diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/.gitignore b/.gitignore index dd63848..f1e876b 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1,2 @@ /libcap-*.tar.gz +*.src.rpm diff --git a/0001-cap_alloc.c-fix-CVE-2023-2603.patch b/0001-cap_alloc.c-fix-CVE-2023-2603.patch new file mode 100644 index 0000000..2ee9161 --- /dev/null +++ b/0001-cap_alloc.c-fix-CVE-2023-2603.patch @@ -0,0 +1,34 @@ +From 59bae31a96003840c064573904a4041427df3890 Mon Sep 17 00:00:00 2001 +From: Carlos Rodriguez-Fernandez +Date: Wed, 22 Nov 2023 07:53:36 -0700 +Subject: [PATCH 1/2] cap_alloc.c:fix CVE-2023-2603 + +--- + libcap/cap_alloc.c | 11 +++++++++-- + 1 file changed, 9 insertions(+), 2 deletions(-) + +diff --git a/libcap/cap_alloc.c b/libcap/cap_alloc.c +index 6dab4e6..7456d97 100644 +--- a/libcap/cap_alloc.c ++++ b/libcap/cap_alloc.c +@@ -81,8 +81,15 @@ char *_libcap_strdup(const char *old) + errno = EINVAL; + return NULL; + } +- +- raw_data = malloc( sizeof(__u32) + strlen(old) + 1 ); ++ size_t len; ++ len = strlen(old); ++ if ((len & 0x3fffffff) != len) { ++ _cap_debug("len is too long for libcap to manage"); ++ errno = EINVAL; ++ return NULL; ++ } ++ len += sizeof(__u32) + 1; ++ raw_data = malloc(len); + if (raw_data == NULL) { + errno = ENOMEM; + return NULL; +-- +2.42.0 + diff --git a/0002-psx.c-fix-CVE-2023-2602.patch b/0002-psx.c-fix-CVE-2023-2602.patch new file mode 100644 index 0000000..a297465 --- /dev/null +++ b/0002-psx.c-fix-CVE-2023-2602.patch @@ -0,0 +1,25 @@ +From 5abae730d176107642d5d24cc14f27595ca88a69 Mon Sep 17 00:00:00 2001 +From: Carlos Rodriguez-Fernandez +Date: Wed, 22 Nov 2023 07:55:04 -0700 +Subject: [PATCH 2/2] psx.c:fix CVE-2023-2602 + +--- + psx/psx.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/psx/psx.c b/psx/psx.c +index 4de3653..eec6db8 100644 +--- a/psx/psx.c ++++ b/psx/psx.c +@@ -478,7 +478,7 @@ int __wrap_pthread_create(pthread_t *thread, const pthread_attr_t *attr, + pthread_sigmask(SIG_BLOCK, &sigbit, NULL); + + int ret = __real_pthread_create(thread, attr, _psx_start_fn, starter); +- if (ret == -1) { ++ if (ret > 0) { + psx_new_state(_PSX_CREATE, _PSX_IDLE); + memset(starter, 0, sizeof(*starter)); + free(starter); +-- +2.42.0 + diff --git a/0003-Bug-fixes-identified-by-static-code-analysis.patch b/0003-Bug-fixes-identified-by-static-code-analysis.patch new file mode 100644 index 0000000..6365d12 --- /dev/null +++ b/0003-Bug-fixes-identified-by-static-code-analysis.patch @@ -0,0 +1,101 @@ +From f7e3aeaf41480a8cfd255dd198f16af9e5e99e5b Mon Sep 17 00:00:00 2001 +From: "Andrew G. Morgan" +Date: Wed, 21 Apr 2021 20:08:50 -0700 +Subject: [PATCH 3/3] Bug fixes identified by static code analysis. + +Analysis and much of this commit was contributed by Zoltan +Fridrich of Redhat. + +Signed-off-by: Andrew G. Morgan +--- + pam_cap/pam_cap.c | 9 ++++----- + progs/capsh.c | 30 ++++++++++++++++++++++-------- + 2 files changed, 26 insertions(+), 13 deletions(-) + +diff --git a/pam_cap/pam_cap.c b/pam_cap/pam_cap.c +index 6927f7b..5b48b06 100644 +--- a/pam_cap/pam_cap.c ++++ b/pam_cap/pam_cap.c +@@ -218,7 +218,7 @@ static int set_capabilities(struct pam_cap_s *cs) + if (!cap_set_proc(cap_s)) { + ok = 1; + } +- goto cleanup_cap_s; ++ goto cleanup_conf; + } + + iab = cap_iab_from_text(conf_caps); +@@ -238,10 +238,9 @@ cleanup_conf: + _pam_drop(conf_caps); + + cleanup_cap_s: +- if (cap_s) { +- cap_free(cap_s); +- cap_s = NULL; +- } ++ cap_free(cap_s); ++ cap_s = NULL; ++ + return ok; + } + +diff --git a/progs/capsh.c b/progs/capsh.c +index a39ceeb..0507ea4 100644 +--- a/progs/capsh.c ++++ b/progs/capsh.c +@@ -336,8 +336,8 @@ static void arg_change_amb(const char *arg_names, cap_flag_value_t set) + */ + static char *find_self(const char *arg0) + { +- int i; +- char *parts, *dir, *scratch; ++ int i, status=1; ++ char *p = NULL, *parts, *dir, *scratch; + const char *path; + + for (i = strlen(arg0)-1; i >= 0 && arg0[i] != '/'; i--); +@@ -352,21 +352,35 @@ static char *find_self(const char *arg0) + } + + parts = strdup(path); ++ if (parts == NULL) { ++ fprintf(stderr, "insufficient memory for parts of path\n"); ++ exit(1); ++ } ++ + scratch = malloc(2+strlen(path)+strlen(arg0)); +- if (parts == NULL || scratch == NULL) { ++ if (scratch == NULL) { + fprintf(stderr, "insufficient memory for path building\n"); +- exit(1); ++ goto free_parts; + } + +- for (i=0; (dir = strtok(parts, ":")); parts = NULL) { ++ for (i=0, p = parts; (dir = strtok(p, ":")); p = NULL) { + sprintf(scratch, "%s/%s", dir, arg0); + if (access(scratch, X_OK) == 0) { +- return scratch; ++ status = 0; ++ break; + } + } ++ if (status) { ++ fprintf(stderr, "unable to find executable '%s' in PATH\n", arg0); ++ free(scratch); ++ } + +- fprintf(stderr, "unable to find executable '%s' in PATH\n", arg0); +- exit(1); ++free_parts: ++ free(parts); ++ if (status) { ++ exit(status); ++ } ++ return scratch; + } + + int main(int argc, char *argv[], char *envp[]) +-- +2.42.0 + diff --git a/0004-Fruit-of-more-static-analysis-results.patch b/0004-Fruit-of-more-static-analysis-results.patch new file mode 100644 index 0000000..56d604e --- /dev/null +++ b/0004-Fruit-of-more-static-analysis-results.patch @@ -0,0 +1,108 @@ +From bcfd79b07f60746e84899d2854800f161804d5fb Mon Sep 17 00:00:00 2001 +From: "Andrew G. Morgan" +Date: Thu, 22 Apr 2021 20:06:32 -0700 +Subject: [PATCH] Fruit of more static analysis results + +Fixes for further analysis issues from Zoltan Fridrich of Redhat. + +Signed-off-by: Andrew G. Morgan +--- + progs/capsh.c | 24 ++++++++++++++++++------ + psx/psx.c | 4 ++++ + tests/libcap_launch_test.c | 10 +++++++++- + 3 files changed, 31 insertions(+), 7 deletions(-) + +diff --git a/progs/capsh.c b/progs/capsh.c +index 0507ea4..0d0154a 100644 +--- a/progs/capsh.c ++++ b/progs/capsh.c +@@ -363,7 +363,7 @@ static char *find_self(const char *arg0) + goto free_parts; + } + +- for (i=0, p = parts; (dir = strtok(p, ":")); p = NULL) { ++ for (p = parts; (dir = strtok(p, ":")); p = NULL) { + sprintf(scratch, "%s/%s", dir, arg0); + if (access(scratch, X_OK) == 0) { + status = 0; +@@ -383,6 +383,16 @@ free_parts: + return scratch; + } + ++static long safe_sysconf(int name) ++{ ++ long ans = sysconf(name); ++ if (ans <= 0) { ++ fprintf(stderr, "sysconf(%d) returned a non-positive number: %ld\n", name, ans); ++ exit(1); ++ } ++ return ans; ++} ++ + int main(int argc, char *argv[], char *envp[]) + { + pid_t child; +@@ -631,7 +641,9 @@ int main(int argc, char *argv[], char *envp[]) + * Given we are now in a new directory tree, its good practice + * to start off in a sane location + */ +- status = chdir("/"); ++ if (status == 0) { ++ status = chdir("/"); ++ } + + cap_free(orig); + +@@ -732,14 +744,14 @@ int main(int argc, char *argv[], char *envp[]) + gid_t *group_list; + int g_count; + +- length = sysconf(_SC_GETGR_R_SIZE_MAX); ++ length = safe_sysconf(_SC_GETGR_R_SIZE_MAX); + buf = calloc(1, length); + if (NULL == buf) { + fprintf(stderr, "No memory for [%s] operation\n", argv[i]); + exit(1); + } + +- max_groups = sysconf(_SC_NGROUPS_MAX); ++ max_groups = safe_sysconf(_SC_NGROUPS_MAX); + group_list = calloc(max_groups, sizeof(gid_t)); + if (NULL == group_list) { + fprintf(stderr, "No memory for gid list\n"); +@@ -755,8 +767,7 @@ int main(int argc, char *argv[], char *envp[]) + } + if (!isdigit(*ptr)) { + struct group *g, grp; +- getgrnam_r(ptr, &grp, buf, length, &g); +- if (NULL == g) { ++ if (getgrnam_r(ptr, &grp, buf, length, &g) || NULL == g) { + fprintf(stderr, "Failed to identify gid for group [%s]\n", ptr); + exit(1); + } +@@ -849,6 +860,7 @@ int main(int argc, char *argv[], char *envp[]) + argv[argc] = NULL; + execve(argv[i], argv+i, envp); + fprintf(stderr, "execve '%s' failed!\n", argv[i]); ++ free(argv[i]); + exit(1); + } else if (!strncmp("--shell=", argv[i], 8)) { + shell = argv[i]+8; +diff --git a/psx/psx.c b/psx/psx.c +index eec6db8..1ace898 100644 +--- a/psx/psx.c ++++ b/psx/psx.c +@@ -454,6 +454,10 @@ static void *_psx_start_fn(void *data) { + int __wrap_pthread_create(pthread_t *thread, const pthread_attr_t *attr, + void *(*start_routine) (void *), void *arg) { + psx_starter_t *starter = calloc(1, sizeof(psx_starter_t)); ++ if (starter == NULL) { ++ perror("failed at thread creation"); ++ exit(1); ++ } + starter->fn = start_routine; + starter->arg = arg; + /* +-- +2.42.0 + diff --git a/gating.yaml b/gating.yaml index 4a1c38a..fba44d0 100644 --- a/gating.yaml +++ b/gating.yaml @@ -2,6 +2,19 @@ product_versions: - fedora-* decision_context: bodhi_update_push_testing +subject_type: koji_build rules: - - !PassingTestCaseRule {test_case_name: dist.depcheck} - - !PassingTestCaseRule {test_case_name: dist.abicheck} + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.rpmdeplint.functional} + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.rpminspect.static-analysis} + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.installability.functional} + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional} +--- !Policy +product_versions: + - fedora-* +decision_context: bodhi_update_push_stable +subject_type: koji_build +rules: + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.rpmdeplint.functional} + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.rpminspect.static-analysis} + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.installability.functional} + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional} diff --git a/libcap.rpmlintrc b/libcap.rpmlintrc new file mode 100644 index 0000000..e7a5e81 --- /dev/null +++ b/libcap.rpmlintrc @@ -0,0 +1,2 @@ +addFilter('.*static-library-without-debuginfo.*') +addFilter('.*pam-unauthorized-module.*') diff --git a/libcap.spec b/libcap.spec index c5d5c92..7fad386 100644 --- a/libcap.spec +++ b/libcap.spec @@ -1,12 +1,16 @@ Name: libcap Version: 2.48 -Release: 6%{?dist} +Release: 8%{?dist} Summary: Library for getting and setting POSIX.1e capabilities URL: https://sites.google.com/site/fullycapable/ License: BSD or GPLv2 Source: https://git.kernel.org/pub/scm/libs/libcap/libcap.git/snapshot/%{name}-%{version}.tar.gz Patch0: libcap-use-compiler-flag-options.patch +Patch1: 0001-cap_alloc.c-fix-CVE-2023-2603.patch +Patch2: 0002-psx.c-fix-CVE-2023-2602.patch +Patch3: 0003-Bug-fixes-identified-by-static-code-analysis.patch +Patch4: 0004-Fruit-of-more-static-analysis-results.patch BuildRequires: libattr-devel pam-devel perl-interpreter gcc BuildRequires: make @@ -83,6 +87,12 @@ chmod +x %{buildroot}/%{_libdir}/*.so.* %changelog +* Tue Dec 12 2023 Carlos Rodriguez-Fernandez - 2.48-8 +- Backport bug fixes identified by static analysis + +* Wed Nov 22 2023 Carlos Rodriguez-Fernandez - 2.48-7 +- Backport fix for CVE-2023-2602 and CVE-2023-2603 + * Thu Jan 19 2023 Fedora Release Engineering - 2.48-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild diff --git a/plans/main.fmf b/plans/main.fmf new file mode 100644 index 0000000..71d864c --- /dev/null +++ b/plans/main.fmf @@ -0,0 +1,5 @@ +summary: Basic smoke test for libcap +discover: + how: fmf +execute: + how: tmt diff --git a/tests/capsh-basic-functionality/Makefile b/tests/capsh-basic-functionality/Makefile deleted file mode 100644 index 49f35ed..0000000 --- a/tests/capsh-basic-functionality/Makefile +++ /dev/null @@ -1,64 +0,0 @@ -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Makefile of /CoreOS/libcap/Sanity/capsh-basic-functionality -# Description: tests basic functionality -# Author: Karel Srot -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Copyright (c) 2017 Red Hat, Inc. -# -# This copyrighted material is made available to anyone wishing -# to use, modify, copy, or redistribute it subject to the terms -# and conditions of the GNU General Public License version 2. -# -# This program is distributed in the hope that it will be -# useful, but WITHOUT ANY WARRANTY; without even the implied -# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR -# PURPOSE. See the GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public -# License along with this program; if not, write to the Free -# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, -# Boston, MA 02110-1301, USA. -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -export TEST=/CoreOS/libcap/Sanity/capsh-basic-functionality -export TESTVERSION=1.0 - -BUILT_FILES= - -FILES=$(METADATA) runtest.sh Makefile PURPOSE - -.PHONY: all install download clean - -run: $(FILES) build - ./runtest.sh - -build: $(BUILT_FILES) - test -x runtest.sh || chmod a+x runtest.sh - -clean: - rm -f *~ $(BUILT_FILES) - - -include /usr/share/rhts/lib/rhts-make.include - -$(METADATA): Makefile - @echo "Owner: Karel Srot " > $(METADATA) - @echo "Name: $(TEST)" >> $(METADATA) - @echo "TestVersion: $(TESTVERSION)" >> $(METADATA) - @echo "Path: $(TEST_DIR)" >> $(METADATA) - @echo "Description: tests basic functionality" >> $(METADATA) - @echo "Type: Sanity" >> $(METADATA) - @echo "TestTime: 5m" >> $(METADATA) - @echo "RunFor: libcap" >> $(METADATA) - @echo "Requires: libcap" >> $(METADATA) - @echo "Priority: Normal" >> $(METADATA) - @echo "License: GPLv2" >> $(METADATA) - @echo "Confidential: no" >> $(METADATA) - @echo "Destructive: no" >> $(METADATA) - @echo "Releases: -RHEL4 -RHELClient5 -RHELServer5 -RHEL6" >> $(METADATA) - - rhts-lint $(METADATA) diff --git a/tests/capsh-basic-functionality/PURPOSE b/tests/capsh-basic-functionality/PURPOSE deleted file mode 100644 index 810902f..0000000 --- a/tests/capsh-basic-functionality/PURPOSE +++ /dev/null @@ -1,3 +0,0 @@ -PURPOSE of /CoreOS/libcap/Sanity/capsh-basic-functionality -Description: tests basic functionality -Author: Karel Srot diff --git a/tests/capsh-basic-functionality/runtest.sh b/tests/capsh-basic-functionality/runtest.sh deleted file mode 100755 index 6102418..0000000 --- a/tests/capsh-basic-functionality/runtest.sh +++ /dev/null @@ -1,123 +0,0 @@ -#!/bin/bash -# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# runtest.sh of /CoreOS/libcap/Sanity/capsh-basic-functionality -# Description: tests basic functionality -# Author: Karel Srot -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Copyright (c) 2017 Red Hat, Inc. -# -# This copyrighted material is made available to anyone wishing -# to use, modify, copy, or redistribute it subject to the terms -# and conditions of the GNU General Public License version 2. -# -# This program is distributed in the hope that it will be -# useful, but WITHOUT ANY WARRANTY; without even the implied -# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR -# PURPOSE. See the GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public -# License along with this program; if not, write to the Free -# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, -# Boston, MA 02110-1301, USA. -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -# Include Beaker environment -. /usr/bin/rhts-environment.sh || exit 1 -. /usr/share/beakerlib/beakerlib.sh || exit 1 - -PACKAGE="libcap" - -rlJournalStart - rlPhaseStartSetup - rlAssertRpm $PACKAGE - rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" - rlRun "pushd $TmpDir" - rlRun "useradd -m libcap_tester" - rlPhaseEnd - - rlPhaseStartTest "Remove the listed capabilities from the prevailing bounding set" - rlRun -s "capsh --drop=cap_net_raw -- -c 'getpcaps \$\$'" - rlAssertGrep "Capabilities for" $rlRun_LOG - rlAssertNotGrep cap_net_raw $rlRun_LOG - rlRun -s "capsh --drop=cap_net_raw -- -c 'ping localhost -c 1'" 2,126 "Ping without cap_net_raw shoud fail" - rlAssertGrep "Operation not permitted" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "Set the prevailing process capabilities" - rlRun -s "capsh --caps=cap_chown+p --print" - rlAssertGrep "Current: = cap_chown+p" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "Set the inheritable set of capabilities" - rlRun -s "capsh --inh=cap_chown --print" - rlRun "grep 'Current: = ' $rlRun_LOG | grep 'cap_chown+eip'" - rlRun -s "capsh --inh=cap_chown -- -c 'getpcaps \$\$' 2>&1" - rlAssertGrep "cap_chown+eip" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "Assume the identity of the user nobody" - USERID=`id -u nobody` - GROUPID=`id -g nobody` - rlRun -s "capsh --user=nobody -- -c 'id'" - rlAssertGrep "uid=$USERID(nobody) gid=$GROUPID(nobody) groups=$GROUPID(nobody)" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "Force all uid values to equal to nobody" - rlRun -s "capsh --uid=$USERID -- -c 'id'" - rlAssertGrep "uid=$USERID(nobody) gid=0(root) groups=0(root)" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "Force all gid values to equal to nobody" - rlRun -s "capsh --gid=$GROUPID -- -c 'id'" - rlAssertGrep "uid=0(root) gid=$GROUPID(nobody)" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "Set the supplementary groups" - GROUP2ID=`id -g daemon` - rlRun -s "capsh --groups=${GROUPID},${GROUP2ID} -- -c id" - rlAssertGrep "uid=0(root) gid=0(root) groups=0(root),${GROUP2ID}(daemon),${GROUPID}(nobody)" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "Permit the process to retain its capabilities after a setuid" - CURRENT=`capsh --print | grep 'Current:' | cut -d '+' -f 1` - rlRun -s "capsh --keep=0 --uid=$USERID --print" - rlAssertGrep 'Current: =$' $rlRun_LOG -E - rlRun -s "capsh --keep=1 --uid=$USERID --print" - rlAssertGrep "$CURRENT" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "Decode capabilities" - rlRun "CODE=$( cat /proc/$$/status | awk '/CapEff/ { print $2 }' )" - rlRun "DECODE=$( capsh --decode=$CODE | cut -d '=' -f 2 )" - rlRun "capsh --print | grep 'Current: = $DECODE'" - rlPhaseEnd - - rlPhaseStartTest "Verify the existence of a capability on the system" - rlRun "capsh --supports=cap_net_raw" - rlRun -s "capsh --supports=cap_foo_bar" 1 - rlAssertGrep "cap\[cap_foo_bar\] not recognized by library" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "Verify exit code for unsupported option" - rlRun "capsh --foo bar" 1 - rlPhaseEnd - - rlPhaseStartTest "Run as a regular user" - USERID=`id -u libcap_tester` - rlRun -s "su - libcap_tester -c 'capsh --print'" - rlAssertGrep "Current: =\$" $rlRun_LOG -E - rlAssertGrep "uid=$USERID(libcap_tester)" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartCleanup - rlRun "userdel -r libcap_tester" - rlRun "popd" - rlRun "rm -r $TmpDir" 0 "Removing tmp directory" - rlPhaseEnd -rlJournalPrintText -rlJournalEnd diff --git a/tests/capsh/main.fmf b/tests/capsh/main.fmf new file mode 100644 index 0000000..28d19cd --- /dev/null +++ b/tests/capsh/main.fmf @@ -0,0 +1,2 @@ +summary: capsh tests +description: tests basic capsh functionality diff --git a/tests/capsh/test.sh b/tests/capsh/test.sh new file mode 100755 index 0000000..92a59d0 --- /dev/null +++ b/tests/capsh/test.sh @@ -0,0 +1,94 @@ +#!/bin/bash + +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +rlJournalStart + rlPhaseStartSetup + rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" + rlRun "pushd $TmpDir" + rlRun "useradd -m libcap_tester" + rlPhaseEnd + + rlPhaseStartTest "Should remove capability" + rlRun -s "capsh --drop=cap_sys_admin -- -c 'getpcaps \$\$'" + rlAssertGrep "cap_sys_admin-ep" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartTest "Should prevent the use of removed capability" + rlRun -s "capsh --drop=cap_net_raw -- -c 'ping localhost -e 0 -c 1'" 2,126 "Ping without cap_net_raw shoud fail" + rlAssertGrep "Operation not permitted" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartTest "Should set the prevailing process capabilities" + rlRun -s "capsh --caps=cap_chown+p --print" + rlAssertGrep "^Current:.