#!/bin/bash

# Copyright (c) 2026 Red Hat.
#
# This is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published
# by the Free Software Foundation; either version 3, or (at your
# option) any later version.
#
# It is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU General Public License for more details.

# Test that annocheck detects insecure RPATH/RUNPATH via --test-run-path

TEST_NAME=run-path
. $srcdir/common.sh

PLUGIN_OPTS="-fplugin-arg-annobin-no-attach"
OPTS="-O2 -D_FORTIFY_SOURCE=2 -fPIE -Wall -fstack-protector-strong -D_GLIBCXX_ASSERTIONS -fstack-clash-protection"

start_test

# Compile test object files
$GCC -fplugin=$PLUGIN $PLUGIN_OPTS -c $OPTS $srcdir/hello.c && \
    $GCC -fplugin=$PLUGIN $PLUGIN_OPTS -c $OPTS $srcdir/hello2.c && \
    $GCC -fplugin=$PLUGIN $PLUGIN_OPTS -c $OPTS $srcdir/hello3.c && \
    $GCC -fplugin=$PLUGIN $PLUGIN_OPTS -c $OPTS $srcdir/hello_lib.c

# Part 1: Link without any RPATH/RUNPATH - should PASS (no run-path to check)
$GCC hello.o hello2.o hello3.o hello_lib.o -pie -Wl,-z,now,-z,relro -o $EXE > $G_OUT 2>&1
if [ $? != 0 ];
then
    echo " $TEST_NAME: SKIP: unable to link test executable"
    cat $G_OUT
    end_test
    exit $EXIT_TEST_SKIPPED
fi

A_OUT=run-path-test.out
SKIPS="--skip-all --test-run-path --suppress-version-warnings"

A_COMMAND="$ANNOCHECK $EXE $SKIPS --verbose"
$A_COMMAND > $A_OUT
grep -q -e"FAIL: run-path test" $A_OUT
if [ $? == 0 ];
then
    echo " $TEST_NAME: FAIL: annocheck incorrectly failed a binary without RPATH/RUNPATH"
    echo " $TEST_NAME: annocheck output:"
    cat $A_OUT
    end_test
    exit $EXIT_TEST_FAILED
fi

echo " $TEST_NAME: PASS: annocheck correctly passed a binary without RPATH/RUNPATH"

#------------------------------------------------------------------------------------

# Part 2: Link with a secure RUNPATH (/usr/lib64) - should PASS

$GCC hello.o hello2.o hello3.o hello_lib.o -pie -Wl,-z,now,-z,relro -Wl,--enable-new-dtags -Wl,-rpath,/usr/lib64 -o $EXE > $G_OUT 2>&1
if [ $? != 0 ];
then
    echo " $TEST_NAME: SKIP: unable to link test executable with -rpath /usr/lib64"
    cat $G_OUT
    end_test
    exit $EXIT_TEST_SKIPPED
fi

A_COMMAND="$ANNOCHECK $EXE $SKIPS --verbose"
$A_COMMAND > $A_OUT
grep -q -e"FAIL: run-path test" $A_OUT
if [ $? == 0 ];
then
    echo " $TEST_NAME: FAIL: annocheck incorrectly failed a binary with secure RUNPATH /usr/lib64"
    echo " $TEST_NAME: annocheck output:"
    cat $A_OUT
    end_test
    exit $EXIT_TEST_FAILED
fi

echo " $TEST_NAME: PASS: annocheck correctly passed a binary with secure RUNPATH /usr/lib64"

#------------------------------------------------------------------------------------

# Part 3: Link with an insecure RUNPATH (/tmp) - should FAIL

$GCC hello.o hello2.o hello3.o hello_lib.o -pie -Wl,-z,now,-z,relro -Wl,--enable-new-dtags -Wl,-rpath,/tmp -o $EXE > $G_OUT 2>&1
if [ $? != 0 ];
then
    echo " $TEST_NAME: SKIP: unable to link test executable with -rpath /tmp"
    cat $G_OUT
    end_test
    exit $EXIT_TEST_SKIPPED
fi

A_COMMAND="$ANNOCHECK $EXE $SKIPS --verbose"
$A_COMMAND > $A_OUT
grep -q -e"FAIL: run-path test" $A_OUT
if [ $? != 0 ];
then
    echo " $TEST_NAME: FAIL: annocheck did not detect insecure RUNPATH /tmp"
    echo " $TEST_NAME: annocheck output:"
    cat $A_OUT
    end_test
    exit $EXIT_TEST_FAILED
fi

echo " $TEST_NAME: PASS: annocheck detected an insecure RUNPATH /tmp"

end_test
