Commit graph

17 commits

Author SHA1 Message Date
Milos Malik
4e1655b3f3 make the upstream tests up-to-date
Some upstream tests diverged from their downstream versions. Let's
synchronize them.
2024-04-30 14:19:57 +00:00
Milos Malik
26a276d5c9 fix the tests which fail on CentOS-stream-10
The rlImport command fails in many tests because the epel-release
package is not available for RHEL-10 or CentOS-stream-10 yet.
As a workaround, an additional exit code 1 is accepted now.
2024-04-04 16:35:36 +00:00
Milos Malik
26edd45004 adapt to modified sedispol commands
The sedispol tool recognizes several commands. Before the checkpolicy
version 3.6 was introduced, one of the commands was 'u' which displayed
unknown handling setting. With the new version, the 'u' command prints
SELinux users which are defined and the 'U' command displays the unknown
handling setting.
2023-12-18 17:21:57 +01:00
Milos Malik
ef67d0deea test the actions recognized by sedismod and sedispol
Since SELinux user-space 3.6 was introduced, the sedismod and sedispol
programs are able to perform various actions non-interactively when
the following options are supplied: -a, --actions. In previous versions,
these actions were only usable in the interactive mode.
From now on, the automated test also covers these options.
2023-11-23 19:25:59 +00:00
Milos Malik
db5f56d258 work around the dnf5 issue when --skip-broken is not recognized
The SELinux beaker library calls the yum/dnf command and the
"--skip-broken" option is placed before the "install" word on the
command line. Such command line executed on Fedora rawhide leads to
the following error message:

  Unknown argument "--skip-broken" for command "dnf5". Add "--help" for
  more information about the arguments.

In order to work around this issue, the "install" word was moved before
the rest of options. Manual testing revealed that this approach works
on Fedora rawhide.
2023-06-23 10:41:42 +02:00
Milos Malik
75e8d39310 ensure that selinux-policy-{minimum,mls,targeted} are installed
For unknown reasons, selinux-policy-{minimum,mls,targeted} packages
are not installed or their available versions differ from each other.
Let's work around the issue.
2022-08-22 09:24:25 +00:00
Milos Malik
61078d379a convert metadata of all checkpolicy tests to TMT/FMF 2022-04-26 13:18:49 +00:00
Milos Malik
7a766b5ecd install the required packages
For unknown reason, the selinux-policy-mls package is not installed
before execution of the TC, even though it it a required package.
From now on, the TC will install the package explicitely.
2022-02-24 13:17:44 +00:00
Petr Lautrbach
1d45ca7dec checkmodule/checkmodule: Grep for error messages rather than debug logs
checkpolicy was updated in 2.9 in order not to write debug messages on ouput. It
doesn't output "loading policy ..." messages anymore.

At the same time, it should be enough to check the checkmodule exit status and
whether the OUTPUT_FILE exists

See 854fdc1ac4

Fixes:
[   PASS   ] :: Command 'checkmodule >& /tmp/tmp.GUkhm09UGI' (Expected 1, got 1)
[   FAIL   ] :: File '/tmp/tmp.GUkhm09UGI' should contain 'loading policy configuration from policy.conf'
[   PASS   ] :: Command 'checkmodule -b >& /tmp/tmp.GUkhm09UGI' (Expected 1, got 1)
[   FAIL   ] :: File '/tmp/tmp.GUkhm09UGI' should contain 'loading policy configuration from policy'
[  BEGIN   ] :: Running 'checkmodule -m -o mypolicy.output mypolicy.te 2>&1 | grep "checkmodule.*loading policy configuration from mypolicy.te"'
[   FAIL   ] :: Command 'checkmodule -m -o mypolicy.output mypolicy.te 2>&1 | grep "checkmodule.*loading policy configuration from mypolicy.te"' (Expected 0, got 1)
[  BEGIN   ] :: Running 'checkmodule -m -o mypolicy.output mypolicy.te 2>&1 | grep "checkmodule.*writing binary representation.*to mypolicy.output"'
[   FAIL   ] :: Command 'checkmodule -m -o mypolicy.output mypolicy.te 2>&1 | grep "checkmodule.*writing binary representation.*to mypolicy.output"' (Expected 0, got 1)
[  BEGIN   ] :: Running 'checkmodule -m -C -o mypolicy.output mypolicy.te 2>&1 | grep "checkmodule.*loading policy configuration from mypolicy.te"'
[   FAIL   ] :: Command 'checkmodule -m -C -o mypolicy.output mypolicy.te 2>&1 | grep "checkmodule.*loading policy configuration from mypolicy.te"' (Expected 0, got 1)
[  BEGIN   ] :: Running 'checkmodule -m -C -o mypolicy.output mypolicy.te 2>&1 | grep "checkmodule.*writing CIL to mypolicy.output"'
[   FAIL   ] :: Command 'checkmodule -m -C -o mypolicy.output mypolicy.te 2>&1 | grep "checkmodule.*writing CIL to mypolicy.output"' (Expected 0, got 1)
2019-04-09 15:32:29 +02:00
Petr Lautrbach
a207b0ec49 checkpolicy/checkpolicy: Grep for error messages rather than debug logs
checkpolicy was updated in 2.9 in order not to write debug messages on ouput. It
doesn't output "loading policy ..." messages anymore.

