public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Ondrej Mosnacek <omosnace@redhat.com>
To: git-commits@fedoraproject.org
Subject: [tests/selinux] pr775-checkpolicy-revdeps: kernel/selinux-testsuite: patch the policy for restraint
Date: Fri, 11 Sep 2026 13:19:23 GMT [thread overview]
Message-ID: <178913276312.1.16082049971523578616.tests-selinux-08dcaa35346d@fedoraproject.org> (raw)
A new commit has been pushed.
Repo : tests/selinux
Branch : pr775-checkpolicy-revdeps
Commit : 08dcaa35346d7d80301a9bb026207f8d70ea2ebe
Author : Ondrej Mosnacek <omosnace@redhat.com>
Date : 2021-09-22T22:41:55+02:00
Stats : +4/-0 in 1 file(s)
URL : https://src.fedoraproject.org/tests/selinux/c/08dcaa35346d7d80301a9bb026207f8d70ea2ebe?branch=pr775-checkpolicy-revdeps
Log:
kernel/selinux-testsuite: patch the policy for restraint
When this test in run via restraint (e.g. on Beaker), it inherits some
file descriptors originating from it, labeled unconfined_service_t. This
leads to a huge amount of denials when test programs are exectuted.
To work around this, add a rule to the policy that allows the test
domains to inherit these descriptors from unconfined_service_t.
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
---
diff --git a/kernel/selinux-testsuite/runtest.sh b/kernel/selinux-testsuite/runtest.sh
index b12338c..188c240 100755
--- a/kernel/selinux-testsuite/runtest.sh
+++ b/kernel/selinux-testsuite/runtest.sh
@@ -304,6 +304,10 @@ rlJournalStart
} | rlRun "tee -a tests/tun_tap/tun_common.h" 0 \
"Harden tun_tap test against missing defs"
+ # needed to avoid a flood of AVCs when run via restraint
+ rlRun "sed -i 's/type unconfined_t;/type unconfined_t, unconfined_service_t;/' policy/test_policy.if" 0
+ rlRun "sed -i 's/\\(allow \\\$1 initrc_t:fd use;\\)/\\1 allow \$1 unconfined_service_t:fd use;/' policy/test_policy.if" 0
+
exclude_tests=""
force_tests=""
for file in ./tests/nnp*/execnnp.c; do
reply other threads:[~2026-09-11 13:19 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178913276312.1.16082049971523578616.tests-selinux-08dcaa35346d@fedoraproject.org \
--to=omosnace@redhat.com \
--cc=git-commits@fedoraproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox