1479 }
1480 
1481 /*
1482  * Verify that the expected ptrace event is reported for a signal.
1483  */
1484 ATF_TC_WITHOUT_HEAD(ptrace__siginfo);
ATF_TC_BODY(ptrace__siginfo,tc)1485 ATF_TC_BODY(ptrace__siginfo, tc)
1486 {
1487 	struct ptrace_lwpinfo pl;
1488 	pid_t fpid, wpid;
1489 	int status;
1490 
1491 	ATF_REQUIRE((fpid = fork()) != -1);
1492 	if (fpid == 0) {
1493 		trace_me();
1494 		signal_main();
1495 	}
1496 
1497 	/* The first wait() should report the stop from SIGSTOP. */
1498 	wpid = waitpid(fpid, &status, 0);
1499 	ATF_REQUIRE(wpid == fpid);
1500 	ATF_REQUIRE(WIFSTOPPED(status));
1501 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1502 
1503 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1504 
1505 	/* The next event should be for the SIGINFO. */
1506 	wpid = waitpid(fpid, &status, 0);
1507 	ATF_REQUIRE(WIFSTOPPED(status));
1508 	ATF_REQUIRE(WSTOPSIG(status) == SIGINFO);
1509 
1510 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
1511 	ATF_REQUIRE(pl.pl_event == PL_EVENT_SIGNAL);
1512 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SI);
1513 	ATF_REQUIRE(pl.pl_siginfo.si_code == SI_LWP);
1514 	ATF_REQUIRE(pl.pl_siginfo.si_pid == wpid);
1515 
1516 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1517 
1518 	/* The last event should be for the child process's exit. */
1519 	wpid = waitpid(fpid, &status, 0);
1520 	ATF_REQUIRE(WIFEXITED(status));
1521 	ATF_REQUIRE(WEXITSTATUS(status) == 0);
1522 
1523 	wpid = wait(&status);
1524 	ATF_REQUIRE(wpid == -1);
1525 	ATF_REQUIRE(errno == ECHILD);
1526 }
1527 
1528 /*
1529  * Verify that the expected ptrace events are reported for PTRACE_EXEC.
1530  */
1531 ATF_TC_WITHOUT_HEAD(ptrace__ptrace_exec_disable);
ATF_TC_BODY(ptrace__ptrace_exec_disable,tc)1532 ATF_TC_BODY(ptrace__ptrace_exec_disable, tc)
1533 {
1534 	pid_t fpid, wpid;
1535 	int events, status;
1536 
1537 	ATF_REQUIRE((fpid = fork()) != -1);
1538 	if (fpid == 0) {
1539 		trace_me();
1540 		exec_thread(NULL);
1541 	}
1542 
1543 	/* The first wait() should report the stop from SIGSTOP. */
1544 	wpid = waitpid(fpid, &status, 0);
1545 	ATF_REQUIRE(wpid == fpid);
1546 	ATF_REQUIRE(WIFSTOPPED(status));
1547 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1548 
1549 	events = 0;
1550 	ATF_REQUIRE(ptrace(PT_SET_EVENT_MASK, fpid, (caddr_t)&events,
1551 	    sizeof(events)) == 0);
1552 
1553 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1554 
1555 	/* Should get one event at exit. */
1556 	wpid = waitpid(fpid, &status, 0);
1557 	ATF_REQUIRE(WIFEXITED(status));
1558 	ATF_REQUIRE(WEXITSTATUS(status) == 0);
1559 
1560 	wpid = wait(&status);
1561 	ATF_REQUIRE(wpid == -1);
1562 	ATF_REQUIRE(errno == ECHILD);
1563 }
1564 
1565 ATF_TC_WITHOUT_HEAD(ptrace__ptrace_exec_enable);
ATF_TC_BODY(ptrace__ptrace_exec_enable,tc)1566 ATF_TC_BODY(ptrace__ptrace_exec_enable, tc)
1567 {
1568 	struct ptrace_lwpinfo pl;
1569 	pid_t fpid, wpid;
1570 	int events, status;
1571 
1572 	ATF_REQUIRE((fpid = fork()) != -1);
1573 	if (fpid == 0) {
1574 		trace_me();
1575 		exec_thread(NULL);
1576 	}
1577 
1578 	/* The first wait() should report the stop from SIGSTOP. */
1579 	wpid = waitpid(fpid, &status, 0);
1580 	ATF_REQUIRE(wpid == fpid);
1581 	ATF_REQUIRE(WIFSTOPPED(status));
1582 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1583 
1584 	events = PTRACE_EXEC;
1585 	ATF_REQUIRE(ptrace(PT_SET_EVENT_MASK, fpid, (caddr_t)&events,
1586 	    sizeof(events)) == 0);
1587 
1588 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1589 
1590 	/* The next event should be for the child process's exec. */
1591 	wpid = waitpid(fpid, &status, 0);
1592 	ATF_REQUIRE(WIFSTOPPED(status));
1593 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1594 
1595 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
1596 	ATF_REQUIRE((pl.pl_flags & (PL_FLAG_EXEC | PL_FLAG_SCX)) ==
1597 	    (PL_FLAG_EXEC | PL_FLAG_SCX));
1598 
1599 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1600 
1601 	/* The last event should be for the child process's exit. */
1602 	wpid = waitpid(fpid, &status, 0);
1603 	ATF_REQUIRE(WIFEXITED(status));
1604 	ATF_REQUIRE(WEXITSTATUS(status) == 0);
1605 
1606 	wpid = wait(&status);
1607 	ATF_REQUIRE(wpid == -1);
1608 	ATF_REQUIRE(errno == ECHILD);
1609 }
1610 
1611 ATF_TC_WITHOUT_HEAD(ptrace__event_mask);
ATF_TC_BODY(ptrace__event_mask,tc)1612 ATF_TC_BODY(ptrace__event_mask, tc)
1613 {
1614 	pid_t fpid, wpid;
1615 	int events, status;
1616 
1617 	ATF_REQUIRE((fpid = fork()) != -1);
1618 	if (fpid == 0) {
1619 		trace_me();
1620 		exit(0);
1621 	}
1622 
1623 	/* The first wait() should report the stop from SIGSTOP. */
1624 	wpid = waitpid(fpid, &status, 0);
1625 	ATF_REQUIRE(wpid == fpid);
1626 	ATF_REQUIRE(WIFSTOPPED(status));
1627 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1628 
1629 	/* PT_FOLLOW_FORK should toggle the state of PTRACE_FORK. */
1630 	ATF_REQUIRE(ptrace(PT_FOLLOW_FORK, fpid, NULL, 1) != -1);
1631 	ATF_REQUIRE(ptrace(PT_GET_EVENT_MASK, fpid, (caddr_t)&events,
1632 	    sizeof(events)) == 0);
1633 	ATF_REQUIRE(events & PTRACE_FORK);
1634 	ATF_REQUIRE(ptrace(PT_FOLLOW_FORK, fpid, NULL, 0) != -1);
1635 	ATF_REQUIRE(ptrace(PT_GET_EVENT_MASK, fpid, (caddr_t)&events,
1636 	    sizeof(events)) == 0);
1637 	ATF_REQUIRE(!(events & PTRACE_FORK));
1638 
1639 	/* PT_LWP_EVENTS should toggle the state of PTRACE_LWP. */
1640 	ATF_REQUIRE(ptrace(PT_LWP_EVENTS, fpid, NULL, 1) != -1);
1641 	ATF_REQUIRE(ptrace(PT_GET_EVENT_MASK, fpid, (caddr_t)&events,
1642 	    sizeof(events)) == 0);
1643 	ATF_REQUIRE(events & PTRACE_LWP);
1644 	ATF_REQUIRE(ptrace(PT_LWP_EVENTS, fpid, NULL, 0) != -1);
1645 	ATF_REQUIRE(ptrace(PT_GET_EVENT_MASK, fpid, (caddr_t)&events,
1646 	    sizeof(events)) == 0);
1647 	ATF_REQUIRE(!(events & PTRACE_LWP));
1648 
1649 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1650 
1651 	/* Should get one event at exit. */
1652 	wpid = waitpid(fpid, &status, 0);
1653 	ATF_REQUIRE(WIFEXITED(status));
1654 	ATF_REQUIRE(WEXITSTATUS(status) == 0);
1655 
1656 	wpid = wait(&status);
1657 	ATF_REQUIRE(wpid == -1);
1658 	ATF_REQUIRE(errno == ECHILD);
1659 }
1660 
1661 /*
1662  * Verify that the expected ptrace events are reported for PTRACE_VFORK.
1663  */
1664 ATF_TC_WITHOUT_HEAD(ptrace__ptrace_vfork);
ATF_TC_BODY(ptrace__ptrace_vfork,tc)1665 ATF_TC_BODY(ptrace__ptrace_vfork, tc)
1666 {
1667 	struct ptrace_lwpinfo pl;
1668 	pid_t fpid, wpid;
1669 	int events, status;
1670 
1671 	ATF_REQUIRE((fpid = fork()) != -1);
1672 	if (fpid == 0) {
1673 		trace_me();
1674 		follow_fork_parent(true);
1675 	}
1676 
1677 	/* The first wait() should report the stop from SIGSTOP. */
1678 	wpid = waitpid(fpid, &status, 0);
1679 	ATF_REQUIRE(wpid == fpid);
1680 	ATF_REQUIRE(WIFSTOPPED(status));
1681 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1682 
1683 	ATF_REQUIRE(ptrace(PT_GET_EVENT_MASK, fpid, (caddr_t)&events,
1684 	    sizeof(events)) == 0);
1685 	events |= PTRACE_VFORK;
1686 	ATF_REQUIRE(ptrace(PT_SET_EVENT_MASK, fpid, (caddr_t)&events,
1687 	    sizeof(events)) == 0);
1688 
1689 	/* Continue the child ignoring the SIGSTOP. */
1690 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) != -1);
1691 
1692 	/* The next event should report the end of the vfork. */
1693 	wpid = wait(&status);
1694 	ATF_REQUIRE(wpid == fpid);
1695 	ATF_REQUIRE(WIFSTOPPED(status));
1696 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1697 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
1698 	ATF_REQUIRE((pl.pl_flags & PL_FLAG_VFORK_DONE) != 0);
1699 
1700 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) != -1);
1701 
1702 	wpid = wait(&status);
1703 	ATF_REQUIRE(wpid == fpid);
1704 	ATF_REQUIRE(WIFEXITED(status));
1705 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
1706 
1707 	wpid = wait(&status);
1708 	ATF_REQUIRE(wpid == -1);
1709 	ATF_REQUIRE(errno == ECHILD);
1710 }
1711 
1712 ATF_TC_WITHOUT_HEAD(ptrace__ptrace_vfork_follow);
ATF_TC_BODY(ptrace__ptrace_vfork_follow,tc)1713 ATF_TC_BODY(ptrace__ptrace_vfork_follow, tc)
1714 {
1715 	struct ptrace_lwpinfo pl[2];
1716 	pid_t children[2], fpid, wpid;
1717 	int events, status;
1718 
1719 	ATF_REQUIRE((fpid = fork()) != -1);
1720 	if (fpid == 0) {
1721 		trace_me();
1722 		follow_fork_parent(true);
1723 	}
1724 
1725 	/* Parent process. */
1726 	children[0] = fpid;
1727 
1728 	/* The first wait() should report the stop from SIGSTOP. */
1729 	wpid = waitpid(children[0], &status, 0);
1730 	ATF_REQUIRE(wpid == children[0]);
1731 	ATF_REQUIRE(WIFSTOPPED(status));
1732 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1733 
1734 	ATF_REQUIRE(ptrace(PT_GET_EVENT_MASK, children[0], (caddr_t)&events,
1735 	    sizeof(events)) == 0);
1736 	events |= PTRACE_FORK | PTRACE_VFORK;
1737 	ATF_REQUIRE(ptrace(PT_SET_EVENT_MASK, children[0], (caddr_t)&events,
1738 	    sizeof(events)) == 0);
1739 
1740 	/* Continue the child ignoring the SIGSTOP. */
1741 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
1742 
1743 	/* Wait for both halves of the fork event to get reported. */
1744 	children[1] = handle_fork_events(children[0], pl);
1745 	ATF_REQUIRE(children[1] > 0);
1746 
1747 	ATF_REQUIRE((pl[0].pl_flags & PL_FLAG_VFORKED) != 0);
1748 
1749 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
1750 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[1], (caddr_t)1, 0) != -1);
1751 
1752 	/*
1753 	 * The child can't exit until the grandchild reports status, so the
1754 	 * grandchild should report its exit first to the debugger.
1755 	 */
1756 	wpid = waitpid(children[1], &status, 0);
1757 	ATF_REQUIRE(wpid == children[1]);
1758 	ATF_REQUIRE(WIFEXITED(status));
1759 	ATF_REQUIRE(WEXITSTATUS(status) == 2);
1760 
1761 	/*
1762 	 * The child should report it's vfork() completion before it
1763 	 * exits.
1764 	 */
1765 	wpid = wait(&status);
1766 	ATF_REQUIRE(wpid == children[0]);
1767 	ATF_REQUIRE(WIFSTOPPED(status));
1768 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1769 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl[0], sizeof(pl[0])) !=
1770 	    -1);
1771 	ATF_REQUIRE((pl[0].pl_flags & PL_FLAG_VFORK_DONE) != 0);
1772 
1773 	ATF_REQUIRE(ptrace(PT_CONTINUE, children[0], (caddr_t)1, 0) != -1);
1774 
1775 	wpid = wait(&status);
1776 	ATF_REQUIRE(wpid == children[0]);
1777 	ATF_REQUIRE(WIFEXITED(status));
1778 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
1779 
1780 	wpid = wait(&status);
1781 	ATF_REQUIRE(wpid == -1);
1782 	ATF_REQUIRE(errno == ECHILD);
1783 }
1784 
1785 #ifdef HAVE_BREAKPOINT
1786 /*
1787  * Verify that no more events are reported after PT_KILL except for the
1788  * process exit when stopped due to a breakpoint trap.
