Compare commits

...
Sign in to create a new pull request.

24 commits

Author SHA1 Message Date
Fedora Release Engineering
b44ccaa1df Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild 2026-07-17 06:25:48 +00:00
Vit Mojzis
fc34171f60 setroubleshoot-plugins-3.3.15-7
- Split multi-command fix_cmds into lists
- catchall: Discourage creating custom policy modules

Note: Swtiched from "Requires" to "Conflicts" with setroubleshoot-server
to remove the circular dependency.
2026-06-18 16:05:45 +02:00
Fedora Release Engineering
a650d518c8 Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild 2026-01-17 17:55:36 +00:00
jan janasek
27717286ea fmf test plan update
updating plan due to new destination of tests and
since there is a dedecated repo for tests (https://gitlab.com/setroubleshoot/tests)
there is no need to have current test directory.

Signed-off-by: Jan Janasek <jjanasek@redhat.com>
2025-09-19 14:41:22 +00:00
Python Maint
691c6b1e53 Rebuilt for Python 3.14.0rc3 bytecode 2025-09-19 14:56:13 +02:00
Python Maint
2c6acc60c5 Rebuilt for Python 3.14.0rc2 bytecode 2025-08-15 15:17:32 +02:00
Fedora Release Engineering
58317166d3 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-25 18:10:51 +00:00
Fedora Release Engineering
8a691be0af Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-19 10:28:23 +00:00
Petr Lautrbach
ae45697aee setroubleshoot-plugin-3.3.15
- restorecon.py: exclude more paths
- Improve disable_ipv6 plugin then_text
- Update generated configuration files
- Update translations
2025-01-06 14:53:46 +01:00
Fedora Release Engineering
6ea678f88f Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild 2024-07-20 05:18:40 +00:00
Milos Malik
0138d422b6 remove the unnecessary tests.yaml file
The repository already contains a TMT test plan (/plans/tests.fmf)
which replaces the tests.yaml file. Let's leave the old STI way of
running tests finally.
2024-04-17 09:55:06 +02:00
Milos Malik
2ad1062d72 run the existing tests via TMT/FMF
Use the TMT/FMF instead of STI for running tests. STI does not respect
the adjust section in main.fmf files of stored tests.

Add missing main.fmf files to tests which are not TMT/FMF enabled.
2024-04-02 13:24:41 +02:00
Fedora Release Engineering
007557e46e Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-27 02:41:44 +00:00
Petr Lautrbach
3e4d0a1baf setroubleshoot-plugins-3.3.14-6
- Update generated configuration files (rhbz#2226425)
- Improve disable_ipv6 plugin then_text
2023-07-26 10:59:38 +02:00
Fedora Release Engineering
b066bbbd7a Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-07-22 01:28:31 +00:00
Fedora Release Engineering
3fdc35208b Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-01-21 03:03:42 +00:00
Petr Lautrbach
60ad8a1851 Migrate License tag to SPDX
https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_1
2022-11-10 09:32:43 +01:00
Fedora Release Engineering
e832770250 Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-07-23 08:26:03 +00:00
Fedora Release Engineering
c6ec1df399 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-01-22 00:44:02 +00:00
Petr Lautrbach
142c889cd2 setroubleshoot-plugins-3.3.14-3
- restorecon.py: exclude more paths (#1960136)
2021-09-03 16:22:46 +02:00
Petr Lautrbach
96233b0392 Drop old tarball from sources 2021-09-03 16:20:12 +02:00
Petr Lautrbach
9aca788f04 restorecon.py: exclude more paths
It doesn't make sense to run restorecon on /sys/ /proc/ and /memfd:
Resolves: rhbz#1960136
2021-09-03 16:17:32 +02:00
Fedora Release Engineering
fd9764ca64 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-07-23 17:25:10 +00:00
Vit Mojzis
0b9f18953a setroubleshoot-plugins-3.3.14-1
- Update translations
2021-03-29 17:33:31 +02:00
10 changed files with 192 additions and 137 deletions

1
.fmf/version Normal file
View file

@ -0,0 +1 @@
1

2
.gitignore vendored
View file

@ -122,3 +122,5 @@ setroubleshoot-plugins-2.1.55.tar.gz
/setroubleshoot-plugins-3.3.10.tar.gz
/setroubleshoot-plugins-3.3.11.tar.gz
/setroubleshoot-plugins-3.3.12.tar.gz
/setroubleshoot-plugins-3.3.14.tar.gz
/setroubleshoot-plugins-3.3.15.tar.gz

View file

@ -0,0 +1,73 @@
From df90bf242b35a9e01f721dd7ad436f1bd5d21616 Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Mon, 9 Mar 2026 22:03:31 +0100
Subject: [PATCH] Split multi-command fix_cmds into lists
This requires
https://gitlab.com/setroubleshoot/setroubleshoot/-/merge_requests/54/diffs?commit_id=d5d13afa86c2bd03952c04a187657ed981c9be7e
to work properly!
---
src/allow_execmod.py | 3 ++-
src/automount_exec_config.py | 3 ++-
src/cvs_data.py | 3 ++-
src/file.py | 2 +-
4 files changed, 7 insertions(+), 4 deletions(-)
diff --git a/src/allow_execmod.py b/src/allow_execmod.py
index 6e1f6bf..0a3995f 100644
--- a/src/allow_execmod.py
+++ b/src/allow_execmod.py
@@ -81,7 +81,8 @@ If you want this to survive a relabel, execute
# semanage fcontext -a -t textrel_shlib_t '$FIX_TARGET_PATH';restorecon -v '$FIX_TARGET_PATH'
"""
- fix_cmd = """/usr/sbin/semanage fcontext -a -t textrel_shlib_t '$FIX_TARGET_PATH';/usr/sbin/restorecon -v '$FIX_TARGET_PATH'"""
+ fix_cmd = ["""/usr/sbin/semanage fcontext -a -t textrel_shlib_t '$FIX_TARGET_PATH'""",
+ """/usr/sbin/restorecon -v '$FIX_TARGET_PATH'"""]
def init_args(self, args):
if len(args) > 0:
diff --git a/src/automount_exec_config.py b/src/automount_exec_config.py
index a64eaf2..81ada8e 100644
--- a/src/automount_exec_config.py
+++ b/src/automount_exec_config.py
@@ -40,7 +40,8 @@ class plugin(Plugin):
If you want to change the file context of $TARGET_PATH so that the automounter can execute it you can execute "chcon -t bin_t $TARGET_PATH". If you want this to survive a relabel, you need to permanently change the file context: execute "semanage fcontext -a -t bin_t '$FIX_TARGET_PATH'".
''')
- fix_cmd = """/usr/sbin/semanage fcontext -a -t bin_t '$FIX_TARGET_PATH';/usr/sbin/restorecon -v '$FIX_TARGET_PATH'"""
+ fix_cmd = ["""/usr/sbin/semanage fcontext -a -t bin_t '$FIX_TARGET_PATH'""",
+ """/usr/sbin/restorecon -v '$FIX_TARGET_PATH'"""]
if_text = 'If you want to allow automounter to execute $TARGET_PATH'
diff --git a/src/cvs_data.py b/src/cvs_data.py
index 7451622..1e75ead 100644
--- a/src/cvs_data.py
+++ b/src/cvs_data.py
@@ -46,7 +46,8 @@ class plugin(Plugin):
do_text = """# semanage fcontext -a -t cvs_data_t '$FIX_TARGET_PATH'
# restorecon -v '$FIX_TARGET_PATH'"""
- fix_cmd = """/usr/sbin/semanage fcontext -a -t cvs_data_t '$FIX_TARGET_PATH';/usr/sbin/restorecon -v '$FIX_TARGET_PATH'"""
+ fix_cmd = ["""/usr/sbin/semanage fcontext -a -t cvs_data_t '$FIX_TARGET_PATH'""",
+ """/usr/sbin/restorecon -v '$FIX_TARGET_PATH'"""]
def __init__(self):
Plugin.__init__(self, __name__)
diff --git a/src/file.py b/src/file.py
index ac24bf9..25f3a43 100644
--- a/src/file.py
+++ b/src/file.py
@@ -66,7 +66,7 @@ home directory from a previous installation that did not use SELinux, 'restoreco
if args == (1,0):
return '/sbin/restorecon -R -v $TARGET_PATH'
else:
- return 'touch /.autorelabel; reboot'
+ return ['touch /.autorelabel', 'reboot']
def init_args(self, args):
if args == (1,0):
--
2.53.0

View file

@ -0,0 +1,36 @@
From 8ad7f4c5528fbbc52a3d391c702102c6fe262d83 Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Tue, 9 Jun 2026 17:27:36 +0200
Subject: [PATCH] catchall: Discourage creating custom policy modules
Update the plugin text to discourage creating custom policy modules by
explaining the lack of support and potential security implications.
---
src/catchall.py | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/src/catchall.py b/src/catchall.py
index 052d6d8..7e4a8fa 100644
--- a/src/catchall.py
+++ b/src/catchall.py
@@ -54,9 +54,14 @@ class plugin(Plugin):
return _('If you believe that $SOURCE_BASE_PATH should be allowed $ACCESS access on $TARGET_CLASS labeled $TARGET_TYPE by default.')
return _('If you believe that $SOURCE_BASE_PATH should be allowed $ACCESS access on the $TARGET_BASE_PATH $TARGET_CLASS by default.')
- then_text = _('You should report this as a bug.\nYou can generate a local policy module to allow this access.')
- do_text = _("""Allow this access for now by executing:
-# ausearch -c '$SOURCE' --raw | audit2allow -M my-$MODULE_NAME
+ then_text = _('''
+ You should report this as a bug.\n
+ If you are certain this access is legitimate and not an intrusion attempt, you
+ can generate a local policy module to allow it.
+ Custom policy modules are not supported as they may weaken the system policy and expose the system to security vulnerabilities.
+ ''')
+
+ do_text = _("""# ausearch -c '$SOURCE' --raw | audit2allow -M my-$MODULE_NAME
# semodule -X 300 -i my-$MODULE_NAME.pp""")
def __init__(self):
--
2.53.0

8
plans/tests.fmf Normal file
View file

@ -0,0 +1,8 @@
summary: basic setroubleshoot-plugins test plan
discover:
how: fmf
url: https://gitlab.com/setroubleshoot/tests.git
filter: "component:setroubleshoot-plugins & tier: 1"
execute:
how: tmt

View file

@ -5,13 +5,15 @@
Summary: Analysis plugins for use with setroubleshoot
Name: setroubleshoot-plugins
Version: 3.3.12
Release: 4%{?dist}
License: GPLv2+
URL: https://github.com/fedora-selinux/setroubleshoot
Source0: https://releases.pagure.org/setroubleshoot/%{name}-%{version}.tar.gz
# git format-patch -N setroubleshoot-plugins-<version> -- plugins
# i=1; for j in 00*patch; do printf "Patch%04d: %s\n" $i $j; i=$((i+1));done
Version: 3.3.15
Release: 8%{?dist}
License: GPL-2.0-or-later
URL: https://gitlab.com/setroubleshoot/plugins
Source0: https://gitlab.com/-/project/24478430/uploads/1d856bff1c9fb16a8c6fc877d7fe91ca/setroubleshoot-plugins-3.3.15.tar.gz
# git format-patch -N setroubleshoot-plugins-<version>
# for j in 00*patch; do printf "Patch: %s\n" $j; done
Patch: 0001-Split-multi-command-fix_cmds-into-lists.patch
Patch: 0002-catchall-Discourage-creating-custom-policy-modules.patch
BuildArch: noarch
# gcc is needed only for ./configure
@ -20,8 +22,8 @@ BuildRequires: gcc
BuildRequires: make
BuildRequires: perl-XML-Parser
BuildRequires: intltool gettext python3-devel
# Introduction of get_package_nvr functions
Requires: setroubleshoot-server >= 3.3.23
# Support for multiple commands in fix_cmd
Conflicts: setroubleshoot-server < 3.3.37
%description
This package provides a set of analysis plugins for use with
@ -30,7 +32,7 @@ data and system data to provide user friendly reports describing how
to interpret SELinux AVC denials.
%prep
%autosetup -p 2
%autosetup -p 1
%build
%configure PYTHON=%{__python3}
@ -49,6 +51,65 @@ rm -rf %{buildroot}
%{_datadir}/setroubleshoot/plugins
%changelog
* Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.15-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Thu May 07 2026 Vit Mojzis <vmojzis@redhat.com> - 3.3.15-7
- Split multi-command fix_cmds into lists
- catchall: Discourage creating custom policy modules
* Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.15-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Sep 19 2025 Python Maint <python-maint@redhat.com> - 3.3.15-5
- Rebuilt for Python 3.14.0rc3 bytecode
* Fri Aug 15 2025 Python Maint <python-maint@redhat.com> - 3.3.15-4
- Rebuilt for Python 3.14.0rc2 bytecode
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.15-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.15-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Mon Jan 06 2025 Petr Lautrbach <lautrbach@redhat.com> - 3.3.15-1
- restorecon.py: exclude more paths
- Improve disable_ipv6 plugin then_text
- Update generated configuration files
- Update translations
* Sat Jul 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.14-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Sat Jan 27 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.14-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Wed Jul 26 2023 Petr Lautrbach <lautrbach@redhat.com> - 3.3.14-8
- Update generated configuration files (rhbz#2226425)
- Improve disable_ipv6 plugin then_text
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.14-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.14-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.14-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Sat Jan 22 2022 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.14-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Fri Sep 3 2021 Petr Lautrbach <plautrba@redhat.com> - 3.3.14-3
- restorecon.py: exclude more paths (#1960136)
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.14-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Mon Mar 29 2021 Vit Mojzis <vmojzis@redhat.com> - 3.3.14-1
- Update translations
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.12-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild

View file

@ -1 +1 @@
SHA512 (setroubleshoot-plugins-3.3.12.tar.gz) = aec345a93aa7cfaea8468c72639dacb89dfc4fa9f1d2ed2e121f5ca20dfd37399877364d95cd8dd548cefcaee4ea818ae4465035a60b6ba18493eb548ef4c87e
SHA512 (setroubleshoot-plugins-3.3.15.tar.gz) = 9741ecd48a7e0cde376ac0f818d94dad32c74acd2afc01ec6f5e3cf74ff9075d4f3406f1a3905cbbdd3833c8c2ef4213deaaf00d0012dbea582eb2b825618d5f

View file

@ -1,50 +0,0 @@
#!/bin/bash
# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
#
# runtest.sh of /CoreOS/setroubleshoot-plugins/Regression/use-of-aliases-in-plugins
# Description: Make sure all types used in setroubleshoot plugins are
# defined in the policy and are not aliases
# Author: Vit Mojzis <vmojzis@redhat.com>
#
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
#
# Copyright (c) 2020 Red Hat, Inc.
#
# This program is free software: you can redistribute it and/or
# modify it under the terms of the GNU General Public License as
# published by the Free Software Foundation, either version 2 of
# the License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be
# useful, but WITHOUT ANY WARRANTY; without even the implied
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
# PURPOSE. See the GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program. If not, see http://www.gnu.org/licenses/.
#
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# Include Beaker environment
. /usr/bin/rhts-environment.sh || exit 1
. /usr/share/beakerlib/beakerlib.sh || exit 1
PACKAGE="setroubleshoot-plugins"
rlJournalStart
rlPhaseStartSetup
rlAssertRpm ${PACKAGE}
rlRun "selinuxenabled" 0
rlPhaseEnd
rlPhaseStartTest "bz#1794807 - look for aliases and undefined types in plugins"
# lists all types not defined in the policy as "type_t not found"
# and all aliases as "alias_t is an alias of type_t"
# all issues are prefixed with a list of offending plugins
# returns 1 if an issue was found
rlRun "./test_aliases.py" 0
rlPhaseEnd
rlJournalPrintText
rlJournalEnd

View file

@ -1,65 +0,0 @@
#!/usr/bin/python3
# lists all types not defined in the policy as "type_t not found"
# and all aliases as "alias_t is an alias of type_t"
# all issues are prefixed with a list of offending plugins
# returns 1 if an issue was found
import subprocess
import sepolicy
import sys
import re
from collections import defaultdict
plugin_path = "/usr/share/setroubleshoot/plugins"
error_code = 0
if len(sys.argv) > 1:
plugin_path = sys.argv[1]
try:
# search all plugin files in given location for the following pattern
# <plugin path>:<delimiter><type name>_t<delimiter>
g = subprocess.check_output('grep -I [^A-Za-z_][A-Za-z][A-Za-z_]*_t[^A-Za-z_] -o {}/*.py'.format(plugin_path),
universal_newlines=True, shell=True)
lines = g.split('\n')
except:
exit(1)
# matches 2 groups: file name and type name
# <path to plugins>(<plugin file name>):<delimiter>(<type name>_t)<delimiter>
reg = re.compile('.*/(.+):[^A-Za-z_]([A-Za-z_]*_t)[^A-Za-z_]')
# generate a dictionary of of all type names used in setroubleshoot plugins
# where types are keys and lists of files where each type appeared are data
found = defaultdict(set)
for l in lines:
m = reg.match(l)
if m is None:
continue
try:
t = m.group(2)
if "_TYPE_" in t:
continue
found[t].add(m.group(1))
except:
# failed to match
continue
for t in sorted(found.keys()):
try:
# try to find each type in system policy
i = next(sepolicy.info(sepolicy.TYPE, t))['name']
if t != i:
# <plugin file names>: alias_t is an alias of type_t
print("{}: {} is an alias of {}".format(", ".join(found[t]), t, i))
error_code = 1
except:
# skip types defined in selinux-policy modules that are not shipped any more
if t not in ["vbetool_t"]:
# <plugin file names>: type_t not found
print("{}: {} not found".format(", ".join(found[t]), t))
error_code = 1
exit(error_code)

View file

@ -1,11 +0,0 @@
- hosts: localhost
roles:
- role: standard-test-beakerlib
tags:
- classic
tests:
- Regression/use-of-aliases-in-plugins
required_packages:
- setroubleshoot-plugins
- selinux-policy-targeted
- python3-policycoreutils