The sepolicy tool can generate man pages for specific SELinux domains.
When the sepolicy tool was instructed to generate man pages in HTML
form (--web), the generated HTML files were very incomplete. The TC
reproduces the situation.
The newly added TC checks if the sepolicy manpage command works
correctly. The checks related to the sepolicy manpage command
were removed from the sepolicy-generate TC.
The TC covers BZ#1989840.
Recently, the new versions of systemd component revealed that SELinux
prevents the journal-offline command from relabeling (syscall=fsetxattr)
the systemd journal files. The TC reproduces the situation.
Because the relabeling of journal files is an intentional operation,
which happens when the systemd journal is rotated, I believe that
SELinux policy should allow it. The TC looks for appropriate policy
rules.
The TC covers BZ#2075527 and BZ#2152823 and their duplicates.
Effective changes:
- fix the policy to allow the new user_namespace::create permission
where needed
- fix the code to build without warnings with latest SELinux userspace
The rest is various cleanups or changes not affecting Fedora/RHEL.
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
SELinux policy now contains a new policy module which confines the
stacd and stafd services, which belong to the nvme-stas package.
This TC covers basic scenarios of running the services in default
configuration. The TC also looks for appropriate policy rules and
file context patterns.
The TC covers BZ#2111414.
Recent RHEL-9.2 instalation testing revealed that SELinux prevents
the systemd-rfkill processes from using the bpf capability. The TC
does not reproduce the situation unless the right HW is available.
In order to support the full functionality of the systemd-rfkill
program, I believe that SELinux policy should allow this action.
The TC looks for appropriate policy rule.
The TC covers BZ#2149390.
The use of systemd-machined and systemd-nspawn services revealed that
SELinux still prevents various actions they do. The TC reproduces the
situation.
In order to support the documented functionality of systemd-machine,
I believe that SELinux policy should allow these actions. The TC
looks for appropriate policy rules and file context patterns.
The TC covers BZ#1847545, BZ#1900869, BZ#1900888 and their duplicates.
Some tests were ending prematurely because their required packages
were not available. Fortunately, more and more packages are available
in the EPEL repository now and the situation has changed.
Some tests require packages which are not available on any RHEL and
most likely will not be available there at all.
If the framework which runs the automated tests does not install
all required packages (listed in Makefile) before the tests are
started, then rlSESatisfyRequires() installs the required packages
during the run of the tests.
Recent stalld testing identified the following error messages in the
systemd journal:
stalld[...]: stalld: Permission denied
Deeper investigation revealed that SELinux prevents the stalld
processes from reading the /sys/kernel/security/lockdown file. The
TC reproduces the situation.
In order to avoid the error messages, I believe that SELinux policy
should allow the access. The TC looks for appropriate policy rules
and file context patterns.
The TC covers BZ#2140673.
Purpose of the Tier1 test plan is to gather all Tier1 tests in this
repository.
Purpose of the Tier2 test plan is to gather all Tier2 tests in this
repository.
Purpose of the Tier3 test plan is to gather all Tier3 tests in this
repository.
Add test to policycoreutils/Regression suite which verifies bug 2128976
and ensures that irrelevant python scripts are not given precedence over
tools like semanage.
Signed-off-by: Amith Kumar <apeetham@redhat.com>
The automated test used to work with 100MB files. Unfortunately,
the mkfs.xfs program started to complain recently:
Filesystem must be larger than 300MB.
In order to use the automated test successfully in the future,
the allocated space was increased to 400MB.
The use of DynamicUser and StateDirectory features of systemd
in customer environments revealed that SELinux prevents the systemd
processes from reading the symbolic links under /var/lib directory.
The TC reproduces the situation.
Detailed information can be found at:
* https://www.redhat.com/sysadmin/systemd-secure-services
In order to fully support the systemd secure services feature,
I believe that SELinux policy should allow this access. The TC
looks for appropriate policy rules and file context patterns.
The TC covers BZ#2118784.
The use of blueman-mechanism service revealed that SELinux prevents
the blueman-mechanism process from reading the content of
/root/.local/lib/python3.10/site-packages/ directory. The TC reproduces
the situation.
Because the blueman-mechanism program is written in Python, it makes
sense to look for locally installed Python modules. In order to
support the basic Python principles, I believe that SELinux policy
should allow this access. The TC looks for appropriate policy rules
and file context patterns.
The TC covers BZ#2027044.
This TC covers the caddy service and its basic scenario with
default configuration.
Purpose of this TC is to find any SELinux interferences with the
caddy service.
The TC covers BZ#1706651 and BZ#2122886.
Otheriwse older kernel entries would still have our injected scripts in
the initramfs after test execution.
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
Forward-port of downstream kernel tests that haven't been upstreamed
yet, manually converted to TMT.
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
ramfs is now treated as an xattr-supporting filesystem and has the
fs_use_trans directive in the base policy. Thus switch to vfat, which is
still genfs.
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
Replace the current soft fallback to raw GIT_BRANCH when a required PR
or Patchwork patch fails to merge/apply with a hoard failure, similar to
what we do when cloning the repo fails.
The main motivation is to not have CKI treat this situation as a
failure, but it also a good practice to ensure we either run the
intended version of the test or no test at all.
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
For unknown reasons, selinux-policy-{minimum,mls,targeted} packages
are not installed or their available versions differ from each other.
Let's work around the issue.
Recent RDMA testing revealed that systemd-modules-load processes
cannot use openat syscall on /dev/kmsg and cannot use connect syscall
on /run/systemd/journal/socket because SELinux denies that. The
TC reproduces the situation when executed on a machine equipped
with RDMA (Infiniband) HW.