1789  */
1790 ATF_TC_WITHOUT_HEAD(ptrace__PT_KILL_breakpoint);
ATF_TC_BODY(ptrace__PT_KILL_breakpoint,tc)1791 ATF_TC_BODY(ptrace__PT_KILL_breakpoint, tc)
1792 {
1793 	pid_t fpid, wpid;
1794 	int status;
1795 
1796 	ATF_REQUIRE((fpid = fork()) != -1);
1797 	if (fpid == 0) {
1798 		trace_me();
1799 		breakpoint();
1800 		exit(1);
1801 	}
1802 
1803 	/* The first wait() should report the stop from SIGSTOP. */
1804 	wpid = waitpid(fpid, &status, 0);
1805 	ATF_REQUIRE(wpid == fpid);
1806 	ATF_REQUIRE(WIFSTOPPED(status));
1807 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1808 
1809 	/* Continue the child ignoring the SIGSTOP. */
1810 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1811 
1812 	/* The second wait() should report hitting the breakpoint. */
1813 	wpid = waitpid(fpid, &status, 0);
1814 	ATF_REQUIRE(wpid == fpid);
1815 	ATF_REQUIRE(WIFSTOPPED(status));
1816 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1817 
1818 	/* Kill the child process. */
1819 	ATF_REQUIRE(ptrace(PT_KILL, fpid, 0, 0) == 0);
1820 
1821 	/* The last wait() should report the SIGKILL. */
1822 	wpid = waitpid(fpid, &status, 0);
1823 	ATF_REQUIRE(wpid == fpid);
1824 	ATF_REQUIRE(WIFSIGNALED(status));
1825 	ATF_REQUIRE(WTERMSIG(status) == SIGKILL);
1826 
1827 	wpid = wait(&status);
1828 	ATF_REQUIRE(wpid == -1);
1829 	ATF_REQUIRE(errno == ECHILD);
1830 }
1831 #endif /* HAVE_BREAKPOINT */
1832 
1833 /*
1834  * Verify that no more events are reported after PT_KILL except for the
1835  * process exit when stopped inside of a system call.
1836  */
1837 ATF_TC_WITHOUT_HEAD(ptrace__PT_KILL_system_call);
ATF_TC_BODY(ptrace__PT_KILL_system_call,tc)1838 ATF_TC_BODY(ptrace__PT_KILL_system_call, tc)
1839 {
1840 	struct ptrace_lwpinfo pl;
1841 	pid_t fpid, wpid;
1842 	int status;
1843 
1844 	ATF_REQUIRE((fpid = fork()) != -1);
1845 	if (fpid == 0) {
1846 		trace_me();
1847 		getpid();
1848 		exit(1);
1849 	}
1850 
1851 	/* The first wait() should report the stop from SIGSTOP. */
1852 	wpid = waitpid(fpid, &status, 0);
1853 	ATF_REQUIRE(wpid == fpid);
1854 	ATF_REQUIRE(WIFSTOPPED(status));
1855 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1856 
1857 	/* Continue the child ignoring the SIGSTOP and tracing system calls. */
1858 	ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
1859 
1860 	/* The second wait() should report a system call entry for getpid(). */
1861 	wpid = waitpid(fpid, &status, 0);
1862 	ATF_REQUIRE(wpid == fpid);
1863 	ATF_REQUIRE(WIFSTOPPED(status));
1864 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1865 
1866 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
1867 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SCE);
1868 
1869 	/* Kill the child process. */
1870 	ATF_REQUIRE(ptrace(PT_KILL, fpid, 0, 0) == 0);
1871 
1872 	/* The last wait() should report the SIGKILL. */
1873 	wpid = waitpid(fpid, &status, 0);
1874 	ATF_REQUIRE(wpid == fpid);
1875 	ATF_REQUIRE(WIFSIGNALED(status));
1876 	ATF_REQUIRE(WTERMSIG(status) == SIGKILL);
1877 
1878 	wpid = wait(&status);
1879 	ATF_REQUIRE(wpid == -1);
1880 	ATF_REQUIRE(errno == ECHILD);
1881 }
1882 
1883 /*
1884  * Verify that no more events are reported after PT_KILL except for the
1885  * process exit when killing a multithreaded process.
1886  */
1887 ATF_TC_WITHOUT_HEAD(ptrace__PT_KILL_threads);
ATF_TC_BODY(ptrace__PT_KILL_threads,tc)1888 ATF_TC_BODY(ptrace__PT_KILL_threads, tc)
1889 {
1890 	struct ptrace_lwpinfo pl;
1891 	pid_t fpid, wpid;
1892 	lwpid_t main_lwp;
1893 	int status;
1894 
1895 	ATF_REQUIRE((fpid = fork()) != -1);
1896 	if (fpid == 0) {
1897 		trace_me();
1898 		simple_thread_main();
1899 	}
1900 
1901 	/* The first wait() should report the stop from SIGSTOP. */
1902 	wpid = waitpid(fpid, &status, 0);
1903 	ATF_REQUIRE(wpid == fpid);
1904 	ATF_REQUIRE(WIFSTOPPED(status));
1905 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
1906 
1907 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
1908 	    sizeof(pl)) != -1);
1909 	main_lwp = pl.pl_lwpid;
1910 
1911 	ATF_REQUIRE(ptrace(PT_LWP_EVENTS, wpid, NULL, 1) == 0);
1912 
1913 	/* Continue the child ignoring the SIGSTOP. */
1914 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
1915 
1916 	/* The first event should be for the child thread's birth. */
1917 	wpid = waitpid(fpid, &status, 0);
1918 	ATF_REQUIRE(wpid == fpid);
1919 	ATF_REQUIRE(WIFSTOPPED(status));
1920 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
1921 
1922 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
1923 	ATF_REQUIRE((pl.pl_flags & (PL_FLAG_BORN | PL_FLAG_SCX)) ==
1924 	    (PL_FLAG_BORN | PL_FLAG_SCX));
1925 	ATF_REQUIRE(pl.pl_lwpid != main_lwp);
1926 
1927 	/* Kill the child process. */
1928 	ATF_REQUIRE(ptrace(PT_KILL, fpid, 0, 0) == 0);
1929 
1930 	/* The last wait() should report the SIGKILL. */
1931 	wpid = waitpid(fpid, &status, 0);
1932 	ATF_REQUIRE(wpid == fpid);
1933 	ATF_REQUIRE(WIFSIGNALED(status));
1934 	ATF_REQUIRE(WTERMSIG(status) == SIGKILL);
1935 
1936 	wpid = wait(&status);
1937 	ATF_REQUIRE(wpid == -1);
1938 	ATF_REQUIRE(errno == ECHILD);
1939 }
1940 
1941 static void *
mask_usr1_thread(void * arg)1942 mask_usr1_thread(void *arg)
1943 {
1944 	pthread_barrier_t *pbarrier;
1945 	sigset_t sigmask;
1946 
1947 	pbarrier = (pthread_barrier_t*)arg;
1948 
1949 	sigemptyset(&sigmask);
1950 	sigaddset(&sigmask, SIGUSR1);
1951 	CHILD_REQUIRE(pthread_sigmask(SIG_BLOCK, &sigmask, NULL) == 0);
1952 
1953 	/* Sync up with other thread after sigmask updated. */
1954 	pthread_barrier_wait(pbarrier);
1955 
1956 	for (;;)
1957 		sleep(60);
1958 
1959 	return (NULL);
1960 }
1961 
1962 /*
1963  * Verify that the SIGKILL from PT_KILL takes priority over other signals
1964  * and prevents spurious stops due to those other signals.
1965  */
1966 ATF_TC(ptrace__PT_KILL_competing_signal);
ATF_TC_HEAD(ptrace__PT_KILL_competing_signal,tc)1967 ATF_TC_HEAD(ptrace__PT_KILL_competing_signal, tc)
1968 {
1969 
1970 	atf_tc_set_md_var(tc, "require.user", "root");
1971 }
ATF_TC_BODY(ptrace__PT_KILL_competing_signal,tc)1972 ATF_TC_BODY(ptrace__PT_KILL_competing_signal, tc)
1973 {
1974 	pid_t fpid, wpid;
1975 	int status;
1976 	cpuset_t setmask;
1977 	pthread_t t;
1978 	pthread_barrier_t barrier;
1979 	struct sched_param sched_param;
1980 
1981 	ATF_REQUIRE((fpid = fork()) != -1);
1982 	if (fpid == 0) {
1983 		/* Bind to one CPU so only one thread at a time will run. */
1984 		CPU_ZERO(&setmask);
1985 		CPU_SET(0, &setmask);
1986 		cpusetid_t setid;
1987 		CHILD_REQUIRE(cpuset(&setid) == 0);
1988 		CHILD_REQUIRE(cpuset_setaffinity(CPU_LEVEL_CPUSET,
1989 		    CPU_WHICH_CPUSET, setid, sizeof(setmask), &setmask) == 0);
1990 
1991 		CHILD_REQUIRE(pthread_barrier_init(&barrier, NULL, 2) == 0);
1992 
1993 		CHILD_REQUIRE(pthread_create(&t, NULL, mask_usr1_thread,
1994 		    (void*)&barrier) == 0);
1995 
1996 		/*
1997 		 * Give the main thread higher priority. The test always
1998 		 * assumes that, if both threads are able to run, the main
1999 		 * thread runs first.
2000 		 */
2001 		sched_param.sched_priority =
2002 		    (sched_get_priority_max(SCHED_FIFO) +
2003 		    sched_get_priority_min(SCHED_FIFO)) / 2;
2004 		CHILD_REQUIRE(pthread_setschedparam(pthread_self(),
2005 		    SCHED_FIFO, &sched_param) == 0);
2006 		sched_param.sched_priority -= RQ_PPQ;
2007 		CHILD_REQUIRE(pthread_setschedparam(t, SCHED_FIFO,
2008 		    &sched_param) == 0);
2009 
2010 		sigset_t sigmask;
2011 		sigemptyset(&sigmask);
2012 		sigaddset(&sigmask, SIGUSR2);
2013 		CHILD_REQUIRE(pthread_sigmask(SIG_BLOCK, &sigmask, NULL) == 0);
2014 
2015 		/* Sync up with other thread after sigmask updated. */
2016 		pthread_barrier_wait(&barrier);
2017 
2018 		trace_me();
2019 
2020 		for (;;)
2021 			sleep(60);
2022 
2023 		exit(1);
2024 	}
2025 
2026 	/* The first wait() should report the stop from SIGSTOP. */
2027 	wpid = waitpid(fpid, &status, 0);
2028 	ATF_REQUIRE(wpid == fpid);
2029 	ATF_REQUIRE(WIFSTOPPED(status));
2030 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2031 
2032 	/* Continue the child ignoring the SIGSTOP. */
2033 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2034 
2035 	/* Send a signal that only the second thread can handle. */
2036 	ATF_REQUIRE(kill(fpid, SIGUSR2) == 0);
2037 
2038 	/* The second wait() should report the SIGUSR2. */
2039 	wpid = waitpid(fpid, &status, 0);
2040 	ATF_REQUIRE(wpid == fpid);
2041 	ATF_REQUIRE(WIFSTOPPED(status));
2042 	ATF_REQUIRE(WSTOPSIG(status) == SIGUSR2);
2043 
2044 	/* Send a signal that only the first thread can handle. */
2045 	ATF_REQUIRE(kill(fpid, SIGUSR1) == 0);
2046 
2047 	/* Replace the SIGUSR2 with a kill. */
2048 	ATF_REQUIRE(ptrace(PT_KILL, fpid, 0, 0) == 0);
2049 
2050 	/* The last wait() should report the SIGKILL (not the SIGUSR signal). */
2051 	wpid = waitpid(fpid, &status, 0);
2052 	ATF_REQUIRE(wpid == fpid);
2053 	ATF_REQUIRE(WIFSIGNALED(status));
2054 	ATF_REQUIRE(WTERMSIG(status) == SIGKILL);
2055 
2056 	wpid = wait(&status);
2057 	ATF_REQUIRE(wpid == -1);
2058 	ATF_REQUIRE(errno == ECHILD);
2059 }
2060 
2061 /*
2062  * Verify that the SIGKILL from PT_KILL takes priority over other stop events
2063  * and prevents spurious stops caused by those events.
2064  */
2065 ATF_TC(ptrace__PT_KILL_competing_stop);
ATF_TC_HEAD(ptrace__PT_KILL_competing_stop,tc)2066 ATF_TC_HEAD(ptrace__PT_KILL_competing_stop, tc)
2067 {
2068 
2069 	atf_tc_set_md_var(tc, "require.user", "root");
2070 }
ATF_TC_BODY(ptrace__PT_KILL_competing_stop,tc)2071 ATF_TC_BODY(ptrace__PT_KILL_competing_stop, tc)
2072 {
2073 	pid_t fpid, wpid;
2074 	int status;
2075 	cpuset_t setmask;
2076 	pthread_t t;
2077 	pthread_barrier_t barrier;
2078 	lwpid_t main_lwp;
2079 	struct ptrace_lwpinfo pl;
2080 	struct sched_param sched_param;
2081 
2082 	ATF_REQUIRE((fpid = fork()) != -1);
2083 	if (fpid == 0) {
2084 		trace_me();
2085 
2086 		/* Bind to one CPU so only one thread at a time will run. */
2087 		CPU_ZERO(&setmask);
2088 		CPU_SET(0, &setmask);
2089 		cpusetid_t setid;
2090 		CHILD_REQUIRE(cpuset(&setid) == 0);
2091 		CHILD_REQUIRE(cpuset_setaffinity(CPU_LEVEL_CPUSET,
2092 		    CPU_WHICH_CPUSET, setid, sizeof(setmask), &setmask) == 0);
2093 
2094 		CHILD_REQUIRE(pthread_barrier_init(&barrier, NULL, 2) == 0);
2095 
2096 		CHILD_REQUIRE(pthread_create(&t, NULL, mask_usr1_thread,
2097 		    (void*)&barrier) == 0);
2098 
2099 		/*
2100 		 * Give the main thread higher priority. The test always
2101 		 * assumes that, if both threads are able to run, the main
2102 		 * thread runs first.
