A recently reported customer case revealed that the restorecond
service occasionally fails to start because of a timeout. The
exact reproducer is unknown, but the TC reproduces a similar
situation (mislabeled /run/restorecond.pid file) which also leads
to timeouts.
In order to fix the problem, the restorecond service is no longer
a forking type of service. It is a single type of service. The TC
checks this parameter too.
The TC covers RHEL-142541 and RHEL-165247.
Unfortunately, the test was merged even if some metadata was missing.
Additionally, the description and summary contains characters which
are not allowed based on the output of: tmt tests lint.
Both problems should be fixed now.
A recently reported customer case revealed that the restorecon
program produces error messages even if it was executed with
the '-i' option. In such case no error messages should appear
when the inspected filesystem objects are missing.
The TC reproduces the situation when old libselinux/policycoreutils
packages are installed.
The TC covers RHEL-110181 and RHEL-123884.
Whenever a key is defined in the tmt hierarchy and some child also
defines that key, the child's will overwrite the previous one. The "+"
changes the operation to "append", so the content of key+ in the child
is added to the existing key.
Meaning that any "adjust" statement in a test plan using a test that
defines it's own "adjust:" is ignored.
Since we are expecting other statements to be appended to the "adjust"
sections, the content of each section needs to be a single list item as
opposed to a set of key-value pairs (first line needs to start with a
hyphen).
- Replace all "adjust:" sections with "adjust+:" in order to honor any
adjustments further up the tree (parent tests, or test plans).
- Fix malformed "adjust" sections (sets of key-value pairs)
Signed-off-by: Vit Mojzis <vmojzis@redhat.com>
A syntax error appears when the following test is executed:
* policycoreutils/semodule-rebuild-if-modules-changed
The problem is a missing "then" word in the test code.
Tests which are not suitable (various reasons) for image mode
testing will get the avoidImageMode tag. If their conditions improve,
the tag can be removed.
Removed redundant tags (e.g., Tier2/Tier3 and Tier2se/Tier3se) from all tests
with "tier: 2" and "tier: 3" metadata. The "tier" metadata is used instead.
Signed-off-by: Jan Janasek <jjanasek@redhat.com>
all tests with CI-Tier-1 tag should have "tier: 1" in their metadata,
also removing tags Tier1 and Tier1se and lastly tests with "tier: 2"
and "tier: 3" should not have CI-Tier-1 tag.
Signed-off-by: Jan Janasek <jjanasek@redhat.com>
bootc-e2e tests requires specific environment related to image mode. The
image is prepared using buildah and later booted. This is not supported
in this test suite (yet)
Signed-off-by: Petr Lautrbach <lautrbach@redhat.com>
Even though the tests require various selinux-policy-* packages,
some of packages may not be available on all platforms and
architectures. It can also happen that SELinux policy store is
installed in an unusual location. The tests should cope with both
situations.
Proper list of dependecies is necessary as not all distros
have every package preinstalled, for example on RHIVOS
we didn't have e2fsprogs in the system, while on more general use systems
it is included almost always, which is why it wasn't causing problems before
Apply the failinfedora tag to the tests which fail on Fedora rawhide.
Add a special test plan for regular runs of these failing tests.
Make sure that the no-tier test plan contains tests which succeed on
Fedora rawhide.
In CentOS Stream 10 some modules were moved from selinux-policy to
selinux-policy-epel which is available only in EPEL. It caused problem
with non-existing booleans and their aliases. With this change, an alias
is not checked when a new boolean does not exist.
Fixes:
Error getting active value for puppet_manage_all_files
[ PASS ] :: Command 'getsebool puppet_manage_all_files 2>&1 | tee /tmp/tmp.nx2NlWq1zd' (Expected 0, got 0)
[ BEGIN ] :: Running 'getsebool puppetagent_manage_all_files 2>&1 | tee -a /tmp/tmp.nx2NlWq1zd'
Error getting active value for puppetagent_manage_all_files
[ PASS ] :: Command 'getsebool puppetagent_manage_all_files 2>&1 | tee -a /tmp/tmp.nx2NlWq1zd' (Expected 0, got 0)
[ BEGIN ] :: Running 'uniq -c /tmp/tmp.nx2NlWq1zd | grep '2 ''
[ FAIL ] :: Command 'uniq -c /tmp/tmp.nx2NlWq1zd | grep '2 '' (Expected 0, got 1)
The modified tests used to fail on RHEL-10 or they caused other tests
to fail on RHEL-10. The reasons are various:
* dependency on SELinux types which are no longer defined
* insufficient test cleanup
* unexpected exit codes
* virtual vs. bare metal environment differences
These problems should be fixed now.
The modified tests were failing because:
* the running restorecond service causes problems to the subsequent tests
* an irrelevant bug was tested
* the bind component is available in multiple versions
* rpm output contained unnecessary whitespaces
These issues should be fixed now.
There are booth commands which may stall the automated test execution.
Let's run them with a 20 second deadline.
There are other tests which need more time to finish when executed
on slower machines. Their duration got extended.
1 test was failing because of a test code issue.
1 test was missing an important test phase.
The number of tests which are missing their nitrate metadata
should be again smaller.
The /policycoreutils/setfiles_binary test: the --downloaddir option
is not recognized by the latest version of DNF. The option is removed
now.
The /other/update-packages test: the --skip-broken option is not
recognized by the latest version of DNF. The option is removed now.
The /selinux-policy/install-uninstall-dsp-packages test: let's not
run this test together with other tests, because it often finds
a problem that brakes the environment for the following tests.
Some components/packages are not available on CentOS-stream-10,
which leads to conclusion not to run the affected tests/phases there.
The /var and /run directories very often contain mislabeled files
and directories. In order to find discrepancies between file context
patterns and type_transition rules defined in the SELinux policy,
the restorecon command is needed.
The semanage command from older policycoreutils versions (<= 3.6-1.el9)
behaves in a certain way when a duplicated port context pattern is added.
It does not add the pattern but produces the following message:
ValueError: Port <protocol>/<number> already defined
The semanage command from new policycoreutils versions (>= 3.6-2.el9)
behaves differently when a duplicated port context pattern is added.
It adds the pattern and produces the following message:
Port <protocol>/<number> already defined, modifying instead
Above-mentioned differences in behavior have some consequences for the
automated test when removing a duplicated port context pattern. If the
automated test should pass, it needs to anticipate both possibilities.
Apparently, the first attempt to adjust the relevancy was not
complete. So here is another one.
Certain tests should not be executed on centos-stream 8 or 9 at all,
because packages required by those tests are not available there.
Certain tests need to reflect the fact that SELinux policies which
confine the tested programs are not present on all versions of RHEL,
CentOS or Fedora.
The abrt* packages are not available on RHEL-9, which means that
one of the test phases would fail if this change was not done.
The test phase dedicated to /usr/sbin/abrtd will be executed only
if the file is present.
Restore the restorecond service to its original state.
The restorecond service should not stay running if it was not
running before execution of the test.
Rework the conditional so that the new part of the test runs everywhere
except specified old version cases. Before this it wouldn't be run on
Fedora, CentOS, or RHEL>=10.
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
The bulk of the logic is implemented inside libsemanage, so add to the
component list, so that the test is run also on changes in libsemanage.
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
Not all packages required by the tests were installed. The issue
should be fixed now.
Relevancy of certain tests was set incorrectly. The issue should
be fixed now.
At least 1 test runs longer than its specified duration. The issue
should be fixed now.
A new test phase was added. Purpose of the test phase is to find
out whether the `sepolicy manpage` command can generate man pages
for all SELinux domains without triggering an error or traceback.
The TC covers BZ#1416372.
The sepolicy tool can generate man pages for specific SELinux domains.
When the sepolicy tool was instructed to generate man pages in HTML
form (--web), the generated HTML files were very incomplete. The TC
reproduces the situation.
The newly added TC checks if the sepolicy manpage command works
correctly. The checks related to the sepolicy manpage command
were removed from the sepolicy-generate TC.
The TC covers BZ#1989840.
Add test to policycoreutils/Regression suite which verifies bug 2128976
and ensures that irrelevant python scripts are not given precedence over
tools like semanage.
Signed-off-by: Amith Kumar <apeetham@redhat.com>
Extend the test to verify correct behavior when a boolean setting
override is injected. Also add auto-detection of the --refresh /
--rebuild-if-modules-changed command-line option support, which
indicates the expected level of functionality. (And we also need to
ensure that --refresh is used when supported because the other option
may be removed in the future.)
Additionally, we need to work around the fact that the exact binary
policy content can now be different depending on if the optimized code
path has been taken. Do this by toggling a boolean before introducing
injected customizations, thus obtaining the expected policy content for
the case after `semodule --refresh`.
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
Some CI frameworks still use STI which depends on existence of the
Makefile. In order to run this TC successfully in such frameworks,
the Makefile was added. Test description was also improved.
Recent testing revealed that `semanage import` cannot import
SELinux port definitions correctly if `port -D` is present
among them. The TC reproduces the situation.
The TC covers BZ#2063353 and BZ#2108174.
The semanage tool refuses (for some time already) fcontext patterns
which contain spaces. The TC checks if other whitespace characters
are treated the same way.
The TC covers BZ#1893545.
SELinux user-space version 3.3 and higher does not support loading
of empty CIL modules. If such version is installed, one of the test
phases will be skipped. This commit changes existing code to using
rlTestVersion.