Commit graph

402 commits

Author SHA1 Message Date
Milos Malik
b6ec2fee8d test if sepolicy manpage can generate manpage in HTML form
The sepolicy tool can generate man pages for specific SELinux domains.
When the sepolicy tool was instructed to generate man pages in HTML
form (--web), the generated HTML files were very incomplete. The TC
reproduces the situation.

The newly added TC checks if the sepolicy manpage command works
correctly. The checks related to the sepolicy manpage command
were removed from the sepolicy-generate TC.

The TC covers BZ#1989840.
2023-01-17 11:43:37 +01:00
Zdenek Pytela
ad7293e725 selinux-policy: Do not test if rpmdb can access host name services
Unlike originally reported in bz#1461313 and in some duplicates,
rpmdb does not need access to resolv.conf and sssd any longer.
Refer to https://bugzilla.redhat.com/show_bug.cgi?id=1461313#c73
for more information.
2023-01-09 16:28:59 +00:00
Milos Malik
a59d3c04ad test if journal-offline can relabel the journal files
Recently, the new versions of systemd component revealed that SELinux
prevents the journal-offline command from relabeling (syscall=fsetxattr)
the systemd journal files. The TC reproduces the situation.

Because the relabeling of journal files is an intentional operation,
which happens when the systemd journal is rotated, I believe that
SELinux policy should allow it. The TC looks for appropriate policy
rules.

The TC covers BZ#2075527 and BZ#2152823 and their duplicates.
2022-12-14 10:03:04 +01:00
Ondrej Mosnacek
96c98bb01d
kernel/selinux-testsuite: bump upstream commit
Effective changes:
- fix the policy to allow the new user_namespace::create permission
  where needed
- fix the code to build without warnings with latest SELinux userspace

The rest is various cleanups or changes not affecting Fedora/RHEL.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-12-12 16:19:39 +01:00
Ondrej Mosnacek
e70a8df7c8 Add coverage for the hardening of executing binaries by the kernel
See the test description/Bugzilla for more details.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-12-09 10:40:36 +00:00
Milos Malik
202b220c73 add new test which covers the stacd and stafd services
SELinux policy now contains a new policy module which confines the
stacd and stafd services, which belong to the nvme-stas package.
This TC covers basic scenarios of running the services in default
configuration. The TC also looks for appropriate policy rules and
file context patterns.

The TC covers BZ#2111414.
2022-12-07 08:29:32 +00:00
Milos Malik
677e8492b9 test if systemd-rfkill can use the bpf capability
Recent RHEL-9.2 instalation testing revealed that SELinux prevents
the systemd-rfkill processes from using the bpf capability. The TC
does not reproduce the situation unless the right HW is available.

In order to support the full functionality of the systemd-rfkill
program, I believe that SELinux policy should allow this action.
The TC looks for appropriate policy rule.

The TC covers BZ#2149390.
2022-12-02 19:48:14 +01:00
Milos Malik
de80db37fe add new test which covers systemd-machined
The use of systemd-machined and systemd-nspawn services revealed that
SELinux still prevents various actions they do. The TC reproduces the
situation.

In order to support the documented functionality of systemd-machine,
I believe that SELinux policy should allow these actions. The TC
looks for appropriate policy rules and file context patterns.

The TC covers BZ#1847545, BZ#1900869, BZ#1900888 and their duplicates.
2022-12-02 08:41:50 +00:00
Milos Malik
f1b7777fbf bring all downstream changes to the upstream tests
Downstream and upstream versions of certain automated tests
diverged before the duplicates were removed.

Now, they should be in sync.
2022-12-01 18:42:46 +01:00
Milos Malik
a7d24f4292 test if ladvd produces any SELinux denials
The test should look for any SELinux denials that appear during
its run. No matter which process triggered them.
2022-11-28 15:50:21 +01:00
Petr Lautrbach
8effe6fd87 Use ausearch --input-logs
CI systems don't necessary attach stdin to terminal and this option make
`ausearch` to use audit logs as input for searching.
2022-11-24 11:30:48 +01:00
Milos Malik
162cc22a2e enable tests if their required packages are available
Some tests were ending prematurely because their required packages
were not available. Fortunately, more and more packages are available
in the EPEL repository now and the situation has changed.

Some tests require packages which are not available on any RHEL and
most likely will not be available there at all.
2022-11-23 10:53:11 +01:00
Milos Malik
d1caaec9e2 add a simplified version of rlSESatisfyRequires()
If the framework which runs the automated tests does not install
all required packages (listed in Makefile) before the tests are
started, then rlSESatisfyRequires() installs the required packages
during the run of the tests.
2022-11-22 14:14:16 +01:00
Milos Malik
b28143f1cc don't look for watch* permissions where they aren't defined
The watch* permissions are not defined by SELinux policy on RHEL-8.x.
2022-11-21 11:44:04 +01:00
Milos Malik
889bc16ec3 install required packages from EPEL repository
For successful run, some tests require certain EPEL packages to be
installed.
2022-11-10 15:20:13 +00:00
Petr Lautrbach
3727a6ade6 Adjust duration to 20m in linux-system-roles.selinux-tests
Fixes:
    Maximum test time '10m' exceeded.
    Adjust the test 'duration' attribute if necessary.
    https://tmt.readthedocs.io/en/stable/spec/tests.html#duration
2022-11-10 15:38:16 +01:00
Milos Malik
09f8be4247 test if stalld can read /sys/kernel/security/lockdown
Recent stalld testing identified the following error messages in the
systemd journal:

  stalld[...]: stalld: Permission denied

Deeper investigation revealed that SELinux prevents the stalld
processes from reading the /sys/kernel/security/lockdown file. The
TC reproduces the situation.

In order to avoid the error messages, I believe that SELinux policy
should allow the access. The TC looks for appropriate policy rules
and file context patterns.

The TC covers BZ#2140673.
2022-11-07 18:28:29 +01:00
Milos Malik
7773d77b0b fix the shell script name executed in the Makefile
Now the Makefile runs the test.sh file instead of the runtest.sh file.
2022-11-04 12:04:33 +01:00
Milos Malik
61ef9e6185 add the Tier test plans
Purpose of the Tier1 test plan is to gather all Tier1 tests in this
repository.

Purpose of the Tier2 test plan is to gather all Tier2 tests in this
repository.

Purpose of the Tier3 test plan is to gather all Tier3 tests in this
repository.
2022-11-02 08:10:34 +00:00
Amith Kumar
8f54ba515e harden tools to block rogue python modules
Add test to policycoreutils/Regression suite which verifies bug 2128976
and ensures that irrelevant python scripts are not given precedence over
tools like semanage.

Signed-off-by: Amith Kumar <apeetham@redhat.com>
2022-11-01 18:39:40 +00:00
Milos Malik
289ec8d0b8 use a larger file for mkfs.xfs testing
The automated test used to work with 100MB files. Unfortunately,
the mkfs.xfs program started to complain recently:

  Filesystem must be larger than 300MB.

In order to use the automated test successfully in the future,
the allocated space was increased to 400MB.
2022-11-01 10:52:27 +01:00
Milos Malik
efc6c0b001 test if systemd can read symlinks under /var/lib/
The use of DynamicUser and StateDirectory features of systemd
in customer environments revealed that SELinux prevents the systemd
processes from reading the symbolic links under /var/lib directory.
The TC reproduces the situation.

Detailed information can be found at:
 * https://www.redhat.com/sysadmin/systemd-secure-services

In order to fully support the systemd secure services feature,
I believe that SELinux policy should allow this access. The TC
looks for appropriate policy rules and file context patterns.

The TC covers BZ#2118784.
2022-10-25 08:14:52 +00:00
Petr Lautrbach
31f776e00a Can libsepol handle users declared in modules?
https://bugzilla.redhat.com/show_bug.cgi?id=2136212
2022-10-21 15:33:30 +02:00
Milos Malik
7eff6e0a47 test if blueman-mechanism can read ~/.local/lib/python*/site-packages/
The use of blueman-mechanism service revealed that SELinux prevents
the blueman-mechanism process from reading the content of
/root/.local/lib/python3.10/site-packages/ directory. The TC reproduces
the situation.

Because the blueman-mechanism program is written in Python, it makes
sense to look for locally installed Python modules. In order to
support the basic Python principles, I believe that SELinux policy
should allow this access. The TC looks for appropriate policy rules
and file context patterns.

The TC covers BZ#2027044.
2022-09-23 12:38:51 +02:00
Milos Malik
8d27520fad add new automated test which covers the caddy service
This TC covers the caddy service and its basic scenario with
default configuration.

Purpose of this TC is to find any SELinux interferences with the
caddy service.

The TC covers BZ#1706651 and BZ#2122886.
2022-09-23 08:44:52 +02:00
Ondrej Mosnacek
269502e64d
kernel/labeling_before_...: use --regenerate-all also during cleanup
Otheriwse older kernel entries would still have our injected scripts in
the initramfs after test execution.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-09-15 15:20:55 +02:00
Ondrej Mosnacek
ef2646911d
Port kernel tests from downstream
Forward-port of downstream kernel tests that haven't been upstreamed
yet, manually converted to TMT.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-09-13 14:24:47 +02:00
Ondrej Mosnacek
25176f01ce
kernel/genfs_fallback: use vfat instead of ramfs
ramfs is now treated as an xattr-supporting filesystem and has the
fs_use_trans directive in the base policy. Thus switch to vfat, which is
still genfs.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-09-13 11:06:41 +02:00
Ondrej Mosnacek
03bf3a0e70
kernel/selinux-testsuite: fail hard when PR/patch application fails
Replace the current soft fallback to raw GIT_BRANCH when a required PR
or Patchwork patch fails to merge/apply with a hoard failure, similar to
what we do when cloning the repo fails.

The main motivation is to not have CKI treat this situation as a
failure, but it also a good practice to ensure we either run the
intended version of the test or no test at all.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-08-31 10:23:41 +02:00
Ondrej Mosnacek
21a2855558
kernel/selinux-testsuite: bump upstream commit to c592d7f
Effective changes:
* fix for https://gitlab.com/redhat/centos-stream/tests/kernel/kernel-tests/-/issues/1352
* major testsuite policy refactoring
* various minor fixes/tweaks

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-08-30 20:18:33 +02:00
Milos Malik
d86b1fb0ce test if stalld can get+set scheduling for all domains
TBA later

The TC covers BZ#2105038.
2022-08-25 15:18:26 +02:00
Milos Malik
75e8d39310 ensure that selinux-policy-{minimum,mls,targeted} are installed
For unknown reasons, selinux-policy-{minimum,mls,targeted} packages
are not installed or their available versions differ from each other.
Let's work around the issue.
2022-08-22 09:24:25 +00:00
Milos Malik
d121114f70 test if systemd-modules-load can work with /dev/kmsg and systemd-journal
Recent RDMA testing revealed that systemd-modules-load processes
cannot use openat syscall on /dev/kmsg and cannot use connect syscall
on /run/systemd/journal/socket because SELinux denies that. The
TC reproduces the situation when executed on a machine equipped
with RDMA (Infiniband) HW.

Because this scenario should work, I believe that SELinux policy
should allow above-mentioned actions. The TC looks for appropriate
policy rules and file context patterns.

The TC covers BZ#2088257 and BZ#2088258.
2022-08-15 16:48:26 +02:00
Ondrej Mosnacek
c3dd00f4bc
semodule-rebuild-if-modules-changed: test changing booleans
Extend the test to verify correct behavior when a boolean setting
override is injected. Also add auto-detection of the --refresh /
--rebuild-if-modules-changed command-line option support, which
indicates the expected level of functionality. (And we also need to
ensure that --refresh is used when supported because the other option
may be removed in the future.)

Additionally, we need to work around the fact that the exact binary
policy content can now be different depending on if the optimized code
path has been taken. Do this by toggling a boolean before introducing
injected customizations, thus obtaining the expected policy content for
the case after `semodule --refresh`.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-08-02 15:03:48 +02:00
Ondrej Mosnacek
a77df42754
semodule-rebuild-if-modules-changed: expand vars early
This will make the test output more explicit.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-08-02 15:03:48 +02:00
Milos Malik
98145eff71 add Makefile to enable runs via STI
Some CI frameworks still use STI which depends on existence of the
Makefile. In order to run this TC successfully in such frameworks,
the Makefile was added. Test description was also improved.
2022-08-02 10:00:37 +02:00
Milos Malik
09061d2739 test if semanage can import port definitions correctly
Recent testing revealed that `semanage import` cannot import
SELinux port definitions correctly if `port -D` is present
among them. The TC reproduces the situation.

The TC covers BZ#2063353 and BZ#2108174.
2022-07-27 10:12:11 +02:00
Ondrej Mosnacek
de353795c2
kernel/selinux-testsuite: use correct linker to build kernel modules
Start applying a testsite patch that fixes kernel module build for
kernels built with clang + with LTO enabled.

Fixes: https://gitlab.com/redhat/centos-stream/tests/kernel/kernel-tests/-/issues/1272
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-07-18 13:25:02 +02:00
Milos Malik
01e114b092 test how semanage handles spaces in fcontext patterns
The semanage tool refuses (for some time already) fcontext patterns
which contain spaces. The TC checks if other whitespace characters
are treated the same way.

The TC covers BZ#1893545.
2022-07-15 13:27:05 +00:00
Milos Malik
7f95c9d3a2 add new test which covers the bgpd service
SELinux policy confines the bgpd program (the bgpd service as well).
This TC covers basic scenarios of running the service in default
configuration. The TC also looks for appropriate policy rules and
file context patterns.

The TC covers BZ#2055578.
2022-07-15 07:47:41 +00:00
Milos Malik
606eccfd75 test if stalld can use sched_setattr on kernel
Recent stalld testing revealed that SELinux prevents the stalld
processes from using the sched_setattr syscall on the running
kernel threads. The TC does not reproduce the situation.

In order to avoid the SELinux denials and support all functions
of the stalld service, SELinux policy should allow the use of
sched_setattr syscall. The TC looks for appropriate policy rules.

The TC covers BZ#2102224.
2022-06-30 09:51:02 +02:00
Milos Malik
7710067379 test if dhclient-script can access /run/chrony-dhcp/ and its content
Frequent use of the dhclient program in various environments revealed
that SELinux prevents the /etc/dhcp/dhclient.d/chrony.sh script from
appending to files stored in the /run/chrony-dhcp/ directory. The TC
reproduces the situation.

Because the /etc/dhcp/dhclient.d/chrony.sh script is brought by the
chrony package and the scripts in the /etc/dhcp/dhclient.d/ directory
are by default executed by the dhclient-script program, I believe that
SELinux policy should allow the access. The TC looks for appropriate
policy rules and file context patterns.

The TC covers BZ#2035117, BZ#2093709 and BZ#2094155.
2022-06-28 08:47:39 +00:00
Milos Malik
9c17ff1ea7 add new systemd-creds test
One of the new systemd features allows passing secret credentials
to various services, but SELinux prevents all sd-mkdcreds processes
running as init_t from accessing all /dev/shm/.#cred* files. The
TC reproduces the situation.

In order to support this systemd feature, SELinux policy should allow
these actions. The TC looks for appropriate policy rules and file
context patterns.

The TC covers BZ#2096857 and BZ#2097681.
2022-06-27 13:36:09 +00:00
Milos Malik
9cb79c94c6 test if setfiles works correctly in chroot-ed environment
Recent use of the setfiles program in chroot-ed environment revealed
the following error messages:

  /usr/sbin/setfiles: Could not set context for /usr/include:  No such file or directory

The problem was identified and fixed in the libselinux code. Purpose
of this TC is to test whether the fixfiles behaves correctly in such
environments.

The TC covers BZ#2094683.
2022-06-27 12:17:09 +00:00
Milos Malik
0566a3c889 test if fedora-third-party process can read /etc/passwd file
Recent manual testing of the fedora-third-party-refresh service
revealed that SELinux prevents the fedora-third-party process from
reading the /etc/passwd file. The TC reproduces the situation.

Interestingly, the fedora-third-party-refresh service starts and
succeeds even if the access is denied, which means that SELinux
policy can either allow or dontaudit the access. The TC looks for
appropriate policy rules and file context patterns.

The TC covers BZ#2093453.
2022-06-23 16:11:28 +00:00
Milos Malik
341a2e48ca test if stalld can use sched_getattr on kernel
Recent stalld testing revealed that SELinux prevents the stalld processes
from using the sched_getattr syscall on the running kernel. The TC
does not reproduce the situation.

In order to fix the SELinux denials, SELinux policy should either
allow or dontaudit the use of sched_getattr syscall. The TC looks
for appropriate policy rules.

The TC covers BZ#2096776.
2022-06-14 16:36:47 +02:00
Milos Malik
b322ded769 test if ksmctl process can create /sys/kernel/mm/ksm/run file
Recent use of the ksm service revealed that SELinux prevents the
ksmctl process from creating the run file in the /sys/kernel/mm/ksm/
directory. The TC reproduces the situation.

The ksmctl binary contains the following locations (the strings command
found them):
 * /sys/kernel/mm/ksm/run
 * /sys/kernel/mm/ksm/max_kernel_pages

In order to make the ksm service fully functional, I believe that
SELinux policy should allow the create access to these files. The
TC looks for appropriate policy rules and file context patterns.

The TC covers BZ#2091416, BZ#2091417 and BZ#2091418.
2022-06-09 15:32:49 +00:00
Ondrej Mosnacek
66bf874bec kernel/selinux-testsuite: bump upstream commit
The only effective difference is that the broken SCTP ASCONF tests will
now be skipped, see:
3e93ece73d

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2022-06-08 09:27:31 +00:00
Zdenek Pytela
12dd91c7d4 avoid testing empty CIL modules
SELinux user-space version 3.3 and higher does not support loading
of empty CIL modules. If such version is installed, one of the test
phases will be skipped. This commit changes existing code to using
rlTestVersion.
2022-06-07 15:43:51 +00:00
Milos Malik
b0e50d2418 test if stalld process can use sched_setattr syscall
The following messages found in the systemd journal revealed that
the stalld service cannot perform all operations it wants:

stalld[...]: boost_with_deadline failed to boost pid 0: Operation not permitted
stalld[...]: boost_with_fifo failed to boost pid 0: Operation not permitted
stalld[...]: boost_with_deadline failed to boost pid 0: Permission denied
stalld[...]: boost_with_fifo failed to boost pid 0: Permission denied

Unfortunately, SELinux policy contains a dontaudit rule which hides
SELinux denials triggered by the stalld service in this situation.

In order to fix the issue, SELinux policy should allow the sys_nice
capability and the setsched permission to the stalld_t labeled processes.
The TC runs the stalld service and looks for such rules.

The TC covers BZ#2092864.
2022-06-06 13:34:21 +00:00