kernel/selinux-testsuite: patch the policy for restraint

When this test in run via restraint (e.g. on Beaker), it inherits some
file descriptors originating from it, labeled unconfined_service_t. This
leads to a huge amount of denials when test programs are exectuted.

To work around this, add a rule to the policy that allows the test
domains to inherit these descriptors from unconfined_service_t.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
This commit is contained in:
Ondrej Mosnacek 2021-09-22 22:00:04 +02:00
commit 08dcaa3534

View file

@ -304,6 +304,10 @@ rlJournalStart
} | rlRun "tee -a tests/tun_tap/tun_common.h" 0 \
"Harden tun_tap test against missing defs"
# needed to avoid a flood of AVCs when run via restraint
rlRun "sed -i 's/type unconfined_t;/type unconfined_t, unconfined_service_t;/' policy/test_policy.if" 0
rlRun "sed -i 's/\\(allow \\\$1 initrc_t:fd use;\\)/\\1 allow \$1 unconfined_service_t:fd use;/' policy/test_policy.if" 0
exclude_tests=""
force_tests=""
for file in ./tests/nnp*/execnnp.c; do