public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Ondrej Mosnacek <omosnace@redhat.com>
To: git-commits@fedoraproject.org
Subject: [tests/selinux] pr775-checkpolicy-revdeps: kernel/selinux-testsuite: patch the policy for restraint
Date: Fri, 11 Sep 2026 13:19:23 GMT	[thread overview]
Message-ID: <178913276312.1.16082049971523578616.tests-selinux-08dcaa35346d@fedoraproject.org> (raw)

            A new commit has been pushed.

            Repo   : tests/selinux
            Branch : pr775-checkpolicy-revdeps
            Commit : 08dcaa35346d7d80301a9bb026207f8d70ea2ebe
            Author : Ondrej Mosnacek <omosnace@redhat.com>
            Date   : 2021-09-22T22:41:55+02:00
            Stats  : +4/-0 in 1 file(s)
            URL    : https://src.fedoraproject.org/tests/selinux/c/08dcaa35346d7d80301a9bb026207f8d70ea2ebe?branch=pr775-checkpolicy-revdeps

            Log:
            kernel/selinux-testsuite: patch the policy for restraint

When this test in run via restraint (e.g. on Beaker), it inherits some
file descriptors originating from it, labeled unconfined_service_t. This
leads to a huge amount of denials when test programs are exectuted.

To work around this, add a rule to the policy that allows the test
domains to inherit these descriptors from unconfined_service_t.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>

---
diff --git a/kernel/selinux-testsuite/runtest.sh b/kernel/selinux-testsuite/runtest.sh
index b12338c..188c240 100755
--- a/kernel/selinux-testsuite/runtest.sh
+++ b/kernel/selinux-testsuite/runtest.sh
@@ -304,6 +304,10 @@ rlJournalStart
         } | rlRun "tee -a tests/tun_tap/tun_common.h" 0 \
             "Harden tun_tap test against missing defs"
 
+        # needed to avoid a flood of AVCs when run via restraint
+        rlRun "sed -i 's/type unconfined_t;/type unconfined_t, unconfined_service_t;/' policy/test_policy.if" 0
+        rlRun "sed -i 's/\\(allow \\\$1 initrc_t:fd use;\\)/\\1 allow \$1 unconfined_service_t:fd use;/' policy/test_policy.if" 0
+
         exclude_tests=""
         force_tests=""
         for file in ./tests/nnp*/execnnp.c; do

                 reply	other threads:[~2026-09-11 13:19 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=178913276312.1.16082049971523578616.tests-selinux-08dcaa35346d@fedoraproject.org \
    --to=omosnace@redhat.com \
    --cc=git-commits@fedoraproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox