Commit graph

106 commits

Author SHA1 Message Date
Jan Onderka
7ccb3c22cc setting additional audit-rules package as recommend for policycoreutils/load_policy 2025-12-19 11:47:50 +01:00
Milos Malik
54a83ea1e5 add metadata and fix description+summary
Unfortunately, the test was merged even if some metadata was missing.
Additionally, the description and summary contains characters which
are not allowed based on the output of: tmt tests lint.

Both problems should be fixed now.
2025-12-03 13:32:10 +01:00
Milos Malik
5f241c5352 test if 'restorecon -i' ignores missing filesystem objects
A recently reported customer case revealed that the restorecon
program produces error messages even if it was executed with
the '-i' option. In such case no error messages should appear
when the inspected filesystem objects are missing.

The TC reproduces the situation when old libselinux/policycoreutils
packages are installed.

The TC covers RHEL-110181 and RHEL-123884.
2025-11-25 22:50:31 +01:00
Vit Mojzis
caa904c01f Fix "adjust" statements
Whenever a key is defined in the tmt hierarchy and some child also
defines that key, the child's will overwrite the previous one. The "+"
changes the operation to "append", so the content of key+ in the child
is added to the existing key.

Meaning that any "adjust" statement in a test plan using a test that
defines it's own "adjust:" is ignored.

Since we are expecting other statements to be appended to the "adjust"
sections, the content of each section needs to be a single list item as
opposed to a set of key-value pairs (first line needs to start with a
hyphen).

- Replace all "adjust:" sections with "adjust+:" in order to honor any
  adjustments further up the tree (parent tests, or test plans).
- Fix malformed "adjust" sections (sets of key-value pairs)

Signed-off-by: Vit Mojzis <vmojzis@redhat.com>
2025-10-09 20:22:22 +02:00
Milos Malik
36d28b09f5 fix a syntax error
A syntax error appears when the following test is executed:
 * policycoreutils/semodule-rebuild-if-modules-changed

The problem is a missing "then" word in the test code.
2025-10-02 13:58:11 +02:00
Milos Malik
1eb61b3a69 exclude unsuitable tests from image mode testing
Tests which are not suitable (various reasons) for image mode
testing will get the avoidImageMode tag. If their conditions improve,
the tag can be removed.
2025-09-26 14:45:52 +02:00
Jan Onderka
af6d8ea145 policycoreutils linux system roles test disable for RHIVOS 2025-09-16 15:22:46 +02:00
jan janasek
a74ee6af17 tag:Tier clean up
Removed redundant tags (e.g., Tier2/Tier3 and Tier2se/Tier3se) from all tests
with "tier: 2" and "tier: 3" metadata. The "tier" metadata is used instead.

Signed-off-by: Jan Janasek <jjanasek@redhat.com>
2025-08-26 13:03:09 +00:00
jan janasek
7e37b29514 fix .fmf metadata
all tests with CI-Tier-1 tag should have "tier: 1" in their metadata,
also removing tags Tier1 and Tier1se and lastly tests with "tier: 2"
and "tier: 3" should not have CI-Tier-1 tag.

Signed-off-by: Jan Janasek <jjanasek@redhat.com>
2025-08-26 13:03:09 +00:00
Petr Lautrbach
0e555c68c6 Skip bootc-e2e tests
bootc-e2e tests requires specific environment related to image mode. The
image is prepared using buildah and later booted. This is not supported
in this test suite (yet)

Signed-off-by: Petr Lautrbach <lautrbach@redhat.com>
2025-06-23 20:26:54 +02:00
Milos Malik
7b73a19fe5 modify tests to cope with a missing selinux-policy-* packages
Even though the tests require various selinux-policy-* packages,
some of packages may not be available on all platforms and
architectures. It can also happen that SELinux policy store is
installed in an unusual location. The tests should cope with both
situations.
2025-06-09 16:24:18 +02:00
Petr Matyas
c809f6be4f Update dependencies of policycoreutils setfiles test
Proper list of dependecies is necessary as not all distros
have every package preinstalled, for example on RHIVOS
we didn't have e2fsprogs in the system, while on more general use systems
it is included almost always, which is why it wasn't causing problems before
2025-06-05 17:29:53 +00:00
Milos Malik
b8c668a567 add missing FMF ids into selected tests
Just adding the FMF ids. No functional changes in the tests.
2025-05-13 18:39:11 +00:00
Jan Onderka
6a1e7f4399 skip man page test if no present on the system 2025-04-30 10:17:16 +00:00
Milos Malik
a7b41e8ca1 separate failing tests from no-tier tests
Apply the failinfedora tag to the tests which fail on Fedora rawhide.
Add a special test plan for regular runs of these failing tests.

Make sure that the no-tier test plan contains tests which succeed on
Fedora rawhide.
2025-04-01 08:28:41 +02:00
Petr Lautrbach
d55f7ad6ae setsebool: Do not test aliases for non-existing booleans
In CentOS Stream 10 some modules were moved from selinux-policy to
selinux-policy-epel which is available only in EPEL. It caused problem
with non-existing booleans and their aliases. With this change, an alias
is not checked when a new boolean does not exist.

Fixes:
    Error getting active value for puppet_manage_all_files
    [   PASS   ] :: Command 'getsebool puppet_manage_all_files 2>&1 | tee /tmp/tmp.nx2NlWq1zd' (Expected 0, got 0)
    [  BEGIN   ] :: Running 'getsebool puppetagent_manage_all_files 2>&1 | tee -a /tmp/tmp.nx2NlWq1zd'
    Error getting active value for puppetagent_manage_all_files
    [   PASS   ] :: Command 'getsebool puppetagent_manage_all_files 2>&1 | tee -a /tmp/tmp.nx2NlWq1zd' (Expected 0, got 0)
    [  BEGIN   ] :: Running 'uniq -c /tmp/tmp.nx2NlWq1zd | grep '2 ''
    [   FAIL   ] :: Command 'uniq -c /tmp/tmp.nx2NlWq1zd | grep '2 '' (Expected 0, got 1)
2025-03-10 12:20:06 +01:00
Milos Malik
dbbbfb5d2c fix tests which fail or cause other tests to fail
The modified tests used to fail on RHEL-10 or they caused other tests
to fail on RHEL-10. The reasons are various:
 * dependency on SELinux types which are no longer defined
 * insufficient test cleanup
 * unexpected exit codes
 * virtual vs. bare metal environment differences

These problems should be fixed now.
2025-03-05 10:42:13 +01:00
Milos Malik
a310ff9f85 fix tests which fail in other environments
The modified tests were failing because:
 * the running restorecond service causes problems to the subsequent tests
 * an irrelevant bug was tested
 * the bind component is available in multiple versions
 * rpm output contained unnecessary whitespaces

These issues should be fixed now.
2025-02-27 08:25:04 +01:00
Milos Malik
3d1e1a1ca3 increase the duration of tests which timed out
There are booth commands which may stall the automated test execution.
Let's run them with a 20 second deadline.

There are other tests which need more time to finish when executed
on slower machines. Their duration got extended.
2025-02-24 15:34:53 +01:00
Petr Lautrbach
512ac533f6 sestatus has been moved to /usr/bin on modern systems
https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin

Fixes:
    [   FAIL   ] :: Command 'rpm -ql policycoreutils | grep /usr/sbin/sestatus' (Expected 0, got 1)
2025-01-22 15:18:19 +01:00
Milos Malik
774bd87aac improve failing tests and add missing nitrate metadata
1 test was failing because of a test code issue.
1 test was missing an important test phase.

The number of tests which are missing their nitrate metadata
should be again smaller.
2025-01-13 12:59:22 +00:00
Milos Malik
3e4943c596 add missing metadata to the tests
Some tests were missing important TCMS metadata. Now, the problem
should be fixed.
2024-07-10 17:18:28 +00:00
Milos Malik
ab5c434f53 improve the failing tests
The /policycoreutils/setfiles_binary test: the --downloaddir option
is not recognized by the latest version of DNF. The option is removed
now.

The /other/update-packages test: the --skip-broken option is not
recognized by the latest version of DNF. The option is removed now.

The /selinux-policy/install-uninstall-dsp-packages test: let's not
run this test together with other tests, because it often finds
a problem that brakes the environment for the following tests.
2024-05-18 11:21:13 +02:00
Milos Malik
cc86664885 improve other tests which fail on CentOS-stream-10
Some components/packages are not available on CentOS-stream-10,
which leads to conclusion not to run the affected tests/phases there.

The /var and /run directories very often contain mislabeled files
and directories. In order to find discrepancies between file context
patterns and type_transition rules defined in the SELinux policy,
the restorecon command is needed.
2024-04-15 16:09:41 +02:00
Milos Malik
85a3f368bd adapt to semanage port dealing with duplicated local customization
The semanage command from older policycoreutils versions (<= 3.6-1.el9)
behaves in a certain way when a duplicated port context pattern is added.
It does not add the pattern but produces the following message:

  ValueError: Port <protocol>/<number> already defined

The semanage command from new policycoreutils versions (>= 3.6-2.el9)
behaves differently when a duplicated port context pattern is added.
It adds the pattern and produces the following message:

  Port <protocol>/<number> already defined, modifying instead

Above-mentioned differences in behavior have some consequences for the
automated test when removing a duplicated port context pattern. If the
automated test should pass, it needs to anticipate both possibilities.
2024-02-15 08:09:55 +01:00
Milos Malik
7582d85628 fix the relevancy of tests failing on centos stream
Apparently, the first attempt to adjust the relevancy was not
complete. So here is another one.
Certain tests should not be executed on centos-stream 8 or 9 at all,
because packages required by those tests are not available there.
Certain tests need to reflect the fact that SELinux policies which
confine the tested programs are not present on all versions of RHEL,
CentOS or Fedora.
2023-11-03 20:45:01 +01:00
Milos Malik
fc767823c1 do not require abrt, use recommend instead
The abrt* packages are not available on RHEL-9, which means that
one of the test phases would fail if this change was not done.
The test phase dedicated to /usr/sbin/abrtd will be executed only
if the file is present.
2023-08-23 12:49:30 +02:00
Petr Lautrbach
91109dac9f Does sepolicy generate --application detect writeable locations?
Signed-off-by: Petr Lautrbach <lautrbach@redhat.com>
2023-08-09 10:57:04 +00:00
Ondrej Mosnacek
733f960966
Narrow down relevancy in some tests
Make it reflect the current status in RHEL to avoid running the test
where it doesn't make sense.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2023-06-12 14:28:57 +02:00
Milos Malik
f5c43be61e improve the test to clean-up after itself
Restore the restorecond service to its original state.
The restorecond service should not stay running if it was not
running before execution of the test.
2023-06-05 15:36:19 +02:00
Ondrej Mosnacek
2c82db3d51
semodule-rebuild-if-modules-changed: fix RHEL version check (take 2)
Rework the conditional so that the new part of the test runs everywhere
except specified old version cases. Before this it wouldn't be run on
Fedora, CentOS, or RHEL>=10.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2023-03-24 10:15:21 +01:00
Ondrej Mosnacek
85268e7d6a
semodule-rebuild-if-modules-changed: add libsemanage as component in metatada
The bulk of the logic is implemented inside libsemanage, so add to the
component list, so that the test is run also on changes in libsemanage.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2023-03-23 16:23:59 +01:00
Ondrej Mosnacek
cdc801666e
semodule-rebuild-if-modules-changed: fix RHEL version check
The comparisons were inverted by accident - fix them.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2023-03-23 16:23:22 +01:00
Ondrej Mosnacek
93eca7b0a9 policycoreutils/semodule-rebuild-...: add coverage for dontaudit
Test that semodule --refresh works correctly with the disable_dontaudit
flag.

This currently requires the following patch to pass:
https://lore.kernel.org/selinux/20230309143741.346749-1-omosnace@redhat.com/

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2023-03-21 15:15:30 +00:00
Milos Malik
e0866a22fe fix the failing tests
Not all packages required by the tests were installed. The issue
should be fixed now.

Relevancy of certain tests was set incorrectly. The issue should
be fixed now.

At least 1 test runs longer than its specified duration. The issue
should be fixed now.
2023-01-23 12:47:27 +00:00
Milos Malik
afff1ecfd4 test if sepolicy manpage can generate all man pages
A new test phase was added. Purpose of the test phase is to find
out whether the `sepolicy manpage` command can generate man pages
for all SELinux domains without triggering an error or traceback.

The TC covers BZ#1416372.
2023-01-17 15:27:53 +01:00
Milos Malik
b6ec2fee8d test if sepolicy manpage can generate manpage in HTML form
The sepolicy tool can generate man pages for specific SELinux domains.
When the sepolicy tool was instructed to generate man pages in HTML
form (--web), the generated HTML files were very incomplete. The TC
reproduces the situation.

The newly added TC checks if the sepolicy manpage command works
correctly. The checks related to the sepolicy manpage command
were removed from the sepolicy-generate TC.

The TC covers BZ#1989840.
2023-01-17 11:43:37 +01:00
Petr Lautrbach
8effe6fd87 Use ausearch --input-logs
CI systems don't necessary attach stdin to terminal and this option make
`ausearch` to use audit logs as input for searching.
2022-11-24 11:30:48 +01:00
Petr Lautrbach
3727a6ade6 Adjust duration to 20m in linux-system-roles.selinux-tests
Fixes:
    Maximum test time '10m' exceeded.
    Adjust the test 'duration' attribute if necessary.
    https://tmt.readthedocs.io/en/stable/spec/tests.html#duration
2022-11-10 15:38:16 +01:00
Amith Kumar
8f54ba515e harden tools to block rogue python modules
Add test to policycoreutils/Regression suite which verifies bug 2128976
and ensures that irrelevant python scripts are not given precedence over
tools like semanage.

Signed-off-by: Amith Kumar <apeetham@redhat.com>
2022-11-01 18:39:40 +00:00
Ondrej Mosnacek
c3dd00f4bc
semodule-rebuild-if-modules-changed: test changing booleans
Extend the test to verify correct behavior when a boolean setting
override is injected. Also add auto-detection of the --refresh /
--rebuild-if-modules-changed command-line option support, which
indicates the expected level of functionality. (And we also need to
ensure that --refresh is used when supported because the other option
may be removed in the future.)

Additionally, we need to work around the fact that the exact binary
policy content can now be different depending on if the optimized code
path has been taken. Do this by toggling a boolean before introducing
injected customizations, thus obtaining the expected policy content for
the case after `semodule --refresh`.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-08-02 15:03:48 +02:00
Ondrej Mosnacek
a77df42754
semodule-rebuild-if-modules-changed: expand vars early
This will make the test output more explicit.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-08-02 15:03:48 +02:00
Milos Malik
98145eff71 add Makefile to enable runs via STI
Some CI frameworks still use STI which depends on existence of the
Makefile. In order to run this TC successfully in such frameworks,
the Makefile was added. Test description was also improved.
2022-08-02 10:00:37 +02:00
Milos Malik
09061d2739 test if semanage can import port definitions correctly
Recent testing revealed that `semanage import` cannot import
SELinux port definitions correctly if `port -D` is present
among them. The TC reproduces the situation.

The TC covers BZ#2063353 and BZ#2108174.
2022-07-27 10:12:11 +02:00
Milos Malik
01e114b092 test how semanage handles spaces in fcontext patterns
The semanage tool refuses (for some time already) fcontext patterns
which contain spaces. The TC checks if other whitespace characters
are treated the same way.

The TC covers BZ#1893545.
2022-07-15 13:27:05 +00:00
Zdenek Pytela
12dd91c7d4 avoid testing empty CIL modules
SELinux user-space version 3.3 and higher does not support loading
of empty CIL modules. If such version is installed, one of the test
phases will be skipped. This commit changes existing code to using
rlTestVersion.
2022-06-07 15:43:51 +00:00
Amith Kumar
81bb79481d policycoreutils: fix main.fmf file
Automated tests executed via TMT/FMF are failing due to absence of relevant packages.
Fix the main.fmf file to match the list of required packages/programs in `Makefile`.

Signed-off-by: Amith Kumar <apeetham@redhat.com>
2022-05-11 04:56:25 +05:30
Milos Malik
f1ffb0bbe5 remove all rhts-environment.sh includes
The rhts-environment.sh files are not needed anymore.
The include of beakerlib.sh is sufficient.
2022-04-26 13:18:49 +00:00
Milos Malik
1bf11b6606 convert metadata of all policycoreutils tests to TMT/FMF 2022-04-26 13:18:49 +00:00
Ondrej Mosnacek
8b7e684a0d Add a test for semodule --rebuild-if-modules-changed
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-03-01 12:58:06 +01:00