Compare commits

..

5 commits

Author SHA1 Message Date
Vit Mojzis
136ff6eaa6 udica-0.2.6-1
- New release https://github.com/containers/udica/releases/tag/v0.2.6
- Move policy templates to container-selinux repo
2021-10-25 16:08:39 +02:00
Vit Mojzis
b702a462b3 tests: Require container-selinux
Policy templates where moved to container-selinux package and udica
doesn't work properly without them.

Sanity test temporarily needs git for downloading policy templates.
Those will soon be available via container-selinux.

Signed-off-by: Vit Mojzis <vmojzis@redhat.com>
2021-10-25 15:57:38 +02:00
Vit Mojzis
8d4d9f3eaa udica-0.2.5-1
- New rebase https://github.com/containers/udica/releases/tag/v0.2.5
- Replace capability dictionary with str.lower()
- Enable udica to generate policies with fifo class
- Sort container inspect data before processing
- Update templates to work properly with new cil parser
2021-09-15 09:35:43 +02:00
Vit Mojzis
b0ad976319 * Tue Mar 16 2021 Vit Mojzis <vmojzis@redhat.com> - 0.2.4-4
- Remove  %check section
2021-03-16 16:06:06 +01:00
Vit Mojzis
5031b14264 Revert "Add %check section to run basic tests during rpm build process"
The check is not necessary since it's part of the CI and brings needless
dependencies.

This reverts commits fa6f003ec4 and
4dc4b32e96.
2021-03-11 16:23:25 +01:00
28 changed files with 94 additions and 5811 deletions

View file

@ -1 +0,0 @@
1

2
.gitignore vendored
View file

@ -14,5 +14,3 @@
/v0.2.4.tar.gz
/v0.2.5.tar.gz
/v0.2.6.tar.gz
/v0.2.7.tar.gz
/v0.2.8.tar.gz

File diff suppressed because it is too large Load diff

View file

@ -1,170 +0,0 @@
From d444e67ead27266d57184ab8bc032c5528f7e26c Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Wed, 20 Dec 2023 14:33:27 +0100
Subject: [PATCH] Add tests covering confined user policy generation
Signed-off-by: Vit Mojzis <vmojzis@redhat.com>
---
tests/test_confined_abcdgilmns.cil | 24 ++++++++++++++++++++
tests/test_confined_cla.cil | 15 +++++++++++++
tests/test_confined_lb.cil | 12 ++++++++++
tests/test_confined_lsid.cil | 17 +++++++++++++++
tests/test_main.py | 35 +++++++++++++++++++++++++-----
5 files changed, 98 insertions(+), 5 deletions(-)
create mode 100644 tests/test_confined_abcdgilmns.cil
create mode 100644 tests/test_confined_cla.cil
create mode 100644 tests/test_confined_lb.cil
create mode 100644 tests/test_confined_lsid.cil
diff --git a/tests/test_confined_abcdgilmns.cil b/tests/test_confined_abcdgilmns.cil
new file mode 100644
index 0000000..5fd619f
--- /dev/null
+++ b/tests/test_confined_abcdgilmns.cil
@@ -0,0 +1,24 @@
+(boolean my_container_exec_content true)
+(role my_container_r)
+(type my_container_dbus_t)
+(type my_container_gkeyringd_t)
+(type my_container_ssh_agent_t)
+(type my_container_sudo_t)
+(type my_container_sudo_tmp_t)
+(type my_container_t)
+(type my_container_userhelper_t)
+(user my_container_u)
+(userrole my_container_u my_container_r)
+(userlevel my_container_u (s0))
+(userrange my_container_u ((s0 ) (s0 (c0))))
+
+(call confinedom_admin_commands_macro (my_container_t my_container_r my_container_sudo_t))
+(call confinedom_graphical_login_macro (my_container_t my_container_r my_container_dbus_t))
+(call confinedom_mozilla_usage_macro (my_container_t my_container_r))
+(call confinedom_networking_macro (my_container_t my_container_r))
+(call confinedom_security_advanced_macro (my_container_t my_container_r my_container_sudo_t my_container_userhelper_t))
+(call confinedom_security_basic_macro (my_container_t my_container_r))
+(call confinedom_sudo_macro (my_container_t my_container_r my_container_sudo_t my_container_sudo_tmp_t))
+(call confinedom_user_login_macro (my_container_t my_container_r my_container_gkeyringd_t my_container_dbus_t my_container_exec_content))
+(call confined_ssh_connect_macro (my_container_t my_container_r my_container_ssh_agent_t))
+(call confined_use_basic_commands_macro (my_container_t my_container_r))
\ No newline at end of file
diff --git a/tests/test_confined_cla.cil b/tests/test_confined_cla.cil
new file mode 100644
index 0000000..a633aaa
--- /dev/null
+++ b/tests/test_confined_cla.cil
@@ -0,0 +1,15 @@
+(boolean my_container_exec_content true)
+(role my_container_r)
+(type my_container_dbus_t)
+(type my_container_gkeyringd_t)
+(type my_container_ssh_agent_t)
+(type my_container_sudo_t)
+(type my_container_t)
+(user my_container_u)
+(userrole my_container_u my_container_r)
+(userlevel my_container_u (s0))
+(userrange my_container_u ((s0 ) (s0 (c0))))
+
+(call confinedom_admin_commands_macro (my_container_t my_container_r my_container_sudo_t))
+(call confinedom_user_login_macro (my_container_t my_container_r my_container_gkeyringd_t my_container_dbus_t my_container_exec_content))
+(call confined_ssh_connect_macro (my_container_t my_container_r my_container_ssh_agent_t))
\ No newline at end of file
diff --git a/tests/test_confined_lb.cil b/tests/test_confined_lb.cil
new file mode 100644
index 0000000..3e3c997
--- /dev/null
+++ b/tests/test_confined_lb.cil
@@ -0,0 +1,12 @@
+(boolean my_container_exec_content true)
+(role my_container_r)
+(type my_container_dbus_t)
+(type my_container_gkeyringd_t)
+(type my_container_t)
+(user my_container_u)
+(userrole my_container_u my_container_r)
+(userlevel my_container_u (s0))
+(userrange my_container_u ((s0 ) (s0 (c0))))
+
+(call confinedom_user_login_macro (my_container_t my_container_r my_container_gkeyringd_t my_container_dbus_t my_container_exec_content))
+(call confined_use_basic_commands_macro (my_container_t my_container_r))
\ No newline at end of file
diff --git a/tests/test_confined_lsid.cil b/tests/test_confined_lsid.cil
new file mode 100644
index 0000000..8719420
--- /dev/null
+++ b/tests/test_confined_lsid.cil
@@ -0,0 +1,17 @@
+(boolean my_container_exec_content true)
+(role my_container_r)
+(type my_container_dbus_t)
+(type my_container_gkeyringd_t)
+(type my_container_sudo_t)
+(type my_container_sudo_tmp_t)
+(type my_container_t)
+(type my_container_userhelper_t)
+(user my_container_u)
+(userrole my_container_u my_container_r)
+(userlevel my_container_u (s0))
+(userrange my_container_u ((s0 ) (s0 (c0))))
+
+(call confinedom_security_advanced_macro (my_container_t my_container_r my_container_sudo_t my_container_userhelper_t))
+(call confinedom_security_basic_macro (my_container_t my_container_r))
+(call confinedom_sudo_macro (my_container_t my_container_r my_container_sudo_t my_container_sudo_tmp_t))
+(call confinedom_user_login_macro (my_container_t my_container_r my_container_gkeyringd_t my_container_dbus_t my_container_exec_content))
\ No newline at end of file
diff --git a/tests/test_main.py b/tests/test_main.py
index fb6a9ab..0c73861 100644
--- a/tests/test_main.py
+++ b/tests/test_main.py
@@ -369,7 +369,26 @@ class TestBase(unittest.TestCase):
self.assert_templates(output, ["base_container"])
self.assert_policy(test_file("test_devices.podman.cil"))
- def run_udica(self, args):
+ # Confined user tests
+ def test_confined_user(self):
+ """udica confined_user <args> --level s0 --range s0:c0 my_container"""
+ for arg in ["cla", "lb", "lsid", "abcdgilmns"]:
+ output = self.run_udica(
+ [
+ "udica",
+ "confined_user",
+ "-{}".format(arg),
+ "--level",
+ "s0",
+ "--range",
+ "s0:c0",
+ "my_container",
+ ],
+ True,
+ )
+ self.assert_policy(test_file("test_confined_{}.cil".format(arg)))
+
+ def run_udica(self, args, confined=False):
with patch("sys.argv", args):
with patch("sys.stderr.write") as mock_err, patch(
"sys.stdout.write"
@@ -383,10 +402,16 @@ class TestBase(unittest.TestCase):
udica.__main__.main()
mock_err.assert_not_called()
- self.assertRegex(mock_out.output, "Policy my_container created")
- self.assertRegex(
- mock_out.output, "--security-opt label=type:my_container.process"
- )
+ if confined:
+ self.assertRegex(mock_out.output, "semodule -i my_container.cil")
+ self.assertRegex(
+ mock_out.output, "semanage login -a -s my_container_u my_container"
+ )
+ else:
+ self.assertRegex(mock_out.output, "Policy my_container created")
+ self.assertRegex(
+ mock_out.output, "--security-opt label=type:my_container.process"
+ )
return mock_out.output
--
2.43.0

View file

@ -1,57 +0,0 @@
From f411c146986fabe7375724528b2d4ba8cf78b904 Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Mon, 12 Feb 2024 19:38:14 +0100
Subject: [PATCH] confined: make "-l" non optional
The confinedom_user_login_macro is needed for all custom users.
Also, allow the new user type to be accessed via remote login.
Signed-off-by: Vit Mojzis <vmojzis@redhat.com>
---
udica/__main__.py | 2 +-
udica/macros/confined_user_macros.cil | 8 +++++++-
2 files changed, 8 insertions(+), 2 deletions(-)
diff --git a/udica/__main__.py b/udica/__main__.py
index 1ba8515..801499c 100644
--- a/udica/__main__.py
+++ b/udica/__main__.py
@@ -92,7 +92,7 @@ def get_args():
"-l",
"--user_login",
action="store_true",
- default=False,
+ default=True,
dest="user_login",
help="Basic rules common to all users (tty, pty, ...)",
)
diff --git a/udica/macros/confined_user_macros.cil b/udica/macros/confined_user_macros.cil
index ddb5689..06c4c56 100644
--- a/udica/macros/confined_user_macros.cil
+++ b/udica/macros/confined_user_macros.cil
@@ -2411,7 +2411,7 @@
(typetransition utype sudo_exec_t process sudo_type)
(allow sudo_type utype (fd (use)))
(allow sudo_type utype (fifo_file (ioctl read write getattr lock append)))
- (allow sudo_type utype (process (sigchld)))
+ (allow sudo_type utype (process (getpgid sigchld)))
(allow sudo_type bin_t (dir (getattr open search)))
(allow sudo_type bin_t (dir (ioctl read getattr lock open search)))
(allow sudo_type bin_t (dir (getattr open search)))
@@ -4006,6 +4006,12 @@
)
)
)
+ ; Telnet login
+ (optional confinedom_user_login_optional_3
+ (typeattributeset cil_gen_require remote_login_t)
+ (allow remote_login_t utype (process (signal transition)))
+ (allow utype self (bpf (prog_load)))
+ )
)
(macro confined_ssh_connect_macro ((type utype) (role urole) (type ssh_agent_type))
--
2.43.0

View file

@ -1,31 +0,0 @@
From 131d228c6a91eaaeccc1d000821beeccba69d134 Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Mon, 4 Mar 2024 12:59:53 +0100
Subject: [PATCH] confined: allow asynchronous I/O operations
Signed-off-by: Vit Mojzis <vmojzis@redhat.com>
---
udica/macros/confined_user_macros.cil | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/udica/macros/confined_user_macros.cil b/udica/macros/confined_user_macros.cil
index 06c4c56..dcb5198 100644
--- a/udica/macros/confined_user_macros.cil
+++ b/udica/macros/confined_user_macros.cil
@@ -4012,6 +4012,13 @@
(allow remote_login_t utype (process (signal transition)))
(allow utype self (bpf (prog_load)))
)
+ ; asynchronous I/O operations RHEL 10
+ (optional confinedom_user_login_optional_4
+ (typeattributeset cil_gen_require io_uring_t)
+ (allow utype self (io_uring (sqpoll)))
+ (allow utype io_uring_t (anon_inode (create)))
+ (allow utype io_uring_t (anon_inode (read write getattr map)))
+ )
)
(macro confined_ssh_connect_macro ((type utype) (role urole) (type ssh_agent_type))
--
2.43.0

View file

@ -1,30 +0,0 @@
From a9440c7de24e39084bc5f5970bd22eaf224a237f Mon Sep 17 00:00:00 2001
From: Petr Lautrbach <lautrbach@redhat.com>
Date: Fri, 11 Oct 2024 14:18:07 +0200
Subject: [PATCH] use relative paths, it's undefined behavior with absolute
Content-type: text/plain
---
setup.py | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/setup.py b/setup.py
index d3f20f49bdb0..7a29a6f57d8c 100644
--- a/setup.py
+++ b/setup.py
@@ -35,9 +35,9 @@ setuptools.setup(
packages=["udica"],
python_requires=">=3.4, <4",
data_files=[
- ("/usr/share/licenses/udica", ["LICENSE"]),
- ("/usr/share/udica/ansible", ["udica/ansible/deploy-module.yml"]),
- ("/usr/share/udica/macros", ["udica/macros/confined_user_macros.cil"]),
+ ("share/licenses/udica", ["LICENSE"]),
+ ("share/udica/ansible", ["udica/ansible/deploy-module.yml"]),
+ ("share/udica/macros", ["udica/macros/confined_user_macros.cil"]),
],
# scripts=["bin/udica"],
entry_points={"console_scripts": ["udica=udica.__main__:main"]},
--
2.47.0

View file

@ -1,18 +0,0 @@
discover:
- how: shell
dist-git-source: true
tests:
- name: /smoke
test: cd $TMT_SOURCE_DIR/udica-*[0-9]/ && python3 -m unittest -v tests/test_unit.py
- name: /smoke2
test: cd $TMT_SOURCE_DIR/udica-*[0-9]/ && python3 tests/test_integration.py
prepare:
- name: install packages
how: install
package:
- udica
- python3
- container-selinux
- git-core
execute:
how: tmt

View file

@ -1,6 +0,0 @@
summary: basic udica test plan
discover:
how: fmf
execute:
how: tmt

View file

@ -1 +1 @@
SHA512 (v0.2.8.tar.gz) = 513d932cad65d75b5aa753f2b0e4a99c0f5fa930740c65c20343521bc74deca13b140a69b78ab001dcd144a14254d1dda8ca8989531070e545fddbb08c1e64f0
SHA512 (v0.2.6.tar.gz) = 29295c9d95ecb15aed7e226d92a0b838046cf607e98956c66a83ad0f4ddf58b255586c24d407216ae9ddf5b11f502ae2b3a6822208d8dc8141124e68dac19265

View file

@ -1,68 +0,0 @@
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
#
# Makefile of /pkgs.fedoraproject.org/rpms/udica/tests/confined
# Description: Test basic use cases of confined user policies generated by udica
# Authors: Milos Malik <mmalik@redhat.com>, Vit Mojzis <vmojzis@redhat.com>
#
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
#
# Copyright (c) 2015 Red Hat, Inc.
#
# This copyrighted material is made available to anyone wishing
# to use, modify, copy, or redistribute it subject to the terms
# and conditions of the GNU General Public License version 2.
#
# This program is distributed in the hope that it will be
# useful, but WITHOUT ANY WARRANTY; without even the implied
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
# PURPOSE. See the GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public
# License along with this program; if not, write to the Free
# Software Foundation, Inc., 51 Franklin Street, Fifth Floor,
# Boston, MA 02110-1301, USA.
#
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
export TEST=/CoreOS/udica/confined
export TESTVERSION=1.0
BUILT_FILES=
SCRIPTS=a.sh b.sh d.sh i.sh l.sh n.sh s.sh
FILES=$(METADATA) test.sh Makefile $(SCRIPTS) ssh.exp telnet.exp
.PHONY: all install download clean
run: $(FILES) build
./test.sh
build: $(BUILT_FILES)
chmod a+x test.sh ssh.exp telnet.exp $(SCRIPTS)
clean:
rm -f *~ $(BUILT_FILES)
include /usr/share/rhts/lib/rhts-make.include
$(METADATA): Makefile
@echo "Owner: Vit Mojzis <vmojzis@redhat.com>" > $(METADATA)
@echo "Name: $(TEST)" >> $(METADATA)
@echo "TestVersion: $(TESTVERSION)" >> $(METADATA)
@echo "Path: $(TEST_DIR)" >> $(METADATA)
@echo "Description: Test basic use cases of confined user policies generated by udica" >> $(METADATA)
@echo "Type: Regression" >> $(METADATA)
@echo "TestTime: 60m" >> $(METADATA)
@echo "RunFor: udica" >> $(METADATA)
@echo "Requires: udica expect" >> $(METADATA)
@echo "Requires: /usr/sbin/semanage" >> $(METADATA)
@echo "Requires: traceroute tcpdump setools-console policycoreutils-devel bind-utils" >> $(METADATA)
@echo "Requires: grep telnet telnet-server net-tools" >> $(METADATA)
@echo "Priority: Normal" >> $(METADATA)
@echo "License: GPLv2" >> $(METADATA)
@echo "Confidential: no" >> $(METADATA)
@echo "Destructive: no" >> $(METADATA)
@echo "Releases: -RHEL4 -RHEL5 -RHEL6 -RHEL7" >> $(METADATA)
rhts-lint $(METADATA)

View file

@ -1,13 +0,0 @@
#!/bin/sh -x
on_err(){
echo "Error"
}
trap 'on_err' ERR
# gets stuck -- no journal entries
#sudo journalctl -n 1 --no-pager
sudo systemctl --no-pager status dbus
sudo netstat -g
sudo nslookup www.google.com
sudo sysctl net.ipv4.udp_mem

View file

@ -1,17 +0,0 @@
#!/bin/sh -x
on_err(){
echo "Error"
}
trap 'on_err' ERR
id -Z
date
ls ~
ps
man -f selinux
systemctl --no-pager --user status dbus | grep "D-Bus User Message Bus"
journalctl -user
# cannot rotate the orgiginal password as user
#echo -e "$1\n9$1\n9$1" | passwd
#echo -e "9$1\n$1\n$1" | passwd

View file

@ -1,12 +0,0 @@
#!/bin/sh -x
on_err(){
echo "Error"
}
trap 'on_err' ERR
sesearch -A -s httpd_t -t http_port_t -c tcp_socket
sudo semanage user -l
sudo semanage fcontext -lC
sudo semodule -B
sudo sepolicy network -p 44322

View file

@ -1,11 +0,0 @@
#!/bin/sh -x
on_err(){
echo "Error"
}
trap 'on_err' ERR
seinfo
getsebool httpd_can_connect_ftp
sesearch -A -s httpd_t -t http_port_t -c tcp_socket

View file

@ -1,2 +0,0 @@
#!/bin/sh -x
id -Z

View file

@ -1,34 +0,0 @@
summary: Concise summary describing what the test does
description: |+
Test basic functionality of sepolicy_confine tool
contact: Vit Mojzis <vmojzis@redhat.com>
component:
- policycoreutils
- udica
test: ./test.sh
framework: beakerlib
recommend:
- policycoreutils
- /usr/sbin/semanage
- expect
- net-tools
- traceroute
- tcpdump
- setools-console
- policycoreutils-devel
- bind-utils
- grep
- telnet
- telnet-server
- udica
duration: 60m
enabled: true
tag:
- NoRHEL4
- NoRHEL5
- targeted
adjust:
- enabled: false
when: distro == rhel-4, rhel-5, rhel-6, rhel-7
continue: false

View file

@ -1,15 +0,0 @@
#!/bin/sh -x
on_err(){
echo "Error"
}
trap 'on_err' ERR
ip address
ifconfig -s
traceroute 127.0.0.1
# this may block the test if there is no trafic !!!
sudo tcpdump -i any -c 1
netstat -g
nslookup www.google.com
ping -c 1 127.0.0.1

View file

@ -1,9 +0,0 @@
#!/bin/sh -x
on_err(){
echo "Error"
}
trap 'on_err' ERR
sudo id -Z
sudo passwd -S root

View file

@ -1,23 +0,0 @@
#!/usr/bin/expect -f
# Expect script for SSH logging as $username to $hostname using $password and executing $command.
# Usage:
# ./ssh.exp username password hostname command
set username [lrange $argv 0 0]
set password [lrange $argv 1 1]
set hostname [lrange $argv 2 2]
set command [lrange $argv 3 10]
set timeout 300
# connect to remote host and execute given command
log_user 1
spawn ssh -t $username@$hostname $command
expect {
-nocase "yes/no" { send -- "yes\r" ; exp_continue }
-nocase "password" { send -- "$password\r" }
}
#expect {
# "[sudo] password" {send -- "$password" ; exp_continue }
#}
log_user 1
# send -- "\r"
expect eof

View file

@ -1,24 +0,0 @@
#!/usr/bin/expect -f
# Expect script for telnet logging as $username to $hostname using $password and executing $command.
# Usage:
# ./telnet.exp username password hostname command
set username [lrange $argv 0 0]
set password [lrange $argv 1 1]
set hostname [lrange $argv 2 2]
set command [lrange $argv 3 10]
#set timeout 300
# connect to remote host and execute given command
log_user 1
spawn telnet $hostname 23
expect {
-nocase "yes/no" { send -- "yes\r" ; exp_continue }
-nocase "password" { send -- "$password\r" ; exp_continue }
-nocase "kernel" { send -- "$username\r" ; exp_continue }
-nocase "last login" { send -- "$command\r" }
}
log_user 1
send -- "\r"
sleep 1
expect eof

View file

@ -1,89 +0,0 @@
#!/bin/bash
# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k
. /usr/share/beakerlib/beakerlib.sh || exit 1
PACKAGE="selinux-policy"
POLICY_OPTIONS=${POLICY_OPTIONS:-"lbc clbsa lbsidca lbscid lbsidc agmndislcb"}
TEST_SCRIPTS="abdilns"
#SEPOLICY_CONFINE="confined-users-policy/sepolicy_confine/sepolicy_confine"
SEPOLICY_CONFINE="udica confined_user"
rlJournalStart
rlPhaseStartSetup
rlRun "set -o pipefail"
rlRun "systemctl start telnet.socket"
if [ -d /etc/ssh/sshd_config.d ] ; then
rlRun "echo 'PasswordAuthentication yes' > /etc/ssh/sshd_config.d/001-enable-password.conf"
rlRun "service sshd restart"
fi
rlRun "semodule -i /usr/share/udica/macros/confined_user_macros.cil"
rlRun "setsebool ssh_sysadm_login on"
# do not show "With great power comes great responsibility." prompt
# and don't ask for password when using "sudo"
echo "%users ALL=(ALL:ALL) NOPASSWD: ALL" >> /etc/sudoers.d/confined_users_test;
echo "%wheel ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers.d/confined_users_test;
echo 'Defaults lecture="never"' >> /etc/sudoers.d/confined_users_test;
rlPhaseEnd
#TODO try different level and range for the generated user policy
rlPhaseStartTest "real scenario -- confined users"
USER_NAME_SEED="user${RANDOM}"
USER_NAME_INDEX=1
USER_LIST=""
for OPTIONS in ${POLICY_OPTIONS} ; do
USER_NAME="${USER_NAME_SEED}$((USER_NAME_INDEX++))"
USER_LIST+=" ${USER_NAME}"
USER_SECRET="S3kr3t${RANDOM}"
SELINUX_USER="confined_${OPTIONS}"
rlLog "Testing SELinux users: ${SELINUX_USER}"
rlRun "${SEPOLICY_CONFINE} -${OPTIONS} --level s0 --range s0-s0:c0.c1023 ${SELINUX_USER}"
rlRun "semodule -i ${SELINUX_USER}.cil"
rlRun "sed -e 's|user|${SELINUX_USER}|g' /etc/selinux/targeted/contexts/users/user_u > /etc/selinux/targeted/contexts/users/${SELINUX_USER}_u"
rlRun "useradd -Z ${SELINUX_USER}_u ${USER_NAME}"
rlRun "cp *.sh /home/${USER_NAME}"
rlRun "echo ${USER_SECRET} | passwd --stdin ${USER_NAME}"
rlRun "usermod -G wheel ${USER_NAME}"
# dummy -- first telnet connection does not show results properly
rlRun "./telnet.exp ${USER_NAME} ${USER_SECRET} localhost whoami"
# run all available scripts matching given confined user options
TO_RUN=${OPTIONS//[^"$TEST_SCRIPTS"]}
for (( i=0; i<${#TO_RUN}; i++ )) ; do
rlRun -s "./telnet.exp ${USER_NAME} ${USER_SECRET} localhost /home/${USER_NAME}/${TO_RUN:$i:1}.sh ${USER_SECRET}"
echo "\n"
rlRun "grep -e 'Error' $rlRun_LOG" 1
done
# run test scripts over SSH if the new user is allowed to use it
if [[ "$OPTIONS" == *"c"* ]]; then
for (( i=0; i<${#TO_RUN}; i++ )) ; do
rlRun -s "./ssh.exp ${USER_NAME} ${USER_SECRET} localhost /home/${USER_NAME}/${TO_RUN:$i:1}.sh ${USER_SECRET}"
rlRun "grep -e 'Error' $rlRun_LOG" 1
done
fi
sleep 10
done
# remove all test users
for USER_NAME in ${USER_LIST} ; do
rlRun "userdel -rfZ ${USER_NAME}"
done
sleep 10
# remove test SELinux users
for OPTIONS in ${POLICY_OPTIONS} ; do
rlRun "rm -rf confined_${OPTIONS}.cil /etc/selinux/targeted/contexts/users/confined_${OPTIONS}_u"
rlRun "semodule -r confined_${OPTIONS}"
done
rlRun "rm -rf $rlRun_LOG"
rlPhaseEnd
rlPhaseStartCleanup
rlRun "semodule -r confined_user_macros"
rlRun "rm -rf /etc/sudoers.d/confined_users_test"
rlRun "setsebool ssh_sysadm_login off"
if [ -d /etc/ssh/sshd_config.d ] ; then
rlRun "rm -f /etc/ssh/sshd_config.d/001-enable-password.conf"
rlRun "service sshd restart"
fi
rlPhaseEnd
rlJournalEnd

View file

@ -1,27 +0,0 @@
summary: Compare udica output between podman and docker
description: |+
Compare udica output between podman and docker
contact: Jan Zarsky <jzarsky@redhat.com>
component:
- udica
test: ./runtest.sh
framework: beakerlib
recommend:
- container-selinux
- /usr/bin/docker
- podman
- policycoreutils
- udica
duration: 20m
enabled: true
tag:
- NoRHEL4
- NoRHEL5
- NoRHEL6
- NoRHEL7
- targeted
adjust:
- enabled: false
when: distro == rhel-4, rhel-5, rhel-6, rhel-7
because: the udica package is not available there

View file

@ -25,6 +25,7 @@
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# Include Beaker environment
. /usr/bin/rhts-environment.sh || exit 1
. /usr/share/beakerlib/beakerlib.sh || exit 1
PACKAGE="udica"
@ -35,7 +36,7 @@ rlJournalStart
rlAssertRpm "container-selinux"
rlAssertRpm "policycoreutils"
rlAssertRpm "podman"
rlRun "rpm -qf /usr/bin/docker"
rlAssertRpm "docker"
rlRun "rlServiceStart docker"
OUTPUT_FILE=$(mktemp)
rlPhaseEnd

View file

@ -1,26 +0,0 @@
summary: Test basic functionality of udica
description: |+
Test basic functionality of udica
contact: Jan Zarsky <jzarsky@redhat.com>
component:
- udica
test: ./runtest.sh
framework: beakerlib
recommend:
- container-selinux
- podman
- policycoreutils
- udica
duration: 20m
enabled: true
tag:
- NoRHEL4
- NoRHEL5
- NoRHEL6
- NoRHEL7
- targeted
adjust:
- enabled: false
when: distro == rhel-4, rhel-5, rhel-6, rhel-7
because: the udica package is not available there

View file

@ -25,12 +25,11 @@
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# Include Beaker environment
. /usr/bin/rhts-environment.sh || exit 1
. /usr/share/beakerlib/beakerlib.sh || exit 1
PACKAGE="udica"
CONTAINERS="fedora:latest fedora:rawhide ubi9 ubi8 ubi7 centos:stream9"
rlJournalStart
rlPhaseStartSetup
rlAssertRpm "udica"
@ -45,46 +44,44 @@ rlJournalStart
rlRun "PAGER=cat man udica"
rlPhaseEnd
for CONTAINER_NAME in ${CONTAINERS} ; do
rlPhaseStartTest "Test basic scenario for ${CONTAINER_NAME} container"
rlRun "podman run -dit --name test -v /home:/home:ro -v /var/spool:/var/spool:rw -p 21:21 ${CONTAINER_NAME}"
rlRun "podman ps | grep test"
rlRun "ps -efZ | grep bash"
rlRun "ps -efZ | grep bash | grep container_t"
rlPhaseStartTest "Test basic scenario"
rlRun "podman run -dit --name test -v /home:/home:ro -v /var/spool:/var/spool:rw -p 21:21 fedora"
rlRun "podman ps | grep test"
rlRun "ps -efZ | grep bash"
rlRun "ps -efZ | grep bash | grep container_t"
rlRun "podman exec test ls /home" 1,2
rlRun "podman exec test touch /var/spool/test" 1
rlRun "podman exec test yum install nmap-ncat -y" 0
rlWatchdog "rlRun \"podman exec test nc -l 53\"" 3
rlRun "podman exec test ls /home" 1,2
rlRun "podman exec test touch /var/spool/test" 1
rlRun "podman exec test dnf install nmap-ncat -y" 0
rlWatchdog "rlRun \"podman exec test nc -l 53\"" 3
CONT_ID=$(podman ps | grep test | cut -d ' ' -f 1)
rlRun "podman inspect $CONT_ID | udica my_container >$OUTPUT_FILE"
rlRun "podman stop test"
rlRun "podman rm --force test"
CONT_ID=$(podman ps | grep test | cut -d ' ' -f 1)
rlRun "podman inspect $CONT_ID | udica my_container >$OUTPUT_FILE"
rlRun "podman stop test"
rlRun "podman rm --force test"
rlRun "cat $OUTPUT_FILE"
rlAssertExists "my_container.cil"
SEMODULE=$(cat $OUTPUT_FILE | grep "semodule -i" | cut -d '#' -f 2)
rlRun "$SEMODULE"
rlRun "cat $OUTPUT_FILE"
rlAssertExists "my_container.cil"
SEMODULE=$(cat $OUTPUT_FILE | grep "semodule -i" | cut -d '#' -f 2)
rlRun "$SEMODULE"
PODMAN_OPT=$(cat $OUTPUT_FILE | grep "security-opt" | cut -d '"' -f 2)
rlRun "podman run -dit --name test2 $PODMAN_OPT -v /home:/home:ro -v /var/spool:/var/spool:rw -p 21:21 fedora"
rlRun "podman ps | grep test2"
rlRun "ps -efZ | grep bash"
rlRun "ps -efZ | grep bash | grep my_container.process"
PODMAN_OPT=$(cat $OUTPUT_FILE | grep "security-opt" | cut -d '"' -f 2)
rlRun "podman run -dit --name test2 $PODMAN_OPT -v /home:/home:ro -v /var/spool:/var/spool:rw -p 21:21 fedora"
rlRun "podman ps | grep test2"
rlRun "ps -efZ | grep bash"
rlRun "ps -efZ | grep bash | grep my_container.process"
rlRun "podman exec test2 ls /home" 0
rlRun "podman exec test2 touch /var/spool/test" 0
rlRun "podman exec test2 yum install nmap-ncat -y" 0
rlWatchdog "rlRun \"podman exec test2 nc -l 53\" 2" 3
rlRun "podman exec test2 ls /home" 0
rlRun "podman exec test2 touch /var/spool/test" 0
rlRun "podman exec test2 dnf install nmap-ncat -y" 0
rlWatchdog "rlRun \"podman exec test2 nc -l 53\" 2" 3
rlRun "podman stop test2"
rlRun "podman rm --force test2"
rlRun "podman stop test2"
rlRun "podman rm --force test2"
rlRun "semodule -r my_container base_container net_container home_container"
rlRun "rm my_container.cil"
rlPhaseEnd
done
rlRun "semodule -r my_container base_container net_container home_container"
rlRun "rm my_container.cil"
rlPhaseEnd
rlPhaseStartTest "Compare different ways of obtaining policy"
rlRun "podman run -dit --name test -v /home:/home:ro -v /var/spool:/var/spool:rw -p 21:21 fedora"

34
tests/tests.yml Normal file
View file

@ -0,0 +1,34 @@
- hosts: localhost
tags:
- classic
- container
roles:
- role: standard-test-source
- role: standard-test-basic
required_packages:
- python3
- container-selinux
- git
tests:
- smoke:
dir: ./source
run: python3 -m unittest -v tests/test_unit.py
- smoke2:
dir: ./source
run: python3 tests/test_integration.py
- hosts: localhost
tags:
- classic
- container
roles:
- role: standard-test-beakerlib
tags:
- classic
tests:
- sanity
required_packages:
- podman
- udica
- container-selinux

View file

@ -1,26 +1,20 @@
Summary: A tool for generating SELinux security policies for containers
Name: udica
Version: 0.2.8
Release: 11%{?dist}
Version: 0.2.6
Release: 1%{?dist}
Source0: https://github.com/containers/udica/archive/v%{version}.tar.gz
#git format-patch -N v0.2.8 -- . ':!.cirrus.yml' ':!.github'
Patch0001: 0001-Add-option-to-generate-custom-policy-for-a-confined-.patch
Patch0002: 0002-Add-tests-covering-confined-user-policy-generation.patch
Patch0003: 0003-confined-make-l-non-optional.patch
Patch0004: 0004-confined-allow-asynchronous-I-O-operations.patch
Patch0005: 0005-use-relative-paths-it-s-undefined-behavior-with-abso.patch
License: GPL-3.0-or-later
License: GPLv3+
BuildArch: noarch
Url: https://github.com/containers/udica
%if 0%{?fedora} || 0%{?rhel} > 7
BuildRequires: python3 python3-devel
BuildRequires: python3 python3-devel python3-setuptools
Requires: python3 python3-libsemanage python3-libselinux
%else
BuildRequires: python2 python2-devel python2-setuptools
Requires: python2 libsemanage-python libselinux-python
%endif
# container-selinux provides policy templates
Requires: container-selinux >= 2.168.0-2
Requires: container-selinux >= 2.170.0-2
%description
Tool for generating SELinux security profiles for containers based on
@ -29,16 +23,20 @@ inspection of container JSON file.
%prep
%autosetup -p 1
%generate_buildrequires
%pyproject_buildrequires
%build
%pyproject_wheel
%if 0%{?fedora} || 0%{?rhel} > 7
%{__python3} setup.py build
%else
%{__python2} setup.py build
%endif
%install
%pyproject_install
%if 0%{?fedora} || 0%{?rhel} > 7
%{__python3} setup.py install --single-version-externally-managed --root=%{buildroot}
%else
%{__python2} setup.py install --single-version-externally-managed --root=%{buildroot}
%endif
install --directory %{buildroot}%{_datadir}/udica/macros
install --directory %{buildroot}%{_mandir}/man8
install -m 0644 udica/man/man8/udica.8 %{buildroot}%{_mandir}/man8/udica.8
@ -47,83 +45,19 @@ install -m 0644 udica/man/man8/udica.8 %{buildroot}%{_mandir}/man8/udica.8
%{_bindir}/udica
%dir %{_datadir}/udica
%dir %{_datadir}/udica/ansible
%dir %{_datadir}/udica/macros
%{_datadir}/udica/ansible/*
%{_datadir}/udica/macros/*
%if 0%{?fedora} || 0%{?rhel} > 7
%license LICENSE
%{python3_sitelib}/udica/
%{python3_sitelib}/udica-*.dist-info
%{python3_sitelib}/udica-*.egg-info
%else
%{_datarootdir}/licenses/udica/LICENSE
%{python2_sitelib}/udica/
%{python2_sitelib}/udica-*.egg-info
%endif
%changelog
* Fri Sep 19 2025 Python Maint <python-maint@redhat.com> - 0.2.8-11
- Rebuilt for Python 3.14.0rc3 bytecode
* Fri Aug 15 2025 Python Maint <python-maint@redhat.com> - 0.2.8-10
- Rebuilt for Python 3.14.0rc2 bytecode
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.2.8-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jun 02 2025 Python Maint <python-maint@redhat.com> - 0.2.8-8
- Rebuilt for Python 3.14
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.2.8-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Sat Jul 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.2.8-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Fri Jun 07 2024 Python Maint <python-maint@redhat.com> - 0.2.8-5
- Rebuilt for Python 3.13
* Mon Feb 12 2024 Vit Mojzis <vmojzis@redhat.com> - 0.2.8-4
- confined: make "-l" non optional
* Sat Jan 27 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.2.8-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Thu Dec 21 2023 Vit Mojzis <vmojzis@redhat.com> - 0.2.8-2
- Add option to generate custom policy for a confined user
* Wed Nov 29 2023 Vit Mojzis <vmojzis@redhat.com> - 0.2.8-1
- New release
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.2.7-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Tue Jun 13 2023 Python Maint <python-maint@redhat.com> - 0.2.7-6
- Rebuilt for Python 3.12
* Tue Apr 11 2023 Vit Mojzis <vmojzis@redhat.com> - 0.2.7-5
- Show diff when checking formatting
- Fix several lint findings
- Fix generating policy for Crio mounts
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.2.7-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Fri Oct 21 2022 Vit Mojzis <vmojzis@redhat.com> - 0.2.7-3
- Add --devices option
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.2.7-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Wed Jun 22 2022 Vit Mojzis <vmojzis@redhat.com> - 0.2.7-1
- Add support for containerd via "nerdctl inspect"
- Avoid duplicate rules for accessing mounts and devices
* Mon Jun 13 2022 Python Maint <python-maint@redhat.com> - 0.2.6-5
- Rebuilt for Python 3.11
* Mon May 02 2022 Vit Mojzis <vmojzis@redhat.com> - 0.2.6-4
- Improve label collection for mounts and devices
* Sat Jan 22 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.2.6-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Thu Nov 11 2021 Vit Mojzis <vmojzis@redhat.com> - 0.2.6-2
- Make sure each section of the inspect exists before accessing
* Mon Sep 13 2021 Vit Mojzis <vmojzis@redhat.com> - 0.2.6-1
- New release https://github.com/containers/udica/releases/tag/v0.2.6
- Move policy templates to container-selinux repo
@ -135,11 +69,8 @@ install -m 0644 udica/man/man8/udica.8 %{buildroot}%{_mandir}/man8/udica.8
- Sort container inspect data before processing
- Update templates to work properly with new cil parser
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.2.4-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Fri Jun 04 2021 Python Maint <python-maint@redhat.com> - 0.2.4-4
- Rebuilt for Python 3.10
* Tue Mar 16 2021 Vit Mojzis <vmojzis@redhat.com> - 0.2.4-4
- Remove %check section
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.2.4-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild