diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/.gitignore b/.gitignore index ba9e517..8535490 100644 --- a/.gitignore +++ b/.gitignore @@ -214,3 +214,5 @@ setroubleshoot-2.2.93.tar.gz /framework-3.3.27.tar.gz /setroubleshoot-3.3.28.tar.gz /setroubleshoot-3.3.29.tar.gz +/setroubleshoot-3.3.30.tar.gz +/setroubleshoot-3.3.31.tar.gz diff --git a/plans/tests.fmf b/plans/tests.fmf new file mode 100644 index 0000000..ec3661a --- /dev/null +++ b/plans/tests.fmf @@ -0,0 +1,6 @@ +summary: Tier 1 setroubleshoot test plan +discover: + how: fmf +execute: + how: tmt + diff --git a/setroubleshoot.spec b/setroubleshoot.spec index a2ac152..104c584 100644 --- a/setroubleshoot.spec +++ b/setroubleshoot.spec @@ -3,20 +3,20 @@ Summary: Helps troubleshoot SELinux problems Name: setroubleshoot -Version: 3.3.29 +Version: 3.3.31 Release: 1%{?dist} -License: GPLv2+ +License: GPL-2.0-or-later URL: https://gitlab.com/setroubleshoot/setroubleshoot Source0: https://gitlab.com/setroubleshoot/setroubleshoot/-/archive/%{version}/setroubleshoot-%{version}.tar.gz Source1: %{name}.tmpfiles Source2: %{name}.sysusers -# git format-patch -N 3.3.29 +# git format-patch -N 3.3.30 # i=1; for j in 00*patch; do printf "Patch%04d: %s\n" $i $j; i=$((i+1));done BuildRequires: gcc BuildRequires: make BuildRequires: libcap-ng-devel -BuildRequires: intltool gettext python3 python3-devel -BuildRequires: desktop-file-utils dbus-glib-devel gtk2-devel libnotify-devel libselinux-devel polkit-devel +BuildRequires: intltool gettext python3 python3-devel python3-setuptools python3-pip +BuildRequires: desktop-file-utils dbus-glib-devel libnotify-devel libselinux-devel polkit-devel BuildRequires: audit-libs-devel >= 3.0.1 BuildRequires: python3-libselinux python3-dasbus python3-gobject gtk3-devel # for the _tmpfilesdir macro @@ -53,7 +53,7 @@ to user preference. The same tools can be run on existing log files. %{pkgguidir} %config(noreplace) %{_sysconfdir}/xdg/autostart/* %{_datadir}/applications/*.desktop -%{_datadir}/appdata/*.appdata.xml +%{_metainfodir}/*.appdata.xml %{_datadir}/dbus-1/services/sealert.service %{_datadir}/icons/hicolor/*/*/* %dir %attr(0755,root,root) %{pkgpythondir} @@ -179,6 +179,7 @@ to user preference. The same tools can be run on existing log files. %{_mandir}/man8/sedispatch.8.gz %{_mandir}/man8/setroubleshootd.8.gz %config /etc/audit/plugins.d/sedispatch.conf +%{_unitdir}/setroubleshootd.service %{_datadir}/dbus-1/system-services/org.fedoraproject.Setroubleshootd.service %{_datadir}/dbus-1/system-services/org.fedoraproject.SetroubleshootPrivileged.service %{_datadir}/polkit-1/actions/org.fedoraproject.setroubleshootfixit.policy @@ -190,6 +191,21 @@ to user preference. The same tools can be run on existing log files. %doc AUTHORS COPYING ChangeLog DBUS.md NEWS README TODO %changelog +* Wed Nov 23 2022 Petr Lautrbach - 3.3.31-1 +- Add a screen reader label to the icon +- seapplet: avoid ValueError when parsing sealert.conf +- doc: Document performance related changes +- Decrease setroubleshootd priority and limit RAM utilization to 1GB +- Use setup from setuptools +- Use `pip install` instead of `setup.py install` + +* Tue Jun 28 2022 Petr Lautrbach - 3.3.30-1 + - Miscellaneous python and build system changes + - Fix couple of typos + - Drop Python2 support + - Use inspect.signature() instead of instead.getargspec() + - Update translations + * Wed Mar 30 2022 Petr Lautrbach - 3.3.29-1 - Introduce email.use_sendmail option - Update translations diff --git a/sources b/sources index 4c7fe3d..61464b9 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (setroubleshoot-3.3.29.tar.gz) = dc3289b0064192d1fcbea6b2049b746b5515f91c5ed3355ff18918bf7ce78a280c6a533b609a3eab153f557acb393e2ee9a401a992fce7894168c1c9f0d85450 +SHA512 (setroubleshoot-3.3.31.tar.gz) = e3ab60a81c851e1a68b43e6e08b6901caa2c507318ccb24992d24cca785cd3fbbb9e3d94b51f214a42ee3aba200d6d92eefaf38b71251794489a51844913ed64 diff --git a/tests/Regression/Report-bugs-on-corresponding-components/main.fmf b/tests/Regression/Report-bugs-on-corresponding-components/main.fmf new file mode 100644 index 0000000..d70bc2c --- /dev/null +++ b/tests/Regression/Report-bugs-on-corresponding-components/main.fmf @@ -0,0 +1,19 @@ +summary: Test for BZ#1811644 (Let setroubleshoot to report bugs on components) +contact: Vit Mojzis +component: + - setroubleshoot +test: ./runtest.sh +framework: beakerlib +recommend: + - setroubleshoot-server + - flatpak-selinux + - tpm2-abrmd-selinux + - container-selinux + - usbguard-selinux + - mysql-selinux + - fapolicyd-selinux +duration: 5m +link: + - relates: https://bugzilla.redhat.com/show_bug.cgi?id=1811644 +extra-summary: /CoreOS/setroubleshoot/Regression/Report-bugs-on-corresponding-components +extra-task: /CoreOS/setroubleshoot/Regression/Report-bugs-on-corresponding-components diff --git a/tests/Regression/Report-bugs-on-corresponding-components/runtest.sh b/tests/Regression/Report-bugs-on-corresponding-components/runtest.sh index e55a506..c3e04b9 100755 --- a/tests/Regression/Report-bugs-on-corresponding-components/runtest.sh +++ b/tests/Regression/Report-bugs-on-corresponding-components/runtest.sh @@ -26,7 +26,6 @@ # ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # Include Beaker environment -. /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 PACKAGE="setroubleshoot" diff --git a/tests/Regression/no-plugin-exception-during-analyses/main.fmf b/tests/Regression/no-plugin-exception-during-analyses/main.fmf new file mode 100644 index 0000000..923b8d6 --- /dev/null +++ b/tests/Regression/no-plugin-exception-during-analyses/main.fmf @@ -0,0 +1,15 @@ +summary: Does setroubleshoot report any 'Plugin Exception' during analyses? +contact: Petr Lautrbach +component: + - setroubleshoot +test: ./runtest.sh +framework: beakerlib +recommend: + - setroubleshoot-server +environment: + AVC_ERROR: +no_avc_check +duration: 5m +link: + - relates: https://bugzilla.redhat.com/show_bug.cgi?id=1784564 +extra-summary: /CoreOS/setroubleshoot/Regression/no-plugin-exception-during-analyses +extra-task: /CoreOS/setroubleshoot/Regression/no-plugin-exception-during-analyses diff --git a/tests/Regression/no-plugin-exception-during-analyses/runtest.sh b/tests/Regression/no-plugin-exception-during-analyses/runtest.sh index f200f49..74ea50a 100755 --- a/tests/Regression/no-plugin-exception-during-analyses/runtest.sh +++ b/tests/Regression/no-plugin-exception-during-analyses/runtest.sh @@ -27,7 +27,6 @@ # ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # Include Beaker environment -. /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 PACKAGE="setroubleshoot" diff --git a/tests/Regression/sealert-s-traceback-invalid-display/main.fmf b/tests/Regression/sealert-s-traceback-invalid-display/main.fmf new file mode 100644 index 0000000..e6c6f7f --- /dev/null +++ b/tests/Regression/sealert-s-traceback-invalid-display/main.fmf @@ -0,0 +1,13 @@ +summary: Test for traceback when using sealert -s with display set to invalid value +contact: Vit Mojzis +component: + - setroubleshoot +test: ./runtest.sh +framework: beakerlib +recommend: + - setroubleshoot +duration: 5m +link: + - relates: https://bugzilla.redhat.com/show_bug.cgi?id=1574434 +extra-summary: /CoreOS/setroubleshoot/Regression/sealert-s-traceback-invalid-display +extra-task: /CoreOS/setroubleshoot/Regression/sealert-s-traceback-invalid-display diff --git a/tests/Regression/sealert-s-traceback-invalid-display/runtest.sh b/tests/Regression/sealert-s-traceback-invalid-display/runtest.sh index 9c5d0fa..55b0fdd 100755 --- a/tests/Regression/sealert-s-traceback-invalid-display/runtest.sh +++ b/tests/Regression/sealert-s-traceback-invalid-display/runtest.sh @@ -26,7 +26,6 @@ # ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # Include Beaker environment -. /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 PACKAGE="setroubleshoot-server" diff --git a/tests/Sanity/public_content/main.fmf b/tests/Sanity/public_content/main.fmf new file mode 100644 index 0000000..f62fd6d --- /dev/null +++ b/tests/Sanity/public_content/main.fmf @@ -0,0 +1,24 @@ +summary: Does the plugin work as expected? +description: |+ + Does the plugin work as expected? + + Default value of ANALYSIS_DELAY can be overriden. + +contact: Milos Malik +component: + - setroubleshoot-plugins +test: ./runtest.sh +framework: beakerlib +recommend: + - setroubleshoot-plugins + - setroubleshoot-server + - audit + - setools-console + - psmisc + - libselinux-utils + - rsyslog +environment: + AVC_ERROR: +no_avc_check +duration: 10m +extra-summary: /CoreOS/setroubleshoot-plugins/Sanity/public_content +extra-task: /CoreOS/setroubleshoot-plugins/Sanity/public_content diff --git a/tests/Sanity/public_content/runtest.sh b/tests/Sanity/public_content/runtest.sh index e5665c8..60fe547 100755 --- a/tests/Sanity/public_content/runtest.sh +++ b/tests/Sanity/public_content/runtest.sh @@ -27,7 +27,6 @@ # ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # Include Beaker environment -. /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 PACKAGE="setroubleshoot-plugins" @@ -69,8 +68,8 @@ rlJournalStart rlRun "sleep ${ANALYSIS_DELAY}" rlRun "ps -efZ | grep setroubleshootd" 0,1 rlRun "sealert -l '*' > ${AFTER}" 0-3 - rlRun "ausearch -m avc -m selinux_err -i -ts recent | grep 'read.*ls.*test-dir.*:rsync_t:.*:samba_share_t:.*tclass=dir'" - rlRun "ausearch -m avc -m selinux_err -i -ts recent | grep 'read.*cat.*test-file.*:rsync_t:.*:samba_share_t:.*tclass=file'" + rlRun "ausearch -m avc -m selinux_err -i -ts recent --input-logs | grep 'read.*ls.*test-dir.*:rsync_t:.*:samba_share_t:.*tclass=dir'" + rlRun "ausearch -m avc -m selinux_err -i -ts recent --input-logs | grep 'read.*cat.*test-file.*:rsync_t:.*:samba_share_t:.*tclass=file'" rlRun "diff ${BEFORE} ${AFTER} | grep \"Plugin.*suggests\"" rlRun "diff ${BEFORE} ${AFTER} | grep \"Plugin ${PLUGIN_NAME} .*suggests\"" rlRun "diff /var/log/messages ./messages | grep -i -e 'setroubleshoot.*exception' -e 'no such file or directory'" 1 diff --git a/tests/tests.yml b/tests/tests.yml deleted file mode 100644 index ea433bf..0000000 --- a/tests/tests.yml +++ /dev/null @@ -1,19 +0,0 @@ -- hosts: localhost - roles: - - role: standard-test-beakerlib - tags: - - classic - tests: - - Regression/embedded-null-byte-in-audit-records - - Regression/no-plugin-exception-during-analyses - - Regression/sealert-s-traceback-invalid-display - - Regression/Report-bugs-on-corresponding-components - - Sanity/public_content - required_packages: - - setroubleshoot-server - - setroubleshoot-plugins - - audit - - setools-console - - psmisc - - libselinux-utils - - rsyslog