See 854fdc1ac4

Fixes:
[   PASS   ] :: Command 'checkpolicy >& /tmp/tmp.NMYnXbEmez' (Expected 1, got 1)
[   FAIL   ] :: File '/tmp/tmp.NMYnXbEmez' should contain 'loading policy configuration from policy.conf'
[   PASS   ] :: Command 'checkpolicy -b >& /tmp/tmp.NMYnXbEmez' (Expected 1, got 1)
[   FAIL   ] :: File '/tmp/tmp.NMYnXbEmez' should contain 'loading policy configuration from policy'
2019-04-09 15:23:30 +02:00
Petr Lautrbach
b41ff2e4c1 Fix path meta data
Commit 769880f7 added path meta data into .fmf files. As path's didn't have /
at the beginning test were not created correctly.

Fixes:
fatal: [fedora29]: FAILED! => {
    "msg": [
        "Tests failed: True",
        "Tests msg: FAIL selinuxselinux-policy/policy-rpm-macros",
        "FAIL selinuxcheckpolicy/checkpolicy",
        "FAIL selinuxlibsepol/sepol_check_context",
        "FAIL selinuxlibsemanage/verify-options-in-semanage-conf",
...

$ cat artifacts/FAIL_selinuxcheckpolicy-checkpolicy.log
FAIL test selinuxcheckpolicy/checkpolicy does not appear to be a file or directory
2018-10-14 21:52:42 +02:00
Petr Lautrbach
66a56a3e9b Revert "Fix path meta data"
This reverts commit 4cf575fc0b.

Some of paths were not correctly updated

Fixes:
        "FAIL selinux/olicycoreutils/booleans",
2018-10-14 21:48:49 +02:00
Petr Lautrbach
4cf575fc0b Fix path meta data
Commit 769880f7 added path meta data into .fmf files. As path's didn't have /
at the beginning test were not created correctly.

Fixes:
fatal: [fedora29]: FAILED! => {
    "msg": [
        "Tests failed: True",
        "Tests msg: FAIL selinuxselinux-policy/policy-rpm-macros",
        "FAIL selinuxcheckpolicy/checkpolicy",
        "FAIL selinuxlibsepol/sepol_check_context",
        "FAIL selinuxlibsemanage/verify-options-in-semanage-conf",
...

$ cat artifacts/FAIL_selinuxcheckpolicy-checkpolicy.log
FAIL test selinuxcheckpolicy/checkpolicy does not appear to be a file or directory
2018-10-14 21:31:10 +02:00
Petr Šplíchal
769880f739 Define path metadata for each test
Adding attribute "path" to each test according to the CI metadata
specification [1]. This also resolves problem with autodetecting
empty directories [2] which will be fixed in the next fmf release.

[1] https://fedoraproject.org/wiki/CI/Metadata#Path
[2] https://github.com/psss/fmf/pull/48
2018-10-11 10:45:08 +02:00
Petr Šplíchal
40894f79d3 Update tier metadata to the latest specification
There is now a dedicated field to store the tier info:
https://fedoraproject.org/wiki/CI/Metadata#Tier
Also added some missing component data.
2018-09-20 17:08:10 +02:00
Petr Šplíchal
3b2fd40114 Add initial test metadata using the FMF format
This adds an initial set of test metadata using the Flexible Metadata
Format for experimenting. This should allow us to more easily execute
relevant test coverage for all selinux-related components. Example:

    fmf --key test --filter 'tags:Tier1'
    fmf --key test --filter 'component:libselinux'
    fmf --key test --filter 'component:libselinux | tags:Tier1'

See https://github.com/psss/fmf for more details about the FMF format.
2018-02-19 15:05:29 +01:00
Petr Lautrbach
d731f78c63 Add tests from https://src.fedoraproject.org/rpms/checkpolicy/blob/master/f/tests 2018-02-14 13:39:35 +01:00