Because this scenario should work, I believe that SELinux policy
should allow above-mentioned actions. The TC looks for appropriate
policy rules and file context patterns.
The TC covers BZ#2088257 and BZ#2088258.
Extend the test to verify correct behavior when a boolean setting
override is injected. Also add auto-detection of the --refresh /
--rebuild-if-modules-changed command-line option support, which
indicates the expected level of functionality. (And we also need to
ensure that --refresh is used when supported because the other option
may be removed in the future.)
Additionally, we need to work around the fact that the exact binary
policy content can now be different depending on if the optimized code
path has been taken. Do this by toggling a boolean before introducing
injected customizations, thus obtaining the expected policy content for
the case after `semodule --refresh`.
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
Some CI frameworks still use STI which depends on existence of the
Makefile. In order to run this TC successfully in such frameworks,
the Makefile was added. Test description was also improved.
Recent testing revealed that `semanage import` cannot import
SELinux port definitions correctly if `port -D` is present
among them. The TC reproduces the situation.
The TC covers BZ#2063353 and BZ#2108174.
The semanage tool refuses (for some time already) fcontext patterns
which contain spaces. The TC checks if other whitespace characters
are treated the same way.
The TC covers BZ#1893545.
SELinux policy confines the bgpd program (the bgpd service as well).
This TC covers basic scenarios of running the service in default
configuration. The TC also looks for appropriate policy rules and
file context patterns.
The TC covers BZ#2055578.
Recent stalld testing revealed that SELinux prevents the stalld
processes from using the sched_setattr syscall on the running
kernel threads. The TC does not reproduce the situation.
In order to avoid the SELinux denials and support all functions
of the stalld service, SELinux policy should allow the use of
sched_setattr syscall. The TC looks for appropriate policy rules.
The TC covers BZ#2102224.
Frequent use of the dhclient program in various environments revealed
that SELinux prevents the /etc/dhcp/dhclient.d/chrony.sh script from
appending to files stored in the /run/chrony-dhcp/ directory. The TC
reproduces the situation.
Because the /etc/dhcp/dhclient.d/chrony.sh script is brought by the
chrony package and the scripts in the /etc/dhcp/dhclient.d/ directory
are by default executed by the dhclient-script program, I believe that
SELinux policy should allow the access. The TC looks for appropriate
policy rules and file context patterns.
The TC covers BZ#2035117, BZ#2093709 and BZ#2094155.
One of the new systemd features allows passing secret credentials
to various services, but SELinux prevents all sd-mkdcreds processes
running as init_t from accessing all /dev/shm/.#cred* files. The
TC reproduces the situation.
In order to support this systemd feature, SELinux policy should allow
these actions. The TC looks for appropriate policy rules and file
context patterns.
The TC covers BZ#2096857 and BZ#2097681.
Recent use of the setfiles program in chroot-ed environment revealed
the following error messages:
/usr/sbin/setfiles: Could not set context for /usr/include: No such file or directory
The problem was identified and fixed in the libselinux code. Purpose
of this TC is to test whether the fixfiles behaves correctly in such
environments.
The TC covers BZ#2094683.
Recent manual testing of the fedora-third-party-refresh service
revealed that SELinux prevents the fedora-third-party process from
reading the /etc/passwd file. The TC reproduces the situation.
Interestingly, the fedora-third-party-refresh service starts and
succeeds even if the access is denied, which means that SELinux
policy can either allow or dontaudit the access. The TC looks for
appropriate policy rules and file context patterns.
The TC covers BZ#2093453.
Recent stalld testing revealed that SELinux prevents the stalld processes
from using the sched_getattr syscall on the running kernel. The TC
does not reproduce the situation.
In order to fix the SELinux denials, SELinux policy should either
allow or dontaudit the use of sched_getattr syscall. The TC looks
for appropriate policy rules.
The TC covers BZ#2096776.
Recent use of the ksm service revealed that SELinux prevents the
ksmctl process from creating the run file in the /sys/kernel/mm/ksm/
directory. The TC reproduces the situation.
The ksmctl binary contains the following locations (the strings command
found them):
* /sys/kernel/mm/ksm/run
* /sys/kernel/mm/ksm/max_kernel_pages
In order to make the ksm service fully functional, I believe that
SELinux policy should allow the create access to these files. The
TC looks for appropriate policy rules and file context patterns.
The TC covers BZ#2091416, BZ#2091417 and BZ#2091418.
The only effective difference is that the broken SCTP ASCONF tests will
now be skipped, see:
3e93ece73d
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
SELinux user-space version 3.3 and higher does not support loading
of empty CIL modules. If such version is installed, one of the test
phases will be skipped. This commit changes existing code to using
rlTestVersion.
The following messages found in the systemd journal revealed that
the stalld service cannot perform all operations it wants:
stalld[...]: boost_with_deadline failed to boost pid 0: Operation not permitted
stalld[...]: boost_with_fifo failed to boost pid 0: Operation not permitted
stalld[...]: boost_with_deadline failed to boost pid 0: Permission denied
stalld[...]: boost_with_fifo failed to boost pid 0: Permission denied
Unfortunately, SELinux policy contains a dontaudit rule which hides
SELinux denials triggered by the stalld service in this situation.
In order to fix the issue, SELinux policy should allow the sys_nice
capability and the setsched permission to the stalld_t labeled processes.
The TC runs the stalld service and looks for such rules.
The TC covers BZ#2092864.