*cap_chown[+=][ei]?p[ei]?.*" $rlRun_LOG -E + rlPhaseEnd + + rlPhaseStartTest "Should set the inheritable set of capabilities" + rlRun -s "capsh --inh=cap_chown --print" + rlAssertGrep "^Current:.*cap_chown[+=][ep]?i[ep]?.*" $rlRun_LOG -E + rlPhaseEnd + + rlPhaseStartTest "Should set and show the inheritable set of capabilities" + rlRun -s "capsh --inh=cap_chown -- -c 'getpcaps \$\$' 2>&1" + rlAssertGrep ".*cap_chown[+=][ep]?i[ep]?.*" $rlRun_LOG -E + rlPhaseEnd + + rlPhaseStartTest "Should assume the identity of the user nobody" + USERID=`id -u nobody` + GROUPID=`id -g nobody` + rlRun -s "capsh --user=nobody -- -c 'id'" + rlAssertGrep "uid=$USERID(nobody) gid=$GROUPID(nobody) groups=$GROUPID(nobody)" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartTest "Should assume the nobody identity with uid" + USERID=`id -u nobody` + rlRun -s "capsh --uid=$USERID -- -c 'id'" + rlAssertGrep "uid=$USERID(nobody) gid=0(root) groups=0(root)" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartTest "Should assume guid of nobody" + GROUPID=`id -g nobody` + rlRun -s "capsh --gid=$GROUPID -- -c 'id'" + rlAssertGrep "uid=0(root) gid=$GROUPID(nobody)" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartTest "Should assume the supplementary groups" + GROUPID=`id -g nobody` + GROUP2ID=`id -g daemon` + rlRun -s "capsh --groups=${GROUPID},${GROUP2ID} -- -c id" + rlAssertGrep "uid=0(root) gid=0(root) groups=0(root),${GROUP2ID}(daemon),${GROUPID}(nobody)" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartTest "Should decode capabilities" + rlRun "CODE=$( cat /proc/$$/status | awk '/CapEff/ { print $2 }' )" + rlRun "DECODE=$( capsh --decode=$CODE | cut -d '=' -f 2 )" + rlRun "capsh --print | grep \"$DECODE\"" + rlPhaseEnd + + rlPhaseStartTest "Should detect the existence of a capability on the system" + rlRun "capsh --supports=cap_net_raw" + rlPhaseEnd + + rlPhaseStartTest "Should detect the absence of a capability on the system" + rlRun -s "capsh --supports=cap_foo_bar" 1 + rlAssertGrep "cap\[cap_foo_bar\] not recognized by library" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartTest "Should error for unsupported option" + rlRun "capsh --foo bar" 1 + rlPhaseEnd + + rlPhaseStartTest "Should run as a regular user" + USERID=`id -u libcap_tester` + rlRun -s "su - libcap_tester -c 'capsh --print'" + rlAssertGrep "Current: =\$" $rlRun_LOG -E + rlAssertGrep "uid=$USERID(libcap_tester)" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartCleanup + rlRun "userdel -r libcap_tester" + rlRun "popd" + rlRun "rm -r $TmpDir" 0 "Removing tmp directory" + rlPhaseEnd +rlJournalEnd diff --git a/tests/getcap-setcap/main.fmf b/tests/getcap-setcap/main.fmf new file mode 100644 index 0000000..bce9fcd --- /dev/null +++ b/tests/getcap-setcap/main.fmf @@ -0,0 +1,2 @@ +summary: setcap and getcap tests +description: tests setcap and getcap basic functionality diff --git a/tests/getcap-setcap/test.sh b/tests/getcap-setcap/test.sh new file mode 100755 index 0000000..8384cbb --- /dev/null +++ b/tests/getcap-setcap/test.sh @@ -0,0 +1,98 @@ +#!/bin/bash +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +rlJournalStart + rlPhaseStartSetup + rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" + rlRun "pushd $TmpDir" + rlPhaseEnd + + rlPhaseStartTest "Should set and get capabilities on multiple files" + rlRun "touch test-file-0" + rlRun "touch test-file-1" + rlRun "setcap cap_net_admin+p test-file-0 cap_net_raw+ei test-file-1" + rlRun -s "getcap test-file-0 test-file-1" + rlAssertGrep "test-file-0.*cap_net_admin[+=]p" $rlRun_LOG -E + rlAssertGrep "test-file-1.*cap_net_raw[+=]ei" $rlRun_LOG -E + rlRun "rm -f test-file-0 test-file-1" + rlPhaseEnd + + rlPhaseStartTest "Should set capabilities via stdin" + rlRun "touch test-file-0" + rlRun "echo -e 'cap_net_raw+p\ncap_net_admin+p' > input" + rlRun -s "setcap - test-file-0 < input" + rlAssertGrep "Please" $rlRun_LOG + rlRun -s "getcap test-file-0" + rlAssertGrep "cap_net_admin,cap_net_raw[+=]p" $rlRun_LOG -E + rlRun "rm -f test-file-0" + rlPhaseEnd + + rlPhaseStartTest "Should set capabilities quietly via stdin" + rlRun "touch test-file-0" + rlRun "echo -e 'cap_net_raw+p' > input" + rlRun -s "setcap -q - test-file-0 < input" + rlAssertNotGrep "Please" $rlRun_LOG + rlRun -s "getcap test-file-0" + rlAssertGrep "cap_net_raw[+=]p" $rlRun_LOG -E + rlRun "rm -f test-file-0" + rlPhaseEnd + + rlPhaseStartTest "Should remove capabilities" + rlRun "touch test-file-0" + rlRun "setcap cap_net_admin+p test-file-0" + rlRun "setcap -r test-file-0" + rlRun -s "getcap test-file-0" + rlAssertNotGrep "cap_net_admin" $rlRun_LOG + rlRun "rm -f test-file-0" + rlPhaseEnd + + rlPhaseStartTest "Should list capabilities recursively" + rlRun "touch test-file-0" + rlRun "mkdir test-dir-1" + rlRun "touch test-dir-1/test-file-1" + rlRun "setcap cap_net_admin+p test-file-0 cap_net_raw+ei test-dir-1/test-file-1" + rlRun -s "getcap -r *" + rlAssertGrep "^test-file-0.*cap_net_admin[+=]p\$" $rlRun_LOG -E + rlAssertGrep "^test-dir-1/test-file-1.*cap_net_raw[+=]ei\$" $rlRun_LOG -E + rlRun "rm -f test-file-0" + rlRun "rm -rf test-dir-1" + rlPhaseEnd + + rlPhaseStartTest "listing capabilities verbosely" + rlRun "touch test-file-0" + rlRun "mkdir test-dir-1" + rlRun "touch test-dir-1/test-file-1" + rlRun "touch test-dir-1/test-file-2" + rlRun "setcap cap_net_admin+p test-file-0 cap_net_raw+ei test-dir-1/test-file-1" + rlRun -s "getcap -v -r *" + rlAssertGrep "^test-file-0.*cap_net_admin[+=]p\$" $rlRun_LOG -E + rlAssertGrep "^test-dir-1/test-file-1.*cap_net_raw[+=]ei\$" $rlRun_LOG -E + rlAssertGrep "^test-dir-1/test-file-2\$" $rlRun_LOG -E + rlRun "rm -f test-file-0" + rlRun "rm -rf test-dir-1" + rlPhaseEnd + + rlPhaseStartTest "Should setcap print help" + rlRun -s "setcap -h" + rlAssertGrep "usage" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartTest "Should getcap print help" + rlRun -s "getcap -h" + rlAssertGrep "usage" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartTest "setcap should exit with 1 on invalid arguments" + rlRun -s "setcap foo bar" 1 + rlAssertGrep "Invalid" $rlRun_LOG -i + rlPhaseEnd + rlPhaseStartTest "getcap should exit with 1 on invalid arguments" + rlRun -s "getcap -f oo" 1 + rlAssertGrep "Invalid" $rlRun_LOG -i + rlPhaseEnd + + rlPhaseStartCleanup + rlRun "popd" + rlRun "rm -r $TmpDir" 0 "Removing tmp directory" + rlPhaseEnd +rlJournalEnd diff --git a/tests/libcap-devel/main.fmf b/tests/libcap-devel/main.fmf new file mode 100644 index 0000000..3381c96 --- /dev/null +++ b/tests/libcap-devel/main.fmf @@ -0,0 +1,2 @@ +summary: libcap-devel tests +description: tests libcap-devel functionality diff --git a/tests/sanity-tests/test-libcap.c b/tests/libcap-devel/test-libcap.c similarity index 100% rename from tests/sanity-tests/test-libcap.c rename to tests/libcap-devel/test-libcap.c diff --git a/tests/libcap-devel/test.sh b/tests/libcap-devel/test.sh new file mode 100755 index 0000000..3c4fd93 --- /dev/null +++ b/tests/libcap-devel/test.sh @@ -0,0 +1,17 @@ +#!/bin/bash +. /usr/share/beakerlib/beakerlib.sh || exit 1 + + +rlJournalStart + rlPhaseStartSetup + rlRun "gcc -lcap -lcmocka -Wall -g3 -o test-libcap test-libcap.c" + rlPhaseEnd + + rlPhaseStartTest + rlRun "./test-libcap" + rlPhaseEnd + + rlPhaseStartCleanup + rlRun "rm test-libcap" + rlPhaseEnd +rlJournalEnd diff --git a/tests/main.fmf b/tests/main.fmf new file mode 100644 index 0000000..c7122a2 --- /dev/null +++ b/tests/main.fmf @@ -0,0 +1,9 @@ +test: ./test.sh +framework: beakerlib +require: + - libcap + - libcap-devel + - libcmocka + - libcmocka-devel + - gcc + - iputils diff --git a/tests/manpages/main.fmf b/tests/manpages/main.fmf new file mode 100644 index 0000000..3a97d78 --- /dev/null +++ b/tests/manpages/main.fmf @@ -0,0 +1,2 @@ +summary: man pages install smoke tests +description: verify that the man pages are installed correctly diff --git a/tests/manpages/test.sh b/tests/manpages/test.sh new file mode 100755 index 0000000..0796a1f --- /dev/null +++ b/tests/manpages/test.sh @@ -0,0 +1,19 @@ +#!/bin/bash +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +expected_manpages=( + 'capsh(1)' + 'libcap(3)' # there are many more but if these are present then it verifies it because of the glob install + 'libpsx(3)' + 'getcap(8)' + 'getpcaps(8)' + 'setcap(8)' +) + +rlJournalStart + for page in "${expected_manpages[@]}"; do + rlPhaseStartTest "test ${page}" + rlRun "man --pager=cat '${page}'" + rlPhaseEnd + done +rlJournalEnd diff --git a/tests/pam_cap-so-sanity-test/Makefile b/tests/pam_cap-so-sanity-test/Makefile deleted file mode 100644 index 3f30e80..0000000 --- a/tests/pam_cap-so-sanity-test/Makefile +++ /dev/null @@ -1,64 +0,0 @@ -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Makefile of /CoreOS/libcap/Sanity/pam_cap-so-sanity-test -# Description: basic functionality test for pam_cap.so module -# Author: Karel Srot -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Copyright (c) 2017 Red Hat, Inc. -# -# This copyrighted material is made available to anyone wishing -# to use, modify, copy, or redistribute it subject to the terms -# and conditions of the GNU General Public License version 2. -# -# This program is distributed in the hope that it will be -# useful, but WITHOUT ANY WARRANTY; without even the implied -# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR -# PURPOSE. See the GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public -# License along with this program; if not, write to the Free -# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, -# Boston, MA 02110-1301, USA. -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -export TEST=/CoreOS/libcap/Sanity/pam_cap-so-sanity-test -export TESTVERSION=1.0 - -BUILT_FILES= - -FILES=$(METADATA) runtest.sh Makefile PURPOSE - -.PHONY: all install download clean - -run: $(FILES) build - ./runtest.sh - -build: $(BUILT_FILES) - test -x runtest.sh || chmod a+x runtest.sh - -clean: - rm -f *~ $(BUILT_FILES) - - -include /usr/share/rhts/lib/rhts-make.include - -$(METADATA): Makefile - @echo "Owner: Karel Srot " > $(METADATA) - @echo "Name: $(TEST)" >> $(METADATA) - @echo "TestVersion: $(TESTVERSION)" >> $(METADATA) - @echo "Path: $(TEST_DIR)" >> $(METADATA) - @echo "Description: basic functionality test for pam_cap.so module" >> $(METADATA) - @echo "Type: Sanity" >> $(METADATA) - @echo "TestTime: 5m" >> $(METADATA) - @echo "RunFor: libcap" >> $(METADATA) - @echo "Requires: libcap" >> $(METADATA) - @echo "Priority: Normal" >> $(METADATA) - @echo "License: GPLv2" >> $(METADATA) - @echo "Confidential: no" >> $(METADATA) - @echo "Destructive: no" >> $(METADATA) - @echo "Releases: -RHEL4 -RHELClient5 -RHELServer5" >> $(METADATA) - - rhts-lint $(METADATA) diff --git a/tests/pam_cap-so-sanity-test/PURPOSE b/tests/pam_cap-so-sanity-test/PURPOSE deleted file mode 100644 index 9edc2b0..0000000 --- a/tests/pam_cap-so-sanity-test/PURPOSE +++ /dev/null @@ -1,5 +0,0 @@ -PURPOSE of /CoreOS/libcap/Sanity/pam_cap-so-sanity-test -Description: basic functionality test for pam_cap.so module -Author: Karel Srot - -Test if a test user can be granted capabilities via pam_cap.so module. diff --git a/tests/pam_cap-so-sanity-test/runtest.sh b/tests/pam_cap-so-sanity-test/runtest.sh deleted file mode 100755 index be93b30..0000000 --- a/tests/pam_cap-so-sanity-test/runtest.sh +++ /dev/null @@ -1,63 +0,0 @@ -#!/bin/bash -# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# runtest.sh of /CoreOS/libcap/Sanity/pam_cap-so-sanity-test -# Description: basic functionality test for pam_cap.so module -# Author: Karel Srot -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Copyright (c) 2017 Red Hat, Inc. -# -# This copyrighted material is made available to anyone wishing -# to use, modify, copy, or redistribute it subject to the terms -# and conditions of the GNU General Public License version 2. -# -# This program is distributed in the hope that it will be -# useful, but WITHOUT ANY WARRANTY; without even the implied -# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR -# PURPOSE. See the GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public -# License along with this program; if not, write to the Free -# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, -# Boston, MA 02110-1301, USA. -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -# Include Beaker environment -. /usr/bin/rhts-environment.sh || exit 1 -. /usr/share/beakerlib/beakerlib.sh || exit 1 - -PACKAGE="libcap" - -rlJournalStart - rlPhaseStartSetup - rlAssertRpm $PACKAGE - rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" - rlRun "pushd $TmpDir" - rlRun "useradd -m pam_cap_user" - rlRun "useradd -m pam_cap_user2" - rlFileBackup /etc/pam.d/su - [ -f /etc/security/capability.conf ] && rlFileBackup /etc/security/capability.conf - rlRun "echo -e 'cap_net_raw pam_cap_user\nnone *' > /etc/security/capability.conf" - rlRun "sed '1 s/^/auth required pam_cap.so/' -i /etc/pam.d/su" 0 "Configure pam_cap.so in /etc/pam.d/su" - rlPhaseEnd - - rlPhaseStartTest - rlRun "su - pam_cap_user -c 'getpcaps \$\$' &> user1.log" - rlAssertGrep "Capabilities for.* = cap_net_raw" user1.log -E - rlRun "su - pam_cap_user2 -c 'getpcaps \$\$' &> user2.log" - rlAssertNotGrep "cap_net_raw" user2.log - rlPhaseEnd - - rlPhaseStartCleanup - rlRun "userdel -r pam_cap_user" - rlRun "userdel -r pam_cap_user2" - rlFileRestore - rlRun "popd" - rlRun "rm -r $TmpDir" 0 "Removing tmp directory" - rlPhaseEnd -rlJournalPrintText -rlJournalEnd diff --git a/tests/pam_cap/main.fmf b/tests/pam_cap/main.fmf new file mode 100644 index 0000000..15277dc --- /dev/null +++ b/tests/pam_cap/main.fmf @@ -0,0 +1,2 @@ +summary: pam_cap.so tests +description: tests pam_cap.so functionality diff --git a/tests/pam_cap/test.sh b/tests/pam_cap/test.sh new file mode 100755 index 0000000..035edd9 --- /dev/null +++ b/tests/pam_cap/test.sh @@ -0,0 +1,32 @@ +#!/bin/bash +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +rlJournalStart + rlPhaseStartSetup + rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" + rlRun "pushd $TmpDir" + rlRun "useradd -m pam_cap_user" + rlRun "useradd -m pam_cap_user2" + rlFileBackup /etc/pam.d/su + [ -f /etc/security/capability.conf ] && rlFileBackup /etc/security/capability.conf + rlRun "echo -e 'cap_net_raw pam_cap_user\nnone *' > /etc/security/capability.conf" + rlRun "sed '1 s/^/auth required pam_cap.so/' -i /etc/pam.d/su" 0 "Configure pam_cap.so in /etc/pam.d/su" + rlPhaseEnd + + rlPhaseStartTest "Should given pam_cap_user the cap_net_raw capability" + rlRun -s "su - pam_cap_user -c 'getpcaps \$\$'" + rlAssertGrep ".*cap_net_raw[+=].*" $rlRun_LOG -E + rlPhaseEnd + rlPhaseStartTest "The user pam_cap_user2 should not have the cap_net_raw capability" + rlRun -s "su - pam_cap_user2 -c 'getpcaps \$\$'" + rlAssertNotGrep "cap_net_raw" $rlRun_LOG + rlPhaseEnd + + rlPhaseStartCleanup + rlRun "userdel -r pam_cap_user" + rlRun "userdel -r pam_cap_user2" + rlFileRestore + rlRun "popd" + rlRun "rm -r $TmpDir" 0 "Removing tmp directory" + rlPhaseEnd +rlJournalEnd diff --git a/tests/pkg-config-libcap-pc-addition/Makefile b/tests/pkg-config-libcap-pc-addition/Makefile deleted file mode 100644 index 57b4cd6..0000000 --- a/tests/pkg-config-libcap-pc-addition/Makefile +++ /dev/null @@ -1,65 +0,0 @@ -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Makefile of /CoreOS/libcap/Sanity/pkg-config-libcap-pc-addition -# Description: Test for BZ#1425490 (Missing libcap.pc) -# Author: Karel Srot -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Copyright (c) 2017 Red Hat, Inc. -# -# This copyrighted material is made available to anyone wishing -# to use, modify, copy, or redistribute it subject to the terms -# and conditions of the GNU General Public License version 2. -# -# This program is distributed in the hope that it will be -# useful, but WITHOUT ANY WARRANTY; without even the implied -# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR -# PURPOSE. See the GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public -# License along with this program; if not, write to the Free -# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, -# Boston, MA 02110-1301, USA. -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -export TEST=/CoreOS/libcap/Sanity/pkg-config-libcap-pc-addition -export TESTVERSION=1.0 - -BUILT_FILES= - -FILES=$(METADATA) runtest.sh Makefile PURPOSE - -.PHONY: all install download clean - -run: $(FILES) build - ./runtest.sh - -build: $(BUILT_FILES) - test -x runtest.sh || chmod a+x runtest.sh - -clean: - rm -f *~ $(BUILT_FILES) - - -include /usr/share/rhts/lib/rhts-make.include - -$(METADATA): Makefile - @echo "Owner: Karel Srot " > $(METADATA) - @echo "Name: $(TEST)" >> $(METADATA) - @echo "TestVersion: $(TESTVERSION)" >> $(METADATA) - @echo "Path: $(TEST_DIR)" >> $(METADATA) - @echo "Description: Test for BZ#1425490 (Missing libcap.pc)" >> $(METADATA) - @echo "Type: Sanity" >> $(METADATA) - @echo "TestTime: 5m" >> $(METADATA) - @echo "RunFor: libcap" >> $(METADATA) - @echo "Requires: libcap libcap-devel pkgconfig" >> $(METADATA) - @echo "Priority: Normal" >> $(METADATA) - @echo "License: GPLv2" >> $(METADATA) - @echo "Confidential: no" >> $(METADATA) - @echo "Destructive: no" >> $(METADATA) - @echo "Bug: 1425490" >> $(METADATA) - @echo "Releases: -RHEL4 -RHELClient5 -RHELServer5 -RHEL6" >> $(METADATA) - - rhts-lint $(METADATA) diff --git a/tests/pkg-config-libcap-pc-addition/PURPOSE b/tests/pkg-config-libcap-pc-addition/PURPOSE deleted file mode 100644 index 68dbb0b..0000000 --- a/tests/pkg-config-libcap-pc-addition/PURPOSE +++ /dev/null @@ -1,7 +0,0 @@ -PURPOSE of /CoreOS/libcap/Sanity/pkg-config-libcap-pc-addition -Description: Test for BZ#1425490 (Missing libcap.pc) -Author: Karel Srot -Bug summary: Missing libcap.pc -Bugzilla link: https://bugzilla.redhat.com/show_bug.cgi?id=1425490 - -Checking the presence and sanity of the libcap.pc file. diff --git a/tests/pkg-config-libcap-pc-addition/runtest.sh b/tests/pkg-config-libcap-pc-addition/runtest.sh deleted file mode 100755 index b63ad04..0000000 --- a/tests/pkg-config-libcap-pc-addition/runtest.sh +++ /dev/null @@ -1,62 +0,0 @@ -#!/bin/bash -# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# runtest.sh of /CoreOS/libcap/Sanity/pkg-config-libcap-pc-addition -# Description: Test for BZ#1425490 (Missing libcap.pc) -# Author: Karel Srot -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Copyright (c) 2017 Red Hat, Inc. -# -# This copyrighted material is made available to anyone wishing -# to use, modify, copy, or redistribute it subject to the terms -# and conditions of the GNU General Public License version 2. -# -# This program is distributed in the hope that it will be -# useful, but WITHOUT ANY WARRANTY; without even the implied -# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR -# PURPOSE. See the GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public -# License along with this program; if not, write to the Free -# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, -# Boston, MA 02110-1301, USA. -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -# Include Beaker environment -. /usr/bin/rhts-environment.sh || exit 1 -. /usr/share/beakerlib/beakerlib.sh || exit 1 - -PACKAGE="libcap" - -rlJournalStart - rlPhaseStartSetup - rlAssertRpm $PACKAGE - rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" - rlRun "pushd $TmpDir" - rlPhaseEnd - - rlPhaseStartTest - rlRun "rpm -ql libcap-devel | grep libcap.pc" 0 "There must be libcap.pc" - if [ $? -eq 0 ]; then - PCFILE=$(rpm -ql libcap-devel | grep libcap.pc) - rlRun "pkg-config --libs libcap | grep -- '-lcap'" - VER=$(awk '/Version:/ { print $2 }' $PCFILE | tail -1) - rlRun "pkg-config --modversion libcap | grep $VER" - rlRun -s "pkg-config --print-variables libcap" - rlAssertGrep "^prefix" $rlRun_LOG - rlAssertGrep "^exec_prefix" $rlRun_LOG - rlAssertGrep "^libdir" $rlRun_LOG - rlAssertGrep "^includedir" $rlRun_LOG - fi - rlPhaseEnd - - rlPhaseStartCleanup - rlRun "popd" - rlRun "rm -r $TmpDir" 0 "Removing tmp directory" - rlPhaseEnd -rlJournalPrintText -rlJournalEnd diff --git a/tests/pkg-configs/main.fmf b/tests/pkg-configs/main.fmf new file mode 100644 index 0000000..fca923f --- /dev/null +++ b/tests/pkg-configs/main.fmf @@ -0,0 +1,2 @@ +summary: validates pkg-configs presence. +description: ensures libcap.pc and libpsx.pc are installed diff --git a/tests/pkg-configs/test.sh b/tests/pkg-configs/test.sh new file mode 100755 index 0000000..45f98a4 --- /dev/null +++ b/tests/pkg-configs/test.sh @@ -0,0 +1,44 @@ +#!/bin/bash +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +rlJournalStart + rlPhaseStartSetup + rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" + rlRun "pushd $TmpDir" + rlPhaseEnd + + rlPhaseStartTest "libcap pkg-config should be present and valid" + rlRun "rpm -ql libcap-devel | grep libcap.pc" 0 "There must be libcap.pc" + if [ $? -eq 0 ]; then + PCFILE=$(rpm -ql libcap-devel | grep libcap.pc) + rlRun "pkg-config --libs libcap | grep -- '-lcap'" + VER=$(awk '/Version:/ { print $2 }' $PCFILE | tail -1) + rlRun "pkg-config --modversion libcap | grep $VER" + rlRun -s "pkg-config --print-variables libcap" + rlAssertGrep "^prefix" $rlRun_LOG + rlAssertGrep "^exec_prefix" $rlRun_LOG + rlAssertGrep "^libdir" $rlRun_LOG + rlAssertGrep "^includedir" $rlRun_LOG + fi + rlPhaseEnd + + rlPhaseStartTest "libcap pkg-config should be present and valid" + rlRun "rpm -ql libcap-devel | grep libpsx.pc" 0 "There must be libpsx.pc" + if [ $? -eq 0 ]; then + PCFILE=$(rpm -ql libcap-devel | grep libpsx.pc) + rlRun "pkg-config --libs libpsx | grep -- '-lpsx -lpthread -Wl,-wrap,pthread_create'" + VER=$(awk '/Version:/ { print $2 }' $PCFILE | tail -1) + rlRun "pkg-config --modversion libpsx | grep $VER" + rlRun -s "pkg-config --print-variables libpsx" + rlAssertGrep "^prefix" $rlRun_LOG + rlAssertGrep "^exec_prefix" $rlRun_LOG + rlAssertGrep "^libdir" $rlRun_LOG + rlAssertGrep "^includedir" $rlRun_LOG + fi + rlPhaseEnd + + rlPhaseStartCleanup + rlRun "popd" + rlRun "rm -r $TmpDir" 0 "Removing tmp directory" + rlPhaseEnd +rlJournalEnd diff --git a/tests/sanity-tests/Makefile b/tests/sanity-tests/Makefile deleted file mode 100644 index 9e75815..0000000 --- a/tests/sanity-tests/Makefile +++ /dev/null @@ -1,46 +0,0 @@ -# SPDX-License-Identifier: LGPL-2.1+ -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Makefile of /CoreOS/libcap -# Description: Test if libcap working ok -# Author: Susant Sahani -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -export TEST=/CoreOS/libcap -export TESTVERSION=1.0 - -OBJS = test-libcap.c -CFLAG = -Wall -g3 -CC = gcc -LIBS = -lcap -lcmocka - -test-libcap:${OBJ} - ${CC} ${CFLAGS} ${INCLUDES} -o $@ ${OBJS} ${LIBS} - -run: test-libcap - ./runtest.sh -clean: - -rm -f *~ test-libcap - -.c.o: - ${CC} ${CFLAGS} ${INCLUDES} -c $< - -CC = gcc - -include /usr/share/rhts/lib/rhts-make.include -$(METADATA): Makefile - @echo "Owner: Susant Sahani" > $(METADATA) - @echo "Name: $(TEST)" >> $(METADATA) - @echo "TestVersion: $(TESTVERSION)" >> $(METADATA) - @echo "Path: $(TEST_DIR)" >> $(METADATA) - @echo "Description: Test libcap works ok" >> $(METADATA) - @echo "Type: Sanity" >> $(METADATA) - @echo "TestTime: 5m" >> $(METADATA) - @echo "RunFor: libcap" >> $(METADATA) - @echo "Requires: libcap libcap-devel" >> $(METADATA) - @echo "Priority: Normal" >> $(METADATA) - @echo "License: GPLv2" >> $(METADATA) - @echo "Confidential: no" >> $(METADATA) - @echo "Destructive: no" >> $(METADATA) - @echo "Releases: -Fedora 29" >> $(METADATA) - rhts-lint $(METADATA) diff --git a/tests/sanity-tests/runtest.sh b/tests/sanity-tests/runtest.sh deleted file mode 100755 index 17d83e3..0000000 --- a/tests/sanity-tests/runtest.sh +++ /dev/null @@ -1,34 +0,0 @@ -#!/bin/bash -# SPDX-License-Identifier: LGPL-2.1+ -# ~~~ -# runtest.sh of libcap -# Description: Tests for libcap -# -# Author: Susant Sahani -# Copyright (c) 2018 Red Hat, Inc. -# ~~~ - -# Include Beaker environment -. /usr/share/beakerlib/beakerlib.sh || exit 1 - -PACKAGE="libcap" - -rlJournalStart - rlPhaseStartSetup - rlAssertRpm $PACKAGE - rlRun "cp test-libcap /usr/bin/" - rlPhaseEnd - - rlPhaseStartTest - rlLog "Starting libcap tests ..." - rlRun "/usr/bin/test-libcap" - rlPhaseEnd - - rlPhaseStartCleanup - rlRun "rm /usr/bin/test-libcap" - rlLog "libcap tests done" - rlPhaseEnd -rlJournalPrintText -rlJournalEnd - -rlGetTestState diff --git a/tests/setcap-getcap-basic-functionality/Makefile b/tests/setcap-getcap-basic-functionality/Makefile deleted file mode 100644 index 02ce5d5..0000000 --- a/tests/setcap-getcap-basic-functionality/Makefile +++ /dev/null @@ -1,64 +0,0 @@ -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Makefile of /CoreOS/libcap/Sanity/setcap-getcap-basic-functionality -# Description: test basic functionality -# Author: Karel Srot -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Copyright (c) 2017 Red Hat, Inc. -# -# This copyrighted material is made available to anyone wishing -# to use, modify, copy, or redistribute it subject to the terms -# and conditions of the GNU General Public License version 2. -# -# This program is distributed in the hope that it will be -# useful, but WITHOUT ANY WARRANTY; without even the implied -# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR -# PURPOSE. See the GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public -# License along with this program; if not, write to the Free -# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, -# Boston, MA 02110-1301, USA. -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -export TEST=/CoreOS/libcap/Sanity/setcap-getcap-basic-functionality -export TESTVERSION=1.0 - -BUILT_FILES= - -FILES=$(METADATA) runtest.sh Makefile PURPOSE - -.PHONY: all install download clean - -run: $(FILES) build - ./runtest.sh - -build: $(BUILT_FILES) - test -x runtest.sh || chmod a+x runtest.sh - -clean: - rm -f *~ $(BUILT_FILES) - - -include /usr/share/rhts/lib/rhts-make.include - -$(METADATA): Makefile - @echo "Owner: Karel Srot " > $(METADATA) - @echo "Name: $(TEST)" >> $(METADATA) - @echo "TestVersion: $(TESTVERSION)" >> $(METADATA) - @echo "Path: $(TEST_DIR)" >> $(METADATA) - @echo "Description: test basic functionality" >> $(METADATA) - @echo "Type: Sanity" >> $(METADATA) - @echo "TestTime: 5m" >> $(METADATA) - @echo "RunFor: libcap" >> $(METADATA) - @echo "Requires: libcap" >> $(METADATA) - @echo "Priority: Normal" >> $(METADATA) - @echo "License: GPLv2" >> $(METADATA) - @echo "Confidential: no" >> $(METADATA) - @echo "Destructive: no" >> $(METADATA) - @echo "Releases: -RHEL4 -RHELClient5 -RHELServer5" >> $(METADATA) - - rhts-lint $(METADATA) diff --git a/tests/setcap-getcap-basic-functionality/PURPOSE b/tests/setcap-getcap-basic-functionality/PURPOSE deleted file mode 100644 index a6ea33d..0000000 --- a/tests/setcap-getcap-basic-functionality/PURPOSE +++ /dev/null @@ -1,3 +0,0 @@ -PURPOSE of /CoreOS/libcap/Sanity/setcap-getcap-basic-functionality -Description: test basic functionality -Author: Karel Srot diff --git a/tests/setcap-getcap-basic-functionality/runtest.sh b/tests/setcap-getcap-basic-functionality/runtest.sh deleted file mode 100755 index 3639367..0000000 --- a/tests/setcap-getcap-basic-functionality/runtest.sh +++ /dev/null @@ -1,98 +0,0 @@ -#!/bin/bash -# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# runtest.sh of /CoreOS/libcap/Sanity/setcap-getcap-basic-functionality -# Description: test basic functionality -# Author: Karel Srot -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -# -# Copyright (c) 2017 Red Hat, Inc. -# -# This copyrighted material is made available to anyone wishing -# to use, modify, copy, or redistribute it subject to the terms -# and conditions of the GNU General Public License version 2. -# -# This program is distributed in the hope that it will be -# useful, but WITHOUT ANY WARRANTY; without even the implied -# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR -# PURPOSE. See the GNU General Public License for more details. -# -# You should have received a copy of the GNU General Public -# License along with this program; if not, write to the Free -# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, -# Boston, MA 02110-1301, USA. -# -# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -# Include Beaker environment -. /usr/bin/rhts-environment.sh || exit 1 -. /usr/share/beakerlib/beakerlib.sh || exit 1 - -PACKAGE="libcap" - -rlJournalStart - rlPhaseStartSetup - rlAssertRpm $PACKAGE - rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" - rlRun "pushd $TmpDir" - rlRun "mkdir mydir && touch file1 mydir/file2 mydir/file3" - rlPhaseEnd - - rlPhaseStartTest "set and get capabilities" - rlRun "setcap cap_net_admin+p file1 cap_net_raw+ei mydir/file2" - rlRun -s "getcap file1 mydir/file2" - rlAssertGrep "file1 = cap_net_admin+p" $rlRun_LOG - rlAssertGrep "mydir/file2 = cap_net_raw+ei" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "set capabilities via stdin" - rlRun "echo -e 'cap_net_raw+p\ncap_net_admin+p' > input" - rlRun -s "setcap - mydir/file3 < input" - rlAssertGrep "Please enter caps for file \[empty line to end\]:" $rlRun_LOG - rlRun "getcap mydir/file3 | grep 'mydir/file3 = cap_net_admin,cap_net_raw+p'" - rlPhaseEnd - - rlPhaseStartTest "set capabilities quietly via stdin" - rlRun "echo -e 'cap_net_raw+p' > input" - rlRun -s "setcap -q - mydir/file3 < input" - rlAssertNotGrep "Please enter caps for file" $rlRun_LOG - rlRun "getcap mydir/file3 | grep 'mydir/file3 = cap_net_raw+p'" - rlPhaseEnd - - rlPhaseStartTest "remove capabilities" - rlRun "setcap -r mydir/file3" - rlRun "getcap | grep file3" 1 "There should be no capabilities listed for file1" - rlPhaseEnd - - rlPhaseStartTest "listing capabilities recursively" - rlRun -s "getcap -r *" - rlAssertGrep "file1 = cap_net_admin+p" $rlRun_LOG - rlAssertGrep "mydir/file2 = cap_net_raw+ei" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartTest "listing capabilities verbosely" - rlRun -s "getcap -v mydir/*" - rlAssertGrep "mydir/file2 = cap_net_raw+ei" $rlRun_LOG - rlAssertGrep "mydir/file3\$" $rlRun_LOG -E - rlPhaseEnd - - rlPhaseStartTest "print help" - rlRun "setcap -h | grep 'usage: setcap'" 1 - rlRun "getcap -h | grep 'usage: getcap'" 1 - rlPhaseEnd - - rlPhaseStartTest "exit with 1 on error" - rlRun -s "setcap foo bar" 1 - rlAssertGrep "fatal error: Invalid argument" $rlRun_LOG - rlRun -s "getcap -f oo" 1 - rlAssertGrep "getcap: invalid option -- 'f'" $rlRun_LOG - rlPhaseEnd - - rlPhaseStartCleanup - rlRun "popd" - rlRun "rm -r $TmpDir" 0 "Removing tmp directory" - rlPhaseEnd -rlJournalPrintText -rlJournalEnd diff --git a/tests/tests.yml b/tests/tests.yml deleted file mode 100644 index fbbca7f..0000000 --- a/tests/tests.yml +++ /dev/null @@ -1,28 +0,0 @@ -- hosts: localhost - roles: - - role: standard-test-beakerlib - tags: - - classic - - container - tests: - - sanity-tests - - pam_cap-so-sanity-test - - setcap-getcap-basic-functionality - required_packages: - - libcap # libcap package required for all tests - - libcap-devel - - libcmocka - - libcmocka-devel - - gcc - - iputils # ping command required for capsh-basic-functionality - -# Tests that run in atomic -- hosts: localhost - roles: - - role: standard-test-beakerlib - tags: - - atomic - tests: - - capsh-basic-functionality - - pam_cap-so-sanity-test - - setcap-getcap-basic-functionality