2103 		 */
2104 		sched_param.sched_priority =
2105 		    (sched_get_priority_max(SCHED_FIFO) +
2106 		    sched_get_priority_min(SCHED_FIFO)) / 2;
2107 		CHILD_REQUIRE(pthread_setschedparam(pthread_self(),
2108 		    SCHED_FIFO, &sched_param) == 0);
2109 		sched_param.sched_priority -= RQ_PPQ;
2110 		CHILD_REQUIRE(pthread_setschedparam(t, SCHED_FIFO,
2111 		    &sched_param) == 0);
2112 
2113 		sigset_t sigmask;
2114 		sigemptyset(&sigmask);
2115 		sigaddset(&sigmask, SIGUSR2);
2116 		CHILD_REQUIRE(pthread_sigmask(SIG_BLOCK, &sigmask, NULL) == 0);
2117 
2118 		/* Sync up with other thread after sigmask updated. */
2119 		pthread_barrier_wait(&barrier);
2120 
2121 		/* Sync up with the test before doing the getpid(). */
2122 		raise(SIGSTOP);
2123 
2124 		getpid();
2125 		exit(1);
2126 	}
2127 
2128 	/* The first wait() should report the stop from SIGSTOP. */
2129 	wpid = waitpid(fpid, &status, 0);
2130 	ATF_REQUIRE(wpid == fpid);
2131 	ATF_REQUIRE(WIFSTOPPED(status));
2132 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2133 
2134 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2135 	main_lwp = pl.pl_lwpid;
2136 
2137 	/* Continue the child ignoring the SIGSTOP and tracing system calls. */
2138 	ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
2139 
2140 	/*
2141 	 * Continue until child is done with setup, which is indicated with
2142 	 * SIGSTOP. Ignore system calls in the meantime.
2143 	 */
2144 	for (;;) {
2145 		wpid = waitpid(fpid, &status, 0);
2146 		ATF_REQUIRE(wpid == fpid);
2147 		ATF_REQUIRE(WIFSTOPPED(status));
2148 		if (WSTOPSIG(status) == SIGTRAP) {
2149 			ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
2150 			    sizeof(pl)) != -1);
2151 			ATF_REQUIRE(pl.pl_flags & (PL_FLAG_SCE | PL_FLAG_SCX));
2152 		} else {
2153 			ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2154 			break;
2155 		}
2156 		ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
2157 	}
2158 
2159 	/* Proceed, allowing main thread to hit syscall entry for getpid(). */
2160 	ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
2161 
2162 	wpid = waitpid(fpid, &status, 0);
2163 	ATF_REQUIRE(wpid == fpid);
2164 	ATF_REQUIRE(WIFSTOPPED(status));
2165 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
2166 
2167 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
2168 	    sizeof(pl)) != -1);
2169 	ATF_REQUIRE(pl.pl_lwpid == main_lwp);
2170 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SCE);
2171 	/* Prevent the main thread from hitting its syscall exit for now. */
2172 	ATF_REQUIRE(ptrace(PT_SUSPEND, main_lwp, 0, 0) == 0);
2173 
2174 	/*
2175 	 * Proceed, allowing second thread to hit syscall exit for
2176 	 * pthread_barrier_wait().
2177 	 */
2178 	ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
2179 
2180 	wpid = waitpid(fpid, &status, 0);
2181 	ATF_REQUIRE(wpid == fpid);
2182 	ATF_REQUIRE(WIFSTOPPED(status));
2183 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
2184 
2185 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
2186 	    sizeof(pl)) != -1);
2187 	ATF_REQUIRE(pl.pl_lwpid != main_lwp);
2188 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SCX);
2189 
2190 	/* Send a signal that only the second thread can handle. */
2191 	ATF_REQUIRE(kill(fpid, SIGUSR2) == 0);
2192 
2193 	ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
2194 
2195 	/* The next wait() should report the SIGUSR2. */
2196 	wpid = waitpid(fpid, &status, 0);
2197 	ATF_REQUIRE(wpid == fpid);
2198 	ATF_REQUIRE(WIFSTOPPED(status));
2199 	ATF_REQUIRE(WSTOPSIG(status) == SIGUSR2);
2200 
2201 	/* Allow the main thread to try to finish its system call. */
2202 	ATF_REQUIRE(ptrace(PT_RESUME, main_lwp, 0, 0) == 0);
2203 
2204 	/*
2205 	 * At this point, the main thread is in the middle of a system call and
2206 	 * has been resumed. The second thread has taken a SIGUSR2 which will
2207 	 * be replaced with a SIGKILL below. The main thread will get to run
2208 	 * first. It should notice the kill request (even though the signal
2209 	 * replacement occurred in the other thread) and exit accordingly.  It
2210 	 * should not stop for the system call exit event.
2211 	 */
2212 
2213 	/* Replace the SIGUSR2 with a kill. */
2214 	ATF_REQUIRE(ptrace(PT_KILL, fpid, 0, 0) == 0);
2215 
2216 	/* The last wait() should report the SIGKILL (not a syscall exit). */
2217 	wpid = waitpid(fpid, &status, 0);
2218 	ATF_REQUIRE(wpid == fpid);
2219 	ATF_REQUIRE(WIFSIGNALED(status));
2220 	ATF_REQUIRE(WTERMSIG(status) == SIGKILL);
2221 
2222 	wpid = wait(&status);
2223 	ATF_REQUIRE(wpid == -1);
2224 	ATF_REQUIRE(errno == ECHILD);
2225 }
2226 
2227 static void
sigusr1_handler(int sig)2228 sigusr1_handler(int sig)
2229 {
2230 
2231 	CHILD_REQUIRE(sig == SIGUSR1);
2232 	_exit(2);
2233 }
2234 
2235 /*
2236  * Verify that even if the signal queue is full for a child process,
2237  * a PT_KILL will kill the process.
2238  */
2239 ATF_TC_WITHOUT_HEAD(ptrace__PT_KILL_with_signal_full_sigqueue);
ATF_TC_BODY(ptrace__PT_KILL_with_signal_full_sigqueue,tc)2240 ATF_TC_BODY(ptrace__PT_KILL_with_signal_full_sigqueue, tc)
2241 {
2242 	pid_t fpid, wpid;
2243 	int status;
2244 	int max_pending_per_proc;
2245 	size_t len;
2246 	int i;
2247 
2248 	ATF_REQUIRE(signal(SIGUSR1, sigusr1_handler) != SIG_ERR);
2249 
2250 	ATF_REQUIRE((fpid = fork()) != -1);
2251 	if (fpid == 0) {
2252 		trace_me();
2253 		exit(1);
2254 	}
2255 
2256 	/* The first wait() should report the stop from SIGSTOP. */
2257 	wpid = waitpid(fpid, &status, 0);
2258 	ATF_REQUIRE(wpid == fpid);
2259 	ATF_REQUIRE(WIFSTOPPED(status));
2260 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2261 
2262 	len = sizeof(max_pending_per_proc);
2263 	ATF_REQUIRE(sysctlbyname("kern.sigqueue.max_pending_per_proc",
2264 	    &max_pending_per_proc, &len, NULL, 0) == 0);
2265 
2266 	/* Fill the signal queue. */
2267 	for (i = 0; i < max_pending_per_proc; ++i)
2268 		ATF_REQUIRE(kill(fpid, SIGUSR1) == 0);
2269 
2270 	/* Kill the child process. */
2271 	ATF_REQUIRE(ptrace(PT_KILL, fpid, 0, 0) == 0);
2272 
2273 	/* The last wait() should report the SIGKILL. */
2274 	wpid = waitpid(fpid, &status, 0);
2275 	ATF_REQUIRE(wpid == fpid);
2276 	ATF_REQUIRE(WIFSIGNALED(status));
2277 	ATF_REQUIRE(WTERMSIG(status) == SIGKILL);
2278 
2279 	wpid = wait(&status);
2280 	ATF_REQUIRE(wpid == -1);
2281 	ATF_REQUIRE(errno == ECHILD);
2282 }
2283 
2284 /*
2285  * Verify that when stopped at a system call entry, a signal can be
2286  * requested with PT_CONTINUE which will be delivered once the system
2287  * call is complete.
2288  */
2289 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_with_signal_system_call_entry);
ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_system_call_entry,tc)2290 ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_system_call_entry, tc)
2291 {
2292 	struct ptrace_lwpinfo pl;
2293 	pid_t fpid, wpid;
2294 	int status;
2295 
2296 	ATF_REQUIRE(signal(SIGUSR1, sigusr1_handler) != SIG_ERR);
2297 
2298 	ATF_REQUIRE((fpid = fork()) != -1);
2299 	if (fpid == 0) {
2300 		trace_me();
2301 		getpid();
2302 		exit(1);
2303 	}
2304 
2305 	/* The first wait() should report the stop from SIGSTOP. */
2306 	wpid = waitpid(fpid, &status, 0);
2307 	ATF_REQUIRE(wpid == fpid);
2308 	ATF_REQUIRE(WIFSTOPPED(status));
2309 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2310 
2311 	/* Continue the child ignoring the SIGSTOP and tracing system calls. */
2312 	ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
2313 
2314 	/* The second wait() should report a system call entry for getpid(). */
2315 	wpid = waitpid(fpid, &status, 0);
2316 	ATF_REQUIRE(wpid == fpid);
2317 	ATF_REQUIRE(WIFSTOPPED(status));
2318 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
2319 
2320 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2321 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SCE);
2322 
2323 	/* Continue the child process with a signal. */
2324 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
2325 
2326 	for (;;) {
2327 		/*
2328 		 * The last wait() should report exit 2, i.e., a normal _exit
2329 		 * from the signal handler. In the meantime, catch and proceed
2330 		 * past any syscall stops.
2331 		 */
2332 		wpid = waitpid(fpid, &status, 0);
2333 		ATF_REQUIRE(wpid == fpid);
2334 		if (WIFSTOPPED(status) && WSTOPSIG(status) == SIGTRAP) {
2335 			ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2336 			ATF_REQUIRE(pl.pl_flags & (PL_FLAG_SCE | PL_FLAG_SCX));
2337 			ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2338 		} else {
2339 			ATF_REQUIRE(WIFEXITED(status));
2340 			ATF_REQUIRE(WEXITSTATUS(status) == 2);
2341 			break;
2342 		}
2343 	}
2344 
2345 	wpid = wait(&status);
2346 	ATF_REQUIRE(wpid == -1);
2347 	ATF_REQUIRE(errno == ECHILD);
2348 }
2349 
2350 static void
sigusr1_counting_handler(int sig)2351 sigusr1_counting_handler(int sig)
2352 {
2353 	static int counter = 0;
2354 
2355 	CHILD_REQUIRE(sig == SIGUSR1);
2356 	counter++;
2357 	if (counter == 2)
2358 		_exit(2);
2359 }
2360 
2361 /*
2362  * Verify that, when continuing from a stop at system call entry and exit,
2363  * a signal can be requested from both stops, and both will be delivered when
2364  * the system call is complete.
2365  */
2366 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_with_signal_system_call_entry_and_exit);
ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_system_call_entry_and_exit,tc)2367 ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_system_call_entry_and_exit, tc)
2368 {
2369 	struct ptrace_lwpinfo pl;
2370 	pid_t fpid, wpid;
2371 	int status;
2372 
2373 	ATF_REQUIRE(signal(SIGUSR1, sigusr1_counting_handler) != SIG_ERR);
2374 
2375 	ATF_REQUIRE((fpid = fork()) != -1);
2376 	if (fpid == 0) {
2377 		trace_me();
2378 		getpid();
2379 		exit(1);
2380 	}
2381 
2382 	/* The first wait() should report the stop from SIGSTOP. */
2383 	wpid = waitpid(fpid, &status, 0);
2384 	ATF_REQUIRE(wpid == fpid);
2385 	ATF_REQUIRE(WIFSTOPPED(status));
2386 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2387 
2388 	/* Continue the child ignoring the SIGSTOP and tracing system calls. */
2389 	ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
2390 
2391 	/* The second wait() should report a system call entry for getpid(). */
2392 	wpid = waitpid(fpid, &status, 0);
2393 	ATF_REQUIRE(wpid == fpid);
2394 	ATF_REQUIRE(WIFSTOPPED(status));
2395 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
2396 
2397 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2398 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SCE);
2399 
2400 	/* Continue the child process with a signal. */
2401 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
2402 
2403 	/* The third wait() should report a system call exit for getpid(). */
2404 	wpid = waitpid(fpid, &status, 0);
2405 	ATF_REQUIRE(wpid == fpid);
2406 	ATF_REQUIRE(WIFSTOPPED(status));
2407 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
2408 
2409 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2410 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SCX);
2411 
2412 	/* Continue the child process with a signal. */
2413 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
2414 
2415 	for (;;) {
2416 		/*
2417 		 * The last wait() should report exit 2, i.e., a normal _exit
2418 		 * from the signal handler. In the meantime, catch and proceed
2419 		 * past any syscall stops.
2420 		 */
2421 		wpid = waitpid(fpid, &status, 0);
2422 		ATF_REQUIRE(wpid == fpid);
2423 		if (WIFSTOPPED(status) && WSTOPSIG(status) == SIGTRAP) {
2424 			ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2425 			ATF_REQUIRE(pl.pl_flags & (PL_FLAG_SCE | PL_FLAG_SCX));
2426 			ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2427 		} else {
2428 			ATF_REQUIRE(WIFEXITED(status));
2429 			ATF_REQUIRE(WEXITSTATUS(status) == 2);
2430 			break;
2431 		}
2432 	}
2433 
2434 	wpid = wait(&status);
2435 	ATF_REQUIRE(wpid == -1);
2436 	ATF_REQUIRE(errno == ECHILD);
2437 }
2438 
2439 /*
2440  * Verify that even if the signal queue is full for a child process,
2441  * a PT_CONTINUE with a signal will not result in loss of that signal.
2442  */
2443 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_with_signal_full_sigqueue);
ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_full_sigqueue,tc)2444 ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_full_sigqueue, tc)
2445 {
2446 	pid_t fpid, wpid;
2447 	int status;
2448 	int max_pending_per_proc;
2449 	size_t len;
2450 	int i;
2451 
2452 	ATF_REQUIRE(signal(SIGUSR2, handler) != SIG_ERR);
2453 	ATF_REQUIRE(signal(SIGUSR1, sigusr1_handler) != SIG_ERR);
2454 
2455 	ATF_REQUIRE((fpid = fork()) != -1);
2456 	if (fpid == 0) {
2457 		trace_me();
2458 		exit(1);
2459 	}
2460 
2461 	/* The first wait() should report the stop from SIGSTOP. */
2462 	wpid = waitpid(fpid, &status, 0);
2463 	ATF_REQUIRE(wpid == fpid);
2464 	ATF_REQUIRE(WIFSTOPPED(status));
2465 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2466 
2467 	len = sizeof(max_pending_per_proc);
2468 	ATF_REQUIRE(sysctlbyname("kern.sigqueue.max_pending_per_proc",
2469 	    &max_pending_per_proc, &len, NULL, 0) == 0);
2470 
2471 	/* Fill the signal queue. */
2472 	for (i = 0; i < max_pending_per_proc; ++i)
2473 		ATF_REQUIRE(kill(fpid, SIGUSR2) == 0);
2474 
2475 	/* Continue with signal. */
2476 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
2477 
2478 	for (;;) {
2479 		wpid = waitpid(fpid, &status, 0);
2480 		ATF_REQUIRE(wpid == fpid);
2481 		if (WIFSTOPPED(status)) {
2482 			ATF_REQUIRE(WSTOPSIG(status) == SIGUSR2);
2483 			ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2484 		} else {
2485 			/*
2486 			 * The last wait() should report normal _exit from the
2487 			 * SIGUSR1 handler.
2488 			 */
2489 			ATF_REQUIRE(WIFEXITED(status));
2490 			ATF_REQUIRE(WEXITSTATUS(status) == 2);
2491 			break;
2492 		}
2493 	}
2494 
2495 	wpid = wait(&status);
2496 	ATF_REQUIRE(wpid == -1);
2497 	ATF_REQUIRE(errno == ECHILD);
2498 }
2499 
2500 static sem_t sigusr1_sem;
2501 static int got_usr1;
2502 
2503 static void
sigusr1_sempost_handler(int sig __unused)2504 sigusr1_sempost_handler(int sig __unused)
2505 {
2506 
2507 	got_usr1++;
2508 	CHILD_REQUIRE(sem_post(&sigusr1_sem) == 0);
2509 }
2510 
2511 /*
2512  * Verify that even if the signal queue is full for a child process,
2513  * and the signal is masked, a PT_CONTINUE with a signal will not
2514  * result in loss of that signal.
2515  */
2516 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_with_signal_masked_full_sigqueue);
ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_masked_full_sigqueue,tc)2517 ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_masked_full_sigqueue, tc)
2518 {
2519 	struct ptrace_lwpinfo pl;
2520 	pid_t fpid, wpid;
2521 	int status, err;
2522 	int max_pending_per_proc;
2523 	size_t len;
2524 	int i;
2525 	sigset_t sigmask;
2526 
2527 	ATF_REQUIRE(signal(SIGUSR2, handler) != SIG_ERR);
2528 	ATF_REQUIRE(sem_init(&sigusr1_sem, 0, 0) == 0);
2529 	ATF_REQUIRE(signal(SIGUSR1, sigusr1_sempost_handler) != SIG_ERR);
2530 
2531 	got_usr1 = 0;
2532 	ATF_REQUIRE((fpid = fork()) != -1);
2533 	if (fpid == 0) {
2534 		CHILD_REQUIRE(sigemptyset(&sigmask) == 0);
2535 		CHILD_REQUIRE(sigaddset(&sigmask, SIGUSR1) == 0);
2536 		CHILD_REQUIRE(sigprocmask(SIG_BLOCK, &sigmask, NULL) == 0);
2537 
2538 		trace_me();
2539 		CHILD_REQUIRE(got_usr1 == 0);
2540 
2541 		/* Allow the pending SIGUSR1 in now. */
2542 		CHILD_REQUIRE(sigprocmask(SIG_UNBLOCK, &sigmask, NULL) == 0);
2543 		/* Wait to receive the SIGUSR1. */
2544 		do {
2545 			err = sem_wait(&sigusr1_sem);
2546 			CHILD_REQUIRE(err == 0 || errno == EINTR);
2547 		} while (err != 0 && errno == EINTR);
2548 		CHILD_REQUIRE(got_usr1 == 1);
2549 		exit(1);
2550 	}
2551 
2552 	/* The first wait() should report the stop from SIGSTOP. */
2553 	wpid = waitpid(fpid, &status, 0);
2554 	ATF_REQUIRE(wpid == fpid);
2555 	ATF_REQUIRE(WIFSTOPPED(status));
2556 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2557 
2558 	len = sizeof(max_pending_per_proc);
2559 	ATF_REQUIRE(sysctlbyname("kern.sigqueue.max_pending_per_proc",
2560 	    &max_pending_per_proc, &len, NULL, 0) == 0);
2561 
2562 	/* Fill the signal queue. */
2563 	for (i = 0; i < max_pending_per_proc; ++i)
2564 		ATF_REQUIRE(kill(fpid, SIGUSR2) == 0);
2565 
2566 	/* Continue with signal. */
2567 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
2568 
2569 	/* Collect and ignore all of the SIGUSR2. */
2570 	for (i = 0; i < max_pending_per_proc; ++i) {
2571 		wpid = waitpid(fpid, &status, 0);
2572 		ATF_REQUIRE(wpid == fpid);
2573 		ATF_REQUIRE(WIFSTOPPED(status));
2574 		ATF_REQUIRE(WSTOPSIG(status) == SIGUSR2);
2575 		ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2576 	}
2577 
2578 	/* Now our PT_CONTINUE'd SIGUSR1 should cause a stop after unmask. */
2579 	wpid = waitpid(fpid, &status, 0);
2580 	ATF_REQUIRE(wpid == fpid);
2581 	ATF_REQUIRE(WIFSTOPPED(status));
2582 	ATF_REQUIRE(WSTOPSIG(status) == SIGUSR1);
2583 	ATF_REQUIRE(ptrace(PT_LWPINFO, fpid, (caddr_t)&pl, sizeof(pl)) != -1);
2584 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGUSR1);
2585 
2586 	/* Continue the child, ignoring the SIGUSR1. */
2587 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2588 
2589 	/* The last wait() should report exit after receiving SIGUSR1. */
2590 	wpid = waitpid(fpid, &status, 0);
2591 	ATF_REQUIRE(wpid == fpid);
2592 	ATF_REQUIRE(WIFEXITED(status));
2593 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
2594 
2595 	wpid = wait(&status);
2596 	ATF_REQUIRE(wpid == -1);
2597 	ATF_REQUIRE(errno == ECHILD);
2598 }
2599 
2600 /*
2601  * Verify that, after stopping due to a signal, that signal can be
2602  * replaced with another signal.
2603  */
2604 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_change_sig);
ATF_TC_BODY(ptrace__PT_CONTINUE_change_sig,tc)2605 ATF_TC_BODY(ptrace__PT_CONTINUE_change_sig, tc)
2606 {
2607 	struct ptrace_lwpinfo pl;
2608 	pid_t fpid, wpid;
2609 	int status;
2610 
2611 	ATF_REQUIRE((fpid = fork()) != -1);
2612 	if (fpid == 0) {
2613 		trace_me();
2614 		sleep(20);
2615 		exit(1);
2616 	}
2617 
2618 	/* The first wait() should report the stop from SIGSTOP. */
2619 	wpid = waitpid(fpid, &status, 0);
2620 	ATF_REQUIRE(wpid == fpid);
2621 	ATF_REQUIRE(WIFSTOPPED(status));
2622 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2623 
2624 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2625 
2626 	/* Send a signal without ptrace. */
2627 	ATF_REQUIRE(kill(fpid, SIGINT) == 0);
2628 
2629 	/* The second wait() should report a SIGINT was received. */
2630 	wpid = waitpid(fpid, &status, 0);
2631 	ATF_REQUIRE(wpid == fpid);
2632 	ATF_REQUIRE(WIFSTOPPED(status));
2633 	ATF_REQUIRE(WSTOPSIG(status) == SIGINT);
2634 
2635 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2636 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SI);
2637 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGINT);
2638 
2639 	/* Continue the child process with a different signal. */
2640 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGTERM) == 0);
2641 
2642 	/*
2643 	 * The last wait() should report having died due to the new
2644 	 * signal, SIGTERM.
2645 	 */
2646 	wpid = waitpid(fpid, &status, 0);
2647 	ATF_REQUIRE(wpid == fpid);
2648 	ATF_REQUIRE(WIFSIGNALED(status));
2649 	ATF_REQUIRE(WTERMSIG(status) == SIGTERM);
2650 
2651 	wpid = wait(&status);
2652 	ATF_REQUIRE(wpid == -1);
2653 	ATF_REQUIRE(errno == ECHILD);
2654 }
2655 
2656 /*
2657  * Verify that a signal can be passed through to the child even when there
2658  * was no true signal originally. Such cases arise when a SIGTRAP is
2659  * invented for e.g, system call stops.
2660  */
2661 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_with_sigtrap_system_call_entry);
ATF_TC_BODY(ptrace__PT_CONTINUE_with_sigtrap_system_call_entry,tc)2662 ATF_TC_BODY(ptrace__PT_CONTINUE_with_sigtrap_system_call_entry, tc)
2663 {
2664 	struct ptrace_lwpinfo pl;
2665 	struct rlimit rl;
2666 	pid_t fpid, wpid;
2667 	int status;
2668 
2669 	ATF_REQUIRE((fpid = fork()) != -1);
2670 	if (fpid == 0) {
2671 		trace_me();
2672 		/* SIGTRAP expected to cause exit on syscall entry. */
2673 		rl.rlim_cur = rl.rlim_max = 0;
2674 		ATF_REQUIRE(setrlimit(RLIMIT_CORE, &rl) == 0);
2675 		getpid();
2676 		exit(1);
2677 	}
2678 
2679 	/* The first wait() should report the stop from SIGSTOP. */
2680 	wpid = waitpid(fpid, &status, 0);
2681 	ATF_REQUIRE(wpid == fpid);
2682 	ATF_REQUIRE(WIFSTOPPED(status));
2683 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2684 
2685 	/* Continue the child ignoring the SIGSTOP and tracing system calls. */
2686 	ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
2687 
2688 	/* The second wait() should report a system call entry for getpid(). */
2689 	wpid = waitpid(fpid, &status, 0);
2690 	ATF_REQUIRE(wpid == fpid);
2691 	ATF_REQUIRE(WIFSTOPPED(status));
2692 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
2693 
2694 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2695 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SCE);
2696 
2697 	/* Continue the child process with a SIGTRAP. */
2698 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGTRAP) == 0);
2699 
2700 	for (;;) {
2701 		/*
2702 		 * The last wait() should report exit due to SIGTRAP.  In the
2703 		 * meantime, catch and proceed past any syscall stops.
2704 		 */
2705 		wpid = waitpid(fpid, &status, 0);
2706 		ATF_REQUIRE(wpid == fpid);
2707 		if (WIFSTOPPED(status) && WSTOPSIG(status) == SIGTRAP) {
2708 			ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2709 			ATF_REQUIRE(pl.pl_flags & (PL_FLAG_SCE | PL_FLAG_SCX));
2710 			ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2711 		} else {
2712 			ATF_REQUIRE(WIFSIGNALED(status));
2713 			ATF_REQUIRE(WTERMSIG(status) == SIGTRAP);
2714 			break;
2715 		}
2716 	}
2717 
2718 	wpid = wait(&status);
2719 	ATF_REQUIRE(wpid == -1);
2720 	ATF_REQUIRE(errno == ECHILD);
2721 
2722 }
2723 
2724 /*
2725  * A mixed bag PT_CONTINUE with signal test.
2726  */
2727 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_with_signal_mix);
ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_mix,tc)2728 ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_mix, tc)
2729 {
2730 	struct ptrace_lwpinfo pl;
2731 	pid_t fpid, wpid;
2732 	int status;
2733 
2734 	ATF_REQUIRE(signal(SIGUSR1, sigusr1_counting_handler) != SIG_ERR);
2735 
2736 	ATF_REQUIRE((fpid = fork()) != -1);
2737 	if (fpid == 0) {
2738 		trace_me();
2739 		getpid();
2740 		exit(1);
2741 	}
2742 
2743 	/* The first wait() should report the stop from SIGSTOP. */
2744 	wpid = waitpid(fpid, &status, 0);
2745 	ATF_REQUIRE(wpid == fpid);
2746 	ATF_REQUIRE(WIFSTOPPED(status));
2747 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2748 
2749 	/* Continue the child ignoring the SIGSTOP and tracing system calls. */
2750 	ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
2751 
2752 	/* The second wait() should report a system call entry for getpid(). */
2753 	wpid = waitpid(fpid, &status, 0);
2754 	ATF_REQUIRE(wpid == fpid);
2755 	ATF_REQUIRE(WIFSTOPPED(status));
2756 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
2757 
2758 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2759 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SCE);
2760 
2761 	/* Continue with the first SIGUSR1. */
2762 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
2763 
2764 	/* The next wait() should report a system call exit for getpid(). */
2765 	wpid = waitpid(fpid, &status, 0);
2766 	ATF_REQUIRE(wpid == fpid);
2767 	ATF_REQUIRE(WIFSTOPPED(status));
2768 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
2769 
2770 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2771 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SCX);
2772 
2773 	/* Send an ABRT without ptrace. */
2774 	ATF_REQUIRE(kill(fpid, SIGABRT) == 0);
2775 
2776 	/* Continue normally. */
2777 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2778 
2779 	/* The next wait() should report the SIGABRT. */
2780 	wpid = waitpid(fpid, &status, 0);
2781 	ATF_REQUIRE(wpid == fpid);
2782 	ATF_REQUIRE(WIFSTOPPED(status));
2783 	ATF_REQUIRE(WSTOPSIG(status) == SIGABRT);
2784 
2785 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2786 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SI);
2787 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGABRT);
2788 
2789 	/* Continue, replacing the SIGABRT with another SIGUSR1. */
2790 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
2791 
2792 	for (;;) {
2793 		/*
2794 		 * The last wait() should report exit 2, i.e., a normal _exit
2795 		 * from the signal handler. In the meantime, catch and proceed
2796 		 * past any syscall stops.
2797 		 */
2798 		wpid = waitpid(fpid, &status, 0);
2799 		ATF_REQUIRE(wpid == fpid);
2800 		if (WIFSTOPPED(status) && WSTOPSIG(status) == SIGTRAP) {
2801 			ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
2802 			ATF_REQUIRE(pl.pl_flags & (PL_FLAG_SCE | PL_FLAG_SCX));
2803 			ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2804 		} else {
2805 			ATF_REQUIRE(WIFEXITED(status));
2806 			ATF_REQUIRE(WEXITSTATUS(status) == 2);
2807 			break;
2808 		}
2809 	}
2810 
2811 	wpid = wait(&status);
2812 	ATF_REQUIRE(wpid == -1);
2813 	ATF_REQUIRE(errno == ECHILD);
2814 
2815 }
2816 
2817 /*
2818  * Verify a signal delivered by ptrace is noticed by kevent(2).
2819  */
2820 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_with_signal_kqueue);
ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_kqueue,tc)2821 ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_kqueue, tc)
2822 {
2823 	pid_t fpid, wpid;
2824 	int status, kq, nevents;
2825 	struct kevent kev;
2826 
2827 	ATF_REQUIRE(signal(SIGUSR1, SIG_IGN) != SIG_ERR);
2828 
2829 	ATF_REQUIRE((fpid = fork()) != -1);
2830 	if (fpid == 0) {
2831 		CHILD_REQUIRE((kq = kqueue()) > 0);
2832 		EV_SET(&kev, SIGUSR1, EVFILT_SIGNAL, EV_ADD, 0, 0, 0);
2833 		CHILD_REQUIRE(kevent(kq, &kev, 1, NULL, 0, NULL) == 0);
2834 
2835 		trace_me();
2836 
2837 		for (;;) {
2838 			nevents = kevent(kq, NULL, 0, &kev, 1, NULL);
2839 			if (nevents == -1 && errno == EINTR)
2840 				continue;
2841 			CHILD_REQUIRE(nevents > 0);
2842 			CHILD_REQUIRE(kev.filter == EVFILT_SIGNAL);
2843 			CHILD_REQUIRE(kev.ident == SIGUSR1);
2844 			break;
2845 		}
2846 
2847 		exit(1);
2848 	}
2849 
2850 	/* The first wait() should report the stop from SIGSTOP. */
2851 	wpid = waitpid(fpid, &status, 0);
2852 	ATF_REQUIRE(wpid == fpid);
2853 	ATF_REQUIRE(WIFSTOPPED(status));
2854 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2855 
2856 	/* Continue with the SIGUSR1. */
2857 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
2858 
2859 	/*
2860 	 * The last wait() should report normal exit with code 1.
2861 	 */
2862 	wpid = waitpid(fpid, &status, 0);
2863 	ATF_REQUIRE(wpid == fpid);
2864 	ATF_REQUIRE(WIFEXITED(status));
2865 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
2866 
2867 	wpid = wait(&status);
2868 	ATF_REQUIRE(wpid == -1);
2869 	ATF_REQUIRE(errno == ECHILD);
2870 }
2871 
2872 static void *
signal_thread(void * arg)2873 signal_thread(void *arg)
2874 {
2875 	int err;
2876 	sigset_t sigmask;
2877 
2878 	pthread_barrier_t *pbarrier = (pthread_barrier_t*)arg;
2879 
2880 	/* Wait for this thread to receive a SIGUSR1. */
2881 	do {
2882 		err = sem_wait(&sigusr1_sem);
2883 		CHILD_REQUIRE(err == 0 || errno == EINTR);
2884 	} while (err != 0 && errno == EINTR);
2885 
2886 	/* Free our companion thread from the barrier. */
2887 	pthread_barrier_wait(pbarrier);
2888 
2889 	/*
2890 	 * Swap ignore duties; the next SIGUSR1 should go to the
2891 	 * other thread.
2892 	 */
2893 	CHILD_REQUIRE(sigemptyset(&sigmask) == 0);
2894 	CHILD_REQUIRE(sigaddset(&sigmask, SIGUSR1) == 0);
2895 	CHILD_REQUIRE(pthread_sigmask(SIG_BLOCK, &sigmask, NULL) == 0);
2896 
2897 	/* Sync up threads after swapping signal masks. */
2898 	pthread_barrier_wait(pbarrier);
2899 
2900 	/* Wait until our companion has received its SIGUSR1. */
2901 	pthread_barrier_wait(pbarrier);
2902 
2903 	return (NULL);
2904 }
2905 
2906 /*
2907  * Verify that a traced process with blocked signal received the
2908  * signal from kill() once unmasked.
2909  */
2910 ATF_TC_WITHOUT_HEAD(ptrace__killed_with_sigmask);
ATF_TC_BODY(ptrace__killed_with_sigmask,tc)2911 ATF_TC_BODY(ptrace__killed_with_sigmask, tc)
2912 {
2913 	struct ptrace_lwpinfo pl;
2914 	pid_t fpid, wpid;
2915 	int status, err;
2916 	sigset_t sigmask;
2917 
2918 	ATF_REQUIRE(sem_init(&sigusr1_sem, 0, 0) == 0);
2919 	ATF_REQUIRE(signal(SIGUSR1, sigusr1_sempost_handler) != SIG_ERR);
2920 	got_usr1 = 0;
2921 
2922 	ATF_REQUIRE((fpid = fork()) != -1);
2923 	if (fpid == 0) {
2924 		CHILD_REQUIRE(sigemptyset(&sigmask) == 0);
2925 		CHILD_REQUIRE(sigaddset(&sigmask, SIGUSR1) == 0);
2926 		CHILD_REQUIRE(sigprocmask(SIG_BLOCK, &sigmask, NULL) == 0);
2927 
2928 		trace_me();
2929 		CHILD_REQUIRE(got_usr1 == 0);
2930 
2931 		/* Allow the pending SIGUSR1 in now. */
2932 		CHILD_REQUIRE(sigprocmask(SIG_UNBLOCK, &sigmask, NULL) == 0);
2933 		/* Wait to receive a SIGUSR1. */
2934 		do {
2935 			err = sem_wait(&sigusr1_sem);
2936 			CHILD_REQUIRE(err == 0 || errno == EINTR);
2937 		} while (err != 0 && errno == EINTR);
2938 		CHILD_REQUIRE(got_usr1 == 1);
2939 		exit(1);
2940 	}
2941 
2942 	/* The first wait() should report the stop from SIGSTOP. */
2943 	wpid = waitpid(fpid, &status, 0);
2944 	ATF_REQUIRE(wpid == fpid);
2945 	ATF_REQUIRE(WIFSTOPPED(status));
2946 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
2947 	ATF_REQUIRE(ptrace(PT_LWPINFO, fpid, (caddr_t)&pl, sizeof(pl)) != -1);
2948 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGSTOP);
2949 
2950 	/* Send blocked SIGUSR1 which should cause a stop. */
2951 	ATF_REQUIRE(kill(fpid, SIGUSR1) == 0);
2952 
2953 	/* Continue the child ignoring the SIGSTOP. */
2954 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
2955 
2956 	/* The next wait() should report the kill(SIGUSR1) was received. */
2957 	wpid = waitpid(fpid, &status, 0);
2958 	ATF_REQUIRE(wpid == fpid);
2959 	ATF_REQUIRE(WIFSTOPPED(status));
2960 	ATF_REQUIRE(WSTOPSIG(status) == SIGUSR1);
2961 	ATF_REQUIRE(ptrace(PT_LWPINFO, fpid, (caddr_t)&pl, sizeof(pl)) != -1);
2962 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGUSR1);
2963 
2964 	/* Continue the child, allowing in the SIGUSR1. */
2965 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
2966 
2967 	/* The last wait() should report normal exit with code 1. */
2968 	wpid = waitpid(fpid, &status, 0);
2969 	ATF_REQUIRE(wpid == fpid);
2970 	ATF_REQUIRE(WIFEXITED(status));
2971 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
2972 
2973 	wpid = wait(&status);
2974 	ATF_REQUIRE(wpid == -1);
2975 	ATF_REQUIRE(errno == ECHILD);
2976 }
2977 
2978 /*
2979  * Verify that a traced process with blocked signal received the
2980  * signal from PT_CONTINUE once unmasked.
2981  */
2982 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_with_sigmask);
ATF_TC_BODY(ptrace__PT_CONTINUE_with_sigmask,tc)2983 ATF_TC_BODY(ptrace__PT_CONTINUE_with_sigmask, tc)
2984 {
2985 	struct ptrace_lwpinfo pl;
2986 	pid_t fpid, wpid;
2987 	int status, err;
2988 	sigset_t sigmask;
2989 
2990 	ATF_REQUIRE(sem_init(&sigusr1_sem, 0, 0) == 0);
2991 	ATF_REQUIRE(signal(SIGUSR1, sigusr1_sempost_handler) != SIG_ERR);
2992 	got_usr1 = 0;
2993 
2994 	ATF_REQUIRE((fpid = fork()) != -1);
2995 	if (fpid == 0) {
2996 		CHILD_REQUIRE(sigemptyset(&sigmask) == 0);
2997 		CHILD_REQUIRE(sigaddset(&sigmask, SIGUSR1) == 0);
2998 		CHILD_REQUIRE(sigprocmask(SIG_BLOCK, &sigmask, NULL) == 0);
2999 
3000 		trace_me();
3001 		CHILD_REQUIRE(got_usr1 == 0);
3002 
3003 		/* Allow the pending SIGUSR1 in now. */
3004 		CHILD_REQUIRE(sigprocmask(SIG_UNBLOCK, &sigmask, NULL) == 0);
3005 		/* Wait to receive a SIGUSR1. */
3006 		do {
3007 			err = sem_wait(&sigusr1_sem);
3008 			CHILD_REQUIRE(err == 0 || errno == EINTR);
3009 		} while (err != 0 && errno == EINTR);
3010 
3011 		CHILD_REQUIRE(got_usr1 == 1);
3012 		exit(1);
3013 	}
3014 
3015 	/* The first wait() should report the stop from SIGSTOP. */
3016 	wpid = waitpid(fpid, &status, 0);
3017 	ATF_REQUIRE(wpid == fpid);
3018 	ATF_REQUIRE(WIFSTOPPED(status));
3019 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3020 	ATF_REQUIRE(ptrace(PT_LWPINFO, fpid, (caddr_t)&pl, sizeof(pl)) != -1);
3021 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGSTOP);
3022 
3023 	/* Continue the child replacing SIGSTOP with SIGUSR1. */
3024 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
3025 
3026 	/* The next wait() should report the SIGUSR1 was received. */
3027 	wpid = waitpid(fpid, &status, 0);
3028 	ATF_REQUIRE(wpid == fpid);
3029 	ATF_REQUIRE(WIFSTOPPED(status));
3030 	ATF_REQUIRE(WSTOPSIG(status) == SIGUSR1);
3031 	ATF_REQUIRE(ptrace(PT_LWPINFO, fpid, (caddr_t)&pl, sizeof(pl)) != -1);
3032 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGUSR1);
3033 
3034 	/* Continue the child, ignoring the SIGUSR1. */
3035 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3036 
3037 	/* The last wait() should report normal exit with code 1. */
3038 	wpid = waitpid(fpid, &status, 0);
3039 	ATF_REQUIRE(wpid == fpid);
3040 	ATF_REQUIRE(WIFEXITED(status));
3041 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
3042 
3043 	wpid = wait(&status);
3044 	ATF_REQUIRE(wpid == -1);
3045 	ATF_REQUIRE(errno == ECHILD);
3046 }
3047 
3048 /*
3049  * Verify that if ptrace stops due to a signal but continues with
3050  * a different signal that the new signal is routed to a thread
3051  * that can accept it, and that the thread is awakened by the signal
3052  * in a timely manner.
3053  */
3054 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_with_signal_thread_sigmask);
ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_thread_sigmask,tc)3055 ATF_TC_BODY(ptrace__PT_CONTINUE_with_signal_thread_sigmask, tc)
3056 {
3057 	pid_t fpid, wpid;
3058 	int status, err;
3059 	pthread_t t;
3060 	sigset_t sigmask;
3061 	pthread_barrier_t barrier;
3062 
3063 	ATF_REQUIRE(pthread_barrier_init(&barrier, NULL, 2) == 0);
3064 	ATF_REQUIRE(sem_init(&sigusr1_sem, 0, 0) == 0);
3065 	ATF_REQUIRE(signal(SIGUSR1, sigusr1_sempost_handler) != SIG_ERR);
3066 
3067 	ATF_REQUIRE((fpid = fork()) != -1);
3068 	if (fpid == 0) {
3069 		CHILD_REQUIRE(pthread_create(&t, NULL, signal_thread, (void*)&barrier) == 0);
3070 
3071 		/* The other thread should receive the first SIGUSR1. */
3072 		CHILD_REQUIRE(sigemptyset(&sigmask) == 0);
3073 		CHILD_REQUIRE(sigaddset(&sigmask, SIGUSR1) == 0);
3074 		CHILD_REQUIRE(pthread_sigmask(SIG_BLOCK, &sigmask, NULL) == 0);
3075 
3076 		trace_me();
3077 
3078 		/* Wait until other thread has received its SIGUSR1. */
3079 		pthread_barrier_wait(&barrier);
3080 
3081 		/*
3082 		 * Swap ignore duties; the next SIGUSR1 should go to this
3083 		 * thread.
3084 		 */
3085 		CHILD_REQUIRE(pthread_sigmask(SIG_UNBLOCK, &sigmask, NULL) == 0);
3086 
3087 		/* Sync up threads after swapping signal masks. */
3088 		pthread_barrier_wait(&barrier);
3089 
3090 		/*
3091 		 * Sync up with test code; we're ready for the next SIGUSR1
3092 		 * now.
3093 		 */
3094 		raise(SIGSTOP);
3095 
3096 		/* Wait for this thread to receive a SIGUSR1. */
3097 		do {
3098 			err = sem_wait(&sigusr1_sem);
3099 			CHILD_REQUIRE(err == 0 || errno == EINTR);
3100 		} while (err != 0 && errno == EINTR);
3101 
3102 		/* Free the other thread from the barrier. */
3103 		pthread_barrier_wait(&barrier);
3104 
3105 		CHILD_REQUIRE(pthread_join(t, NULL) == 0);
3106 
3107 		exit(1);
3108 	}
3109 
3110 	/* The first wait() should report the stop from SIGSTOP. */
3111 	wpid = waitpid(fpid, &status, 0);
3112 	ATF_REQUIRE(wpid == fpid);
3113 	ATF_REQUIRE(WIFSTOPPED(status));
3114 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3115 
3116 	/* Continue the child ignoring the SIGSTOP. */
3117 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3118 
3119 	/*
3120 	 * Send a signal without ptrace that either thread will accept (USR2,
3121 	 * in this case).
3122 	 */
3123 	ATF_REQUIRE(kill(fpid, SIGUSR2) == 0);
3124 
3125 	/* The second wait() should report a SIGUSR2 was received. */
3126 	wpid = waitpid(fpid, &status, 0);
3127 	ATF_REQUIRE(wpid == fpid);
3128 	ATF_REQUIRE(WIFSTOPPED(status));
3129 	ATF_REQUIRE(WSTOPSIG(status) == SIGUSR2);
3130 
3131 	/* Continue the child, changing the signal to USR1. */
3132 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
3133 
3134 	/* The next wait() should report the stop from SIGSTOP. */
3135 	wpid = waitpid(fpid, &status, 0);
3136 	ATF_REQUIRE(wpid == fpid);
3137 	ATF_REQUIRE(WIFSTOPPED(status));
3138 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3139 
3140 	/* Continue the child ignoring the SIGSTOP. */
3141 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3142 
3143 	ATF_REQUIRE(kill(fpid, SIGUSR2) == 0);
3144 
3145 	/* The next wait() should report a SIGUSR2 was received. */
3146 	wpid = waitpid(fpid, &status, 0);
3147 	ATF_REQUIRE(wpid == fpid);
3148 	ATF_REQUIRE(WIFSTOPPED(status));
3149 	ATF_REQUIRE(WSTOPSIG(status) == SIGUSR2);
3150 
3151 	/* Continue the child, changing the signal to USR1. */
3152 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, SIGUSR1) == 0);
3153 
3154 	/* The last wait() should report normal exit with code 1. */
3155 	wpid = waitpid(fpid, &status, 0);
3156 	ATF_REQUIRE(wpid == fpid);
3157 	ATF_REQUIRE(WIFEXITED(status));
3158 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
3159 
3160 	wpid = wait(&status);
3161 	ATF_REQUIRE(wpid == -1);
3162 	ATF_REQUIRE(errno == ECHILD);
3163 }
3164 
3165 static void *
raise_sigstop_thread(void * arg __unused)3166 raise_sigstop_thread(void *arg __unused)
3167 {
3168 
3169 	raise(SIGSTOP);
3170 	return NULL;
3171 }
3172 
3173 static void *
sleep_thread(void * arg __unused)3174 sleep_thread(void *arg __unused)
3175 {
3176 
3177 	sleep(60);
3178 	return NULL;
3179 }
3180 
3181 static void
terminate_with_pending_sigstop(bool sigstop_from_main_thread)3182 terminate_with_pending_sigstop(bool sigstop_from_main_thread)
3183 {
3184 	pid_t fpid, wpid;
3185 	int status, i;
3186 	cpuset_t setmask;
3187 	cpusetid_t setid;
3188 	pthread_t t;
3189 
3190 	/*
3191 	 * Become the reaper for this process tree. We need to be able to check
3192 	 * that both child and grandchild have died.
3193 	 */
3194 	ATF_REQUIRE(procctl(P_PID, getpid(), PROC_REAP_ACQUIRE, NULL) == 0);
3195 
3196 	fpid = fork();
3197 	ATF_REQUIRE(fpid >= 0);
3198 	if (fpid == 0) {
3199 		fpid = fork();
3200 		CHILD_REQUIRE(fpid >= 0);
3201 		if (fpid == 0) {
3202 			trace_me();
3203 
3204 			/* Pin to CPU 0 to serialize thread execution. */
3205 			CPU_ZERO(&setmask);
3206 			CPU_SET(0, &setmask);
3207 			CHILD_REQUIRE(cpuset(&setid) == 0);
3208 			CHILD_REQUIRE(cpuset_setaffinity(CPU_LEVEL_CPUSET,
3209 			    CPU_WHICH_CPUSET, setid,
3210 			    sizeof(setmask), &setmask) == 0);
3211 
3212 			if (sigstop_from_main_thread) {
3213 				/*
3214 				 * We expect the SIGKILL sent when our parent
3215 				 * dies to be delivered to the new thread.
3216 				 * Raise the SIGSTOP in this thread so the
3217 				 * threads compete.
3218 				 */
3219 				CHILD_REQUIRE(pthread_create(&t, NULL,
3220 				    sleep_thread, NULL) == 0);
3221 				raise(SIGSTOP);
3222 			} else {
3223 				/*
3224 				 * We expect the SIGKILL to be delivered to
3225 				 * this thread. After creating the new thread,
3226 				 * just get off the CPU so the other thread can
3227 				 * raise the SIGSTOP.
3228 				 */
3229 				CHILD_REQUIRE(pthread_create(&t, NULL,
3230 				    raise_sigstop_thread, NULL) == 0);
3231 				sleep(60);
3232 			}
3233 
3234 			exit(0);
3235 		}
3236 		/* First stop is trace_me() immediately after fork. */
3237 		wpid = waitpid(fpid, &status, 0);
3238 		CHILD_REQUIRE(wpid == fpid);
3239 		CHILD_REQUIRE(WIFSTOPPED(status));
3240 		CHILD_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3241 
3242 		CHILD_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3243 
3244 		/* Second stop is from the raise(SIGSTOP). */
3245 		wpid = waitpid(fpid, &status, 0);
3246 		CHILD_REQUIRE(wpid == fpid);
3247 		CHILD_REQUIRE(WIFSTOPPED(status));
3248 		CHILD_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3249 
3250 		/*
3251 		 * Terminate tracing process without detaching. Our child
3252 		 * should be killed.
3253 		 */
3254 		exit(0);
3255 	}
3256 
3257 	/*
3258 	 * We should get a normal exit from our immediate child and a SIGKILL
3259 	 * exit from our grandchild. The latter case is the interesting one.
3260 	 * Our grandchild should not have stopped due to the SIGSTOP that was
3261 	 * left dangling when its parent died.
3262 	 */
3263 	for (i = 0; i < 2; ++i) {
3264 		wpid = wait(&status);
3265 		if (wpid == fpid)
3266 			ATF_REQUIRE(WIFEXITED(status) &&
3267 			    WEXITSTATUS(status) == 0);
3268 		else
3269 			ATF_REQUIRE(WIFSIGNALED(status) &&
3270 			    WTERMSIG(status) == SIGKILL);
3271 	}
3272 }
3273 
3274 /*
3275  * These two tests ensure that if the tracing process exits without detaching
3276  * just after the child received a SIGSTOP, the child is cleanly killed and
3277  * doesn't go to sleep due to the SIGSTOP. The parent's death will send a
3278  * SIGKILL to the child. If the SIGKILL and the SIGSTOP are handled by
3279  * different threads, the SIGKILL must win.  There are two variants of this
3280  * test, designed to catch the case where the SIGKILL is delivered to the
3281  * younger thread (the first test) and the case where the SIGKILL is delivered
3282  * to the older thread (the second test). This behavior has changed in the
3283  * past, so make no assumption.
3284  */
3285 ATF_TC(ptrace__parent_terminate_with_pending_sigstop1);
ATF_TC_HEAD(ptrace__parent_terminate_with_pending_sigstop1,tc)3286 ATF_TC_HEAD(ptrace__parent_terminate_with_pending_sigstop1, tc)
3287 {
3288 
3289 	atf_tc_set_md_var(tc, "require.user", "root");
3290 }
ATF_TC_BODY(ptrace__parent_terminate_with_pending_sigstop1,tc)3291 ATF_TC_BODY(ptrace__parent_terminate_with_pending_sigstop1, tc)
3292 {
3293 
3294 	terminate_with_pending_sigstop(true);
3295 }
3296 
3297 ATF_TC(ptrace__parent_terminate_with_pending_sigstop2);
ATF_TC_HEAD(ptrace__parent_terminate_with_pending_sigstop2,tc)3298 ATF_TC_HEAD(ptrace__parent_terminate_with_pending_sigstop2, tc)
3299 {
3300 
3301 	atf_tc_set_md_var(tc, "require.user", "root");
3302 }
ATF_TC_BODY(ptrace__parent_terminate_with_pending_sigstop2,tc)3303 ATF_TC_BODY(ptrace__parent_terminate_with_pending_sigstop2, tc)
3304 {
3305 
3306 	terminate_with_pending_sigstop(false);
3307 }
3308 
3309 /*
3310  * Verify that after ptrace() discards a SIGKILL signal, the event mask
3311  * is not modified.
3312  */
3313 ATF_TC_WITHOUT_HEAD(ptrace__event_mask_sigkill_discard);
ATF_TC_BODY(ptrace__event_mask_sigkill_discard,tc)3314 ATF_TC_BODY(ptrace__event_mask_sigkill_discard, tc)
3315 {
3316 	struct ptrace_lwpinfo pl;
3317 	pid_t fpid, wpid;
3318 	int status, event_mask, new_event_mask;
3319 
3320 	ATF_REQUIRE((fpid = fork()) != -1);
3321 	if (fpid == 0) {
3322 		trace_me();
3323 		raise(SIGSTOP);
3324 		exit(0);
3325 	}
3326 
3327 	/* The first wait() should report the stop from trace_me(). */
3328 	wpid = waitpid(fpid, &status, 0);
3329 	ATF_REQUIRE(wpid == fpid);
3330 	ATF_REQUIRE(WIFSTOPPED(status));
3331 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3332 
3333 	/* Set several unobtrusive event bits. */
3334 	event_mask = PTRACE_EXEC | PTRACE_FORK | PTRACE_LWP;
3335 	ATF_REQUIRE(ptrace(PT_SET_EVENT_MASK, wpid, (caddr_t)&event_mask,
3336 	    sizeof(event_mask)) == 0);
3337 
3338 	/* Send a SIGKILL without using ptrace. */
3339 	ATF_REQUIRE(kill(fpid, SIGKILL) == 0);
3340 
3341 	/* Continue the child ignoring the SIGSTOP. */
3342 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3343 
3344 	/* The next stop should be due to the SIGKILL. */
3345 	wpid = waitpid(fpid, &status, 0);
3346 	ATF_REQUIRE(wpid == fpid);
3347 	ATF_REQUIRE(WIFSTOPPED(status));
3348 	ATF_REQUIRE(WSTOPSIG(status) == SIGKILL);
3349 
3350 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3351 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SI);
3352 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGKILL);
3353 
3354 	/* Continue the child ignoring the SIGKILL. */
3355 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3356 
3357 	/* The next wait() should report the stop from SIGSTOP. */
3358 	wpid = waitpid(fpid, &status, 0);
3359 	ATF_REQUIRE(wpid == fpid);
3360 	ATF_REQUIRE(WIFSTOPPED(status));
3361 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3362 
3363 	/* Check the current event mask. It should not have changed. */
3364 	new_event_mask = 0;
3365 	ATF_REQUIRE(ptrace(PT_GET_EVENT_MASK, wpid, (caddr_t)&new_event_mask,
3366 	    sizeof(new_event_mask)) == 0);
3367 	ATF_REQUIRE(event_mask == new_event_mask);
3368 
3369 	/* Continue the child to let it exit. */
3370 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3371 
3372 	/* The last event should be for the child process's exit. */
3373 	wpid = waitpid(fpid, &status, 0);
3374 	ATF_REQUIRE(WIFEXITED(status));
3375 	ATF_REQUIRE(WEXITSTATUS(status) == 0);
3376 
3377 	wpid = wait(&status);
3378 	ATF_REQUIRE(wpid == -1);
3379 	ATF_REQUIRE(errno == ECHILD);
3380 }
3381 
3382 static void *
flock_thread(void * arg)3383 flock_thread(void *arg)
3384 {
3385 	int fd;
3386 
3387 	fd = *(int *)arg;
3388 	(void)flock(fd, LOCK_EX);
3389 	(void)flock(fd, LOCK_UN);
3390 	return (NULL);
3391 }
3392 
3393 /*
3394  * Verify that PT_ATTACH will suspend threads sleeping in an SBDRY section.
3395  * We rely on the fact that the lockf implementation sets SBDRY before blocking
3396  * on a lock. This is a regression test for r318191.
3397  */
3398 ATF_TC_WITHOUT_HEAD(ptrace__PT_ATTACH_with_SBDRY_thread);
ATF_TC_BODY(ptrace__PT_ATTACH_with_SBDRY_thread,tc)3399 ATF_TC_BODY(ptrace__PT_ATTACH_with_SBDRY_thread, tc)
3400 {
3401 	pthread_barrier_t barrier;
3402 	pthread_barrierattr_t battr;
3403 	char tmpfile[64];
3404 	pid_t child, wpid;
3405 	int error, fd, i, status;
3406 
3407 	ATF_REQUIRE(pthread_barrierattr_init(&battr) == 0);
3408 	ATF_REQUIRE(pthread_barrierattr_setpshared(&battr,
3409 	    PTHREAD_PROCESS_SHARED) == 0);
3410 	ATF_REQUIRE(pthread_barrier_init(&barrier, &battr, 2) == 0);
3411 
3412 	(void)snprintf(tmpfile, sizeof(tmpfile), "./ptrace.XXXXXX");
3413 	fd = mkstemp(tmpfile);
3414 	ATF_REQUIRE(fd >= 0);
3415 
3416 	ATF_REQUIRE((child = fork()) != -1);
3417 	if (child == 0) {
3418 		pthread_t t[2];
3419 		int cfd;
3420 
3421 		error = pthread_barrier_wait(&barrier);
3422 		if (error != 0 && error != PTHREAD_BARRIER_SERIAL_THREAD)
3423 			_exit(1);
3424 
3425 		cfd = open(tmpfile, O_RDONLY);
3426 		if (cfd < 0)
3427 			_exit(1);
3428 
3429 		/*
3430 		 * We want at least two threads blocked on the file lock since
3431 		 * the SIGSTOP from PT_ATTACH may kick one of them out of
3432 		 * sleep.
3433 		 */
3434 		if (pthread_create(&t[0], NULL, flock_thread, &cfd) != 0)
3435 			_exit(1);
3436 		if (pthread_create(&t[1], NULL, flock_thread, &cfd) != 0)
3437 			_exit(1);
3438 		if (pthread_join(t[0], NULL) != 0)
3439 			_exit(1);
3440 		if (pthread_join(t[1], NULL) != 0)
3441 			_exit(1);
3442 		_exit(0);
3443 	}
3444 
3445 	ATF_REQUIRE(flock(fd, LOCK_EX) == 0);
3446 
3447 	error = pthread_barrier_wait(&barrier);
3448 	ATF_REQUIRE(error == 0 || error == PTHREAD_BARRIER_SERIAL_THREAD);
3449 
3450 	/*
3451 	 * Give the child some time to block. Is there a better way to do this?
3452 	 */
3453 	sleep(1);
3454 
3455 	/*
3456 	 * Attach and give the child 3 seconds to stop.
3457 	 */
3458 	ATF_REQUIRE(ptrace(PT_ATTACH, child, NULL, 0) == 0);
3459 	for (i = 0; i < 3; i++) {
3460 		wpid = waitpid(child, &status, WNOHANG);
3461 		if (wpid == child && WIFSTOPPED(status) &&
3462 		    WSTOPSIG(status) == SIGSTOP)
3463 			break;
3464 		sleep(1);
3465 	}
3466 	ATF_REQUIRE_MSG(i < 3, "failed to stop child process after PT_ATTACH");
3467 
3468 	ATF_REQUIRE(ptrace(PT_DETACH, child, NULL, 0) == 0);
3469 
3470 	ATF_REQUIRE(flock(fd, LOCK_UN) == 0);
3471 	ATF_REQUIRE(unlink(tmpfile) == 0);
3472 	ATF_REQUIRE(close(fd) == 0);
3473 }
3474 
3475 static void
sigusr1_step_handler(int sig)3476 sigusr1_step_handler(int sig)
3477 {
3478 
3479 	CHILD_REQUIRE(sig == SIGUSR1);
3480 	raise(SIGABRT);
3481 }
3482 
3483 /*
3484  * Verify that PT_STEP with a signal invokes the signal before
3485  * stepping the next instruction (and that the next instruction is
3486  * stepped correctly).
3487  */
3488 ATF_TC_WITHOUT_HEAD(ptrace__PT_STEP_with_signal);
ATF_TC_BODY(ptrace__PT_STEP_with_signal,tc)3489 ATF_TC_BODY(ptrace__PT_STEP_with_signal, tc)
3490 {
3491 	struct ptrace_lwpinfo pl;
3492 	pid_t fpid, wpid;
3493 	int status;
3494 
3495 	ATF_REQUIRE((fpid = fork()) != -1);
3496 	if (fpid == 0) {
3497 		trace_me();
3498 		signal(SIGUSR1, sigusr1_step_handler);
3499 		raise(SIGABRT);
3500 		exit(1);
3501 	}
3502 
3503 	/* The first wait() should report the stop from SIGSTOP. */
3504 	wpid = waitpid(fpid, &status, 0);
3505 	ATF_REQUIRE(wpid == fpid);
3506 	ATF_REQUIRE(WIFSTOPPED(status));
3507 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3508 
3509 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3510 
3511 	/* The next stop should report the SIGABRT in the child body. */
3512 	wpid = waitpid(fpid, &status, 0);
3513 	ATF_REQUIRE(wpid == fpid);
3514 	ATF_REQUIRE(WIFSTOPPED(status));
3515 	ATF_REQUIRE(WSTOPSIG(status) == SIGABRT);
3516 
3517 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3518 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SI);
3519 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGABRT);
3520 
3521 	/* Step the child process inserting SIGUSR1. */
3522 	ATF_REQUIRE(ptrace(PT_STEP, fpid, (caddr_t)1, SIGUSR1) == 0);
3523 
3524 	/* The next stop should report the SIGABRT in the signal handler. */
3525 	wpid = waitpid(fpid, &status, 0);
3526 	ATF_REQUIRE(wpid == fpid);
3527 	ATF_REQUIRE(WIFSTOPPED(status));
3528 	ATF_REQUIRE(WSTOPSIG(status) == SIGABRT);
3529 
3530 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3531 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SI);
3532 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGABRT);
3533 
3534 	/* Continue the child process discarding the signal. */
3535 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3536 
3537 	/* The next stop should report a trace trap from PT_STEP. */
3538 	wpid = waitpid(fpid, &status, 0);
3539 	ATF_REQUIRE(wpid == fpid);
3540 	ATF_REQUIRE(WIFSTOPPED(status));
3541 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
3542 
3543 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3544 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SI);
3545 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGTRAP);
3546 	ATF_REQUIRE(pl.pl_siginfo.si_code == TRAP_TRACE);
3547 
3548 	/* Continue the child to let it exit. */
3549 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3550 
3551 	/* The last event should be for the child process's exit. */
3552 	wpid = waitpid(fpid, &status, 0);
3553 	ATF_REQUIRE(WIFEXITED(status));
3554 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
3555 
3556 	wpid = wait(&status);
3557 	ATF_REQUIRE(wpid == -1);
3558 	ATF_REQUIRE(errno == ECHILD);
3559 }
3560 
3561 #ifdef HAVE_BREAKPOINT
3562 /*
3563  * Verify that a SIGTRAP event with the TRAP_BRKPT code is reported
3564  * for a breakpoint trap.
3565  */
3566 ATF_TC_WITHOUT_HEAD(ptrace__breakpoint_siginfo);
ATF_TC_BODY(ptrace__breakpoint_siginfo,tc)3567 ATF_TC_BODY(ptrace__breakpoint_siginfo, tc)
3568 {
3569 	struct ptrace_lwpinfo pl;
3570 	pid_t fpid, wpid;
3571 	int status;
3572 
3573 	ATF_REQUIRE((fpid = fork()) != -1);
3574 	if (fpid == 0) {
3575 		trace_me();
3576 		breakpoint();
3577 		exit(1);
3578 	}
3579 
3580 	/* The first wait() should report the stop from SIGSTOP. */
3581 	wpid = waitpid(fpid, &status, 0);
3582 	ATF_REQUIRE(wpid == fpid);
3583 	ATF_REQUIRE(WIFSTOPPED(status));
3584 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3585 
3586 	/* Continue the child ignoring the SIGSTOP. */
3587 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3588 
3589 	/* The second wait() should report hitting the breakpoint. */
3590 	wpid = waitpid(fpid, &status, 0);
3591 	ATF_REQUIRE(wpid == fpid);
3592 	ATF_REQUIRE(WIFSTOPPED(status));
3593 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
3594 
3595 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3596 	ATF_REQUIRE((pl.pl_flags & PL_FLAG_SI) != 0);
3597 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGTRAP);
3598 	ATF_REQUIRE(pl.pl_siginfo.si_code == TRAP_BRKPT);
3599 
3600 	/* Kill the child process. */
3601 	ATF_REQUIRE(ptrace(PT_KILL, fpid, 0, 0) == 0);
3602 
3603 	/* The last wait() should report the SIGKILL. */
3604 	wpid = waitpid(fpid, &status, 0);
3605 	ATF_REQUIRE(wpid == fpid);
3606 	ATF_REQUIRE(WIFSIGNALED(status));
3607 	ATF_REQUIRE(WTERMSIG(status) == SIGKILL);
3608 
3609 	wpid = wait(&status);
3610 	ATF_REQUIRE(wpid == -1);
3611 	ATF_REQUIRE(errno == ECHILD);
3612 }
3613 #endif /* HAVE_BREAKPOINT */
3614 
3615 /*
3616  * Verify that a SIGTRAP event with the TRAP_TRACE code is reported
3617  * for a single-step trap from PT_STEP.
3618  */
3619 ATF_TC_WITHOUT_HEAD(ptrace__step_siginfo);
ATF_TC_BODY(ptrace__step_siginfo,tc)3620 ATF_TC_BODY(ptrace__step_siginfo, tc)
3621 {
3622 	struct ptrace_lwpinfo pl;
3623 	pid_t fpid, wpid;
3624 	int status;
3625 
3626 	ATF_REQUIRE((fpid = fork()) != -1);
3627 	if (fpid == 0) {
3628 		trace_me();
3629 		exit(1);
3630 	}
3631 
3632 	/* The first wait() should report the stop from SIGSTOP. */
3633 	wpid = waitpid(fpid, &status, 0);
3634 	ATF_REQUIRE(wpid == fpid);
3635 	ATF_REQUIRE(WIFSTOPPED(status));
3636 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3637 
3638 	/* Step the child ignoring the SIGSTOP. */
3639 	ATF_REQUIRE(ptrace(PT_STEP, fpid, (caddr_t)1, 0) == 0);
3640 
3641 	/* The second wait() should report a single-step trap. */
3642 	wpid = waitpid(fpid, &status, 0);
3643 	ATF_REQUIRE(wpid == fpid);
3644 	ATF_REQUIRE(WIFSTOPPED(status));
3645 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
3646 
3647 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3648 	ATF_REQUIRE((pl.pl_flags & PL_FLAG_SI) != 0);
3649 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGTRAP);
3650 	ATF_REQUIRE(pl.pl_siginfo.si_code == TRAP_TRACE);
3651 
3652 	/* Continue the child process. */
3653 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3654 
3655 	/* The last event should be for the child process's exit. */
3656 	wpid = waitpid(fpid, &status, 0);
3657 	ATF_REQUIRE(WIFEXITED(status));
3658 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
3659 
3660 	wpid = wait(&status);
3661 	ATF_REQUIRE(wpid == -1);
3662 	ATF_REQUIRE(errno == ECHILD);
3663 }
3664 
3665 #if defined(HAVE_BREAKPOINT) && defined(SKIP_BREAK)
3666 static void *
continue_thread(void * arg __unused)3667 continue_thread(void *arg __unused)
3668 {
3669 	breakpoint();
3670 	return (NULL);
3671 }
3672 
3673 static __dead2 void
continue_thread_main(void)3674 continue_thread_main(void)
3675 {
3676 	pthread_t threads[2];
3677 
3678 	CHILD_REQUIRE(pthread_create(&threads[0], NULL, continue_thread,
3679 	    NULL) == 0);
3680 	CHILD_REQUIRE(pthread_create(&threads[1], NULL, continue_thread,
3681 	    NULL) == 0);
3682 	CHILD_REQUIRE(pthread_join(threads[0], NULL) == 0);
3683 	CHILD_REQUIRE(pthread_join(threads[1], NULL) == 0);
3684 	exit(1);
3685 }
3686 
3687 /*
3688  * Ensure that PT_CONTINUE clears the status of the thread that
3689  * triggered the stop even if a different thread's LWP was passed to
3690  * PT_CONTINUE.
3691  */
3692 ATF_TC_WITHOUT_HEAD(ptrace__PT_CONTINUE_different_thread);
ATF_TC_BODY(ptrace__PT_CONTINUE_different_thread,tc)3693 ATF_TC_BODY(ptrace__PT_CONTINUE_different_thread, tc)
3694 {
3695 	struct ptrace_lwpinfo pl;
3696 	pid_t fpid, wpid;
3697 	lwpid_t lwps[2];
3698 	bool hit_break[2];
3699 	struct reg reg;
3700 	int i, j, status;
3701 
3702 	ATF_REQUIRE((fpid = fork()) != -1);
3703 	if (fpid == 0) {
3704 		trace_me();
3705 		continue_thread_main();
3706 	}
3707 
3708 	/* The first wait() should report the stop from SIGSTOP. */
3709 	wpid = waitpid(fpid, &status, 0);
3710 	ATF_REQUIRE(wpid == fpid);
3711 	ATF_REQUIRE(WIFSTOPPED(status));
3712 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3713 
3714 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
3715 	    sizeof(pl)) != -1);
3716 
3717 	ATF_REQUIRE(ptrace(PT_LWP_EVENTS, wpid, NULL, 1) == 0);
3718 
3719 	/* Continue the child ignoring the SIGSTOP. */
3720 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3721 
3722 	/* One of the new threads should report it's birth. */
3723 	wpid = waitpid(fpid, &status, 0);
3724 	ATF_REQUIRE(wpid == fpid);
3725 	ATF_REQUIRE(WIFSTOPPED(status));
3726 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
3727 
3728 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3729 	ATF_REQUIRE((pl.pl_flags & (PL_FLAG_BORN | PL_FLAG_SCX)) ==
3730 	    (PL_FLAG_BORN | PL_FLAG_SCX));
3731 	lwps[0] = pl.pl_lwpid;
3732 
3733 	/*
3734 	 * Suspend this thread to ensure both threads are alive before
3735 	 * hitting the breakpoint.
3736 	 */
3737 	ATF_REQUIRE(ptrace(PT_SUSPEND, lwps[0], NULL, 0) != -1);
3738 
3739 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3740 
3741 	/* Second thread should report it's birth. */
3742 	wpid = waitpid(fpid, &status, 0);
3743 	ATF_REQUIRE(wpid == fpid);
3744 	ATF_REQUIRE(WIFSTOPPED(status));
3745 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
3746 
3747 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3748 	ATF_REQUIRE((pl.pl_flags & (PL_FLAG_BORN | PL_FLAG_SCX)) ==
3749 	    (PL_FLAG_BORN | PL_FLAG_SCX));
3750 	ATF_REQUIRE(pl.pl_lwpid != lwps[0]);
3751 	lwps[1] = pl.pl_lwpid;
3752 
3753 	/* Resume both threads waiting for breakpoint events. */
3754 	hit_break[0] = hit_break[1] = false;
3755 	ATF_REQUIRE(ptrace(PT_RESUME, lwps[0], NULL, 0) != -1);
3756 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3757 
3758 	/* One thread should report a breakpoint. */
3759 	wpid = waitpid(fpid, &status, 0);
3760 	ATF_REQUIRE(wpid == fpid);
3761 	ATF_REQUIRE(WIFSTOPPED(status));
3762 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
3763 
3764 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3765 	ATF_REQUIRE((pl.pl_flags & PL_FLAG_SI) != 0);
3766 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGTRAP &&
3767 	    pl.pl_siginfo.si_code == TRAP_BRKPT);
3768 	if (pl.pl_lwpid == lwps[0])
3769 		i = 0;
3770 	else
3771 		i = 1;
3772 	hit_break[i] = true;
3773 	ATF_REQUIRE(ptrace(PT_GETREGS, pl.pl_lwpid, (caddr_t)&reg, 0) != -1);
3774 	SKIP_BREAK(&reg);
3775 	ATF_REQUIRE(ptrace(PT_SETREGS, pl.pl_lwpid, (caddr_t)&reg, 0) != -1);
3776 
3777 	/*
3778 	 * Resume both threads but pass the other thread's LWPID to
3779 	 * PT_CONTINUE.
3780 	 */
3781 	ATF_REQUIRE(ptrace(PT_CONTINUE, lwps[i ^ 1], (caddr_t)1, 0) == 0);
3782 
3783 	/*
3784 	 * Will now get two thread exit events and one more breakpoint
3785 	 * event.
3786 	 */
3787 	for (j = 0; j < 3; j++) {
3788 		wpid = waitpid(fpid, &status, 0);
3789 		ATF_REQUIRE(wpid == fpid);
3790 		ATF_REQUIRE(WIFSTOPPED(status));
3791 		ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
3792 
3793 		ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl,
3794 		    sizeof(pl)) != -1);
3795 
3796 		if (pl.pl_lwpid == lwps[0])
3797 			i = 0;
3798 		else
3799 			i = 1;
3800 
3801 		ATF_REQUIRE_MSG(lwps[i] != 0, "event for exited thread");
3802 		if (pl.pl_flags & PL_FLAG_EXITED) {
3803 			ATF_REQUIRE_MSG(hit_break[i],
3804 			    "exited thread did not report breakpoint");
3805 			lwps[i] = 0;
3806 		} else {
3807 			ATF_REQUIRE((pl.pl_flags & PL_FLAG_SI) != 0);
3808 			ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGTRAP &&
3809 			    pl.pl_siginfo.si_code == TRAP_BRKPT);
3810 			ATF_REQUIRE_MSG(!hit_break[i],
3811 			    "double breakpoint event");
3812 			hit_break[i] = true;
3813 			ATF_REQUIRE(ptrace(PT_GETREGS, pl.pl_lwpid, (caddr_t)&reg,
3814 			    0) != -1);
3815 			SKIP_BREAK(&reg);
3816 			ATF_REQUIRE(ptrace(PT_SETREGS, pl.pl_lwpid, (caddr_t)&reg,
3817 			    0) != -1);
3818 		}
3819 
3820 		ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3821 	}
3822 
3823 	/* Both threads should have exited. */
3824 	ATF_REQUIRE(lwps[0] == 0);
3825 	ATF_REQUIRE(lwps[1] == 0);
3826 
3827 	/* The last event should be for the child process's exit. */
3828 	wpid = waitpid(fpid, &status, 0);
3829 	ATF_REQUIRE(WIFEXITED(status));
3830 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
3831 
3832 	wpid = wait(&status);
3833 	ATF_REQUIRE(wpid == -1);
3834 	ATF_REQUIRE(errno == ECHILD);
3835 }
3836 #endif
3837 
3838 /*
3839  * Verify that PT_LWPINFO doesn't return stale siginfo.
3840  */
3841 ATF_TC_WITHOUT_HEAD(ptrace__PT_LWPINFO_stale_siginfo);
ATF_TC_BODY(ptrace__PT_LWPINFO_stale_siginfo,tc)3842 ATF_TC_BODY(ptrace__PT_LWPINFO_stale_siginfo, tc)
3843 {
3844 	struct ptrace_lwpinfo pl;
3845 	pid_t fpid, wpid;
3846 	int events, status;
3847 
3848 	ATF_REQUIRE((fpid = fork()) != -1);
3849 	if (fpid == 0) {
3850 		trace_me();
3851 		raise(SIGABRT);
3852 		exit(1);
3853 	}
3854 
3855 	/* The first wait() should report the stop from SIGSTOP. */
3856 	wpid = waitpid(fpid, &status, 0);
3857 	ATF_REQUIRE(wpid == fpid);
3858 	ATF_REQUIRE(WIFSTOPPED(status));
3859 	ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3860 
3861 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3862 
3863 	/* The next stop should report the SIGABRT in the child body. */
3864 	wpid = waitpid(fpid, &status, 0);
3865 	ATF_REQUIRE(wpid == fpid);
3866 	ATF_REQUIRE(WIFSTOPPED(status));
3867 	ATF_REQUIRE(WSTOPSIG(status) == SIGABRT);
3868 
3869 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3870 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SI);
3871 	ATF_REQUIRE(pl.pl_siginfo.si_signo == SIGABRT);
3872 
3873 	/*
3874 	 * Continue the process ignoring the signal, but enabling
3875 	 * syscall traps.
3876 	 */
3877 	ATF_REQUIRE(ptrace(PT_SYSCALL, fpid, (caddr_t)1, 0) == 0);
3878 
3879 	/*
3880 	 * The next stop should report a system call entry from
3881 	 * exit().  PL_FLAGS_SI should not be set.
3882 	 */
3883 	wpid = waitpid(fpid, &status, 0);
3884 	ATF_REQUIRE(wpid == fpid);
3885 	ATF_REQUIRE(WIFSTOPPED(status));
3886 	ATF_REQUIRE(WSTOPSIG(status) == SIGTRAP);
3887 
3888 	ATF_REQUIRE(ptrace(PT_LWPINFO, wpid, (caddr_t)&pl, sizeof(pl)) != -1);
3889 	ATF_REQUIRE(pl.pl_flags & PL_FLAG_SCE);
3890 	ATF_REQUIRE((pl.pl_flags & PL_FLAG_SI) == 0);
3891 
3892 	/* Disable syscall tracing and continue the child to let it exit. */
3893 	ATF_REQUIRE(ptrace(PT_GET_EVENT_MASK, fpid, (caddr_t)&events,
3894 	    sizeof(events)) == 0);
3895 	events &= ~PTRACE_SYSCALL;
3896 	ATF_REQUIRE(ptrace(PT_SET_EVENT_MASK, fpid, (caddr_t)&events,
3897 	    sizeof(events)) == 0);
3898 	ATF_REQUIRE(ptrace(PT_CONTINUE, fpid, (caddr_t)1, 0) == 0);
3899 
3900 	/* The last event should be for the child process's exit. */
3901 	wpid = waitpid(fpid, &status, 0);
3902 	ATF_REQUIRE(WIFEXITED(status));
3903 	ATF_REQUIRE(WEXITSTATUS(status) == 1);
3904 
3905 	wpid = wait(&status);
3906 	ATF_REQUIRE(wpid == -1);
3907 	ATF_REQUIRE(errno == ECHILD);
3908 }
3909 
3910 /*
3911  * Verify that when the process is traced that it isn't reparent
3912  * to the init process when we close all process descriptors.
3913  */
3914 ATF_TC(ptrace__proc_reparent);
ATF_TC_HEAD(ptrace__proc_reparent,tc)3915 ATF_TC_HEAD(ptrace__proc_reparent, tc)
3916 {
3917 
3918 	atf_tc_set_md_var(tc, "timeout", "2");
3919 }
ATF_TC_BODY(ptrace__proc_reparent,tc)3920 ATF_TC_BODY(ptrace__proc_reparent, tc)
3921 {
3922 	pid_t traced, debuger, wpid;
3923 	int pd, status;
3924 
3925 	traced = pdfork(&pd, 0);
3926 	ATF_REQUIRE(traced >= 0);
3927 	if (traced == 0) {
3928 		raise(SIGSTOP);
3929 		exit(0);
3930 	}
3931 	ATF_REQUIRE(pd >= 0);
3932 
3933 	debuger = fork();
3934 	ATF_REQUIRE(debuger >= 0);
3935 	if (debuger == 0) {
3936 		/* The traced process is reparented to debuger. */
3937 		ATF_REQUIRE(ptrace(PT_ATTACH, traced, 0, 0) == 0);
3938 		wpid = waitpid(traced, &status, 0);
3939 		ATF_REQUIRE(wpid == traced);
3940 		ATF_REQUIRE(WIFSTOPPED(status));
3941 		ATF_REQUIRE(WSTOPSIG(status) == SIGSTOP);
3942 		ATF_REQUIRE(close(pd) == 0);
3943 		ATF_REQUIRE(ptrace(PT_DETACH, traced, (caddr_t)1, 0) == 0);
3944 
3945 		/* We closed pd so we should not have any child. */
3946 		wpid = wait(&status);
3947 		ATF_REQUIRE(wpid == -1);
3948 		ATF_REQUIRE(errno == ECHILD);
3949 
3950 		exit(0);
3951 	}
3952 
3953 	ATF_REQUIRE(close(pd) == 0);
3954 	wpid = waitpid(debuger, &status, 0);
3955 	ATF_REQUIRE(wpid == debuger);
3956 	ATF_REQUIRE(WEXITSTATUS(status) == 0);
3957 
3958 	/* Check if we still have any child. */
3959 	wpid = wait(&status);
3960 	ATF_REQUIRE(wpid == -1);
3961 	ATF_REQUIRE(errno == ECHILD);
3962 }
3963 
ATF_TP_ADD_TCS(tp)3964 ATF_TP_ADD_TCS(tp)
3965 {
3966 
3967 	ATF_TP_ADD_TC(tp, ptrace__parent_wait_after_trace_me);
3968 	ATF_TP_ADD_TC(tp, ptrace__parent_wait_after_attach);
3969 	ATF_TP_ADD_TC(tp, ptrace__parent_sees_exit_after_child_debugger);
3970 	ATF_TP_ADD_TC(tp, ptrace__parent_sees_exit_after_unrelated_debugger);
3971 	ATF_TP_ADD_TC(tp, ptrace__parent_exits_before_child);
3972 	ATF_TP_ADD_TC(tp, ptrace__follow_fork_both_attached);
3973 	ATF_TP_ADD_TC(tp, ptrace__follow_fork_child_detached);
3974 	ATF_TP_ADD_TC(tp, ptrace__follow_fork_parent_detached);
3975 	ATF_TP_ADD_TC(tp, ptrace__follow_fork_both_attached_unrelated_debugger);
3976 	ATF_TP_ADD_TC(tp,
3977 	    ptrace__follow_fork_child_detached_unrelated_debugger);
3978 	ATF_TP_ADD_TC(tp,
3979 	    ptrace__follow_fork_parent_detached_unrelated_debugger);
3980 	ATF_TP_ADD_TC(tp, ptrace__getppid);
3981 	ATF_TP_ADD_TC(tp, ptrace__new_child_pl_syscall_code_fork);
3982 	ATF_TP_ADD_TC(tp, ptrace__new_child_pl_syscall_code_vfork);
3983 	ATF_TP_ADD_TC(tp, ptrace__new_child_pl_syscall_code_thread);
3984 	ATF_TP_ADD_TC(tp, ptrace__lwp_events);
3985 	ATF_TP_ADD_TC(tp, ptrace__lwp_events_exec);
3986 	ATF_TP_ADD_TC(tp, ptrace__siginfo);
3987 	ATF_TP_ADD_TC(tp, ptrace__ptrace_exec_disable);
3988 	ATF_TP_ADD_TC(tp, ptrace__ptrace_exec_enable);
3989 	ATF_TP_ADD_TC(tp, ptrace__event_mask);
3990 	ATF_TP_ADD_TC(tp, ptrace__ptrace_vfork);
3991 	ATF_TP_ADD_TC(tp, ptrace__ptrace_vfork_follow);
3992 #ifdef HAVE_BREAKPOINT
3993 	ATF_TP_ADD_TC(tp, ptrace__PT_KILL_breakpoint);
3994 #endif
3995 	ATF_TP_ADD_TC(tp, ptrace__PT_KILL_system_call);
3996 	ATF_TP_ADD_TC(tp, ptrace__PT_KILL_threads);
3997 	ATF_TP_ADD_TC(tp, ptrace__PT_KILL_competing_signal);
3998 	ATF_TP_ADD_TC(tp, ptrace__PT_KILL_competing_stop);
3999 	ATF_TP_ADD_TC(tp, ptrace__PT_KILL_with_signal_full_sigqueue);
4000 	ATF_TP_ADD_TC(tp, ptrace__PT_CONTINUE_with_signal_system_call_entry);
4001 	ATF_TP_ADD_TC(tp,
4002 	    ptrace__PT_CONTINUE_with_signal_system_call_entry_and_exit);
4003 	ATF_TP_ADD_TC(tp, ptrace__PT_CONTINUE_with_signal_full_sigqueue);
4004 	ATF_TP_ADD_TC(tp, ptrace__PT_CONTINUE_with_signal_masked_full_sigqueue);
4005 	ATF_TP_ADD_TC(tp, ptrace__PT_CONTINUE_change_sig);
4006 	ATF_TP_ADD_TC(tp, ptrace__PT_CONTINUE_with_sigtrap_system_call_entry);
4007 	ATF_TP_ADD_TC(tp, ptrace__PT_CONTINUE_with_signal_mix);
4008 	ATF_TP_ADD_TC(tp, ptrace__PT_CONTINUE_with_signal_kqueue);
4009 	ATF_TP_ADD_TC(tp, ptrace__killed_with_sigmask);
4010 	ATF_TP_ADD_TC(tp, ptrace__PT_CONTINUE_with_sigmask);
4011 	ATF_TP_ADD_TC(tp, ptrace__PT_CONTINUE_with_signal_thread_sigmask);
4012 	ATF_TP_ADD_TC(tp, ptrace__parent_terminate_with_pending_sigstop1);
4013 	ATF_TP_ADD_TC(tp, ptrace__parent_terminate_with_pending_sigstop2);
4014 	ATF_TP_ADD_TC(tp, ptrace__event_mask_sigkill_discard);
4015 	ATF_TP_ADD_TC(tp, ptrace__PT_ATTACH_with_SBDRY_thread);
4016 	ATF_TP_ADD_TC(tp, ptrace__PT_STEP_with_signal);
4017 #ifdef HAVE_BREAKPOINT
4018 	ATF_TP_ADD_TC(tp, ptrace__breakpoint_siginfo);
4019 #endif
4020 	ATF_TP_ADD_TC(tp, ptrace__step_siginfo);
4021 #if defined(HAVE_BREAKPOINT) && defined(SKIP_BREAK)
4022 	ATF_TP_ADD_TC(tp, ptrace__PT_CONTINUE_different_thread);
4023 #endif
4024 	ATF_TP_ADD_TC(tp, ptrace__PT_LWPINFO_stale_siginfo);
4025 	ATF_TP_ADD_TC(tp, ptrace__proc_reparent);
4026 
4027 	return (atf_no_error());
4028 }
4029