public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Milos Malik <mmalik@redhat.com>
To: git-commits@fedoraproject.org
Subject: [tests/selinux] pr775-checkpolicy-revdeps: fix the failing tests
Date: Fri, 11 Sep 2026 13:20:26 GMT [thread overview]
Message-ID: <178913282639.1.13073532131656857556.tests-selinux-e0866a22fe73@fedoraproject.org> (raw)
A new commit has been pushed.
Repo : tests/selinux
Branch : pr775-checkpolicy-revdeps
Commit : e0866a22fe73ff1c361b88d4bad6f2caa84b913b
Author : Milos Malik <mmalik@redhat.com>
Date : 2023-01-23T12:47:27+00:00
Stats : +34/-17 in 14 file(s)
URL : https://src.fedoraproject.org/tests/selinux/c/e0866a22fe73ff1c361b88d4bad6f2caa84b913b?branch=pr775-checkpolicy-revdeps
Log:
fix the failing tests
Not all packages required by the tests were installed. The issue
should be fixed now.
Relevancy of certain tests was set incorrectly. The issue should
be fixed now.
At least 1 test runs longer than its specified duration. The issue
should be fixed now.
---
diff --git a/policycoreutils/python-module-precedence-issue/main.fmf b/policycoreutils/python-module-precedence-issue/main.fmf
index 48568bc..2dc5935 100644
--- a/policycoreutils/python-module-precedence-issue/main.fmf
+++ b/policycoreutils/python-module-precedence-issue/main.fmf
@@ -1,7 +1,6 @@
summary: Harden tools to avoid loading of unchecked python modules.
description: Tools like semanage must be hardened to avoid loading rogue python modules that could lead to unexpected failures.
contact: Amith Kumar <apeetham@redhat.com>
-
component:
- policycoreutils
test: ./runtest.sh
@@ -27,3 +26,4 @@ adjust:
- enabled: false
when: distro == rhel-4, rhel-5, rhel-6
continue: false
+extra-nitrate: TC#0614726
diff --git a/policycoreutils/sepolicy-manpage/main.fmf b/policycoreutils/sepolicy-manpage/main.fmf
index 380ea44..a342f92 100644
--- a/policycoreutils/sepolicy-manpage/main.fmf
+++ b/policycoreutils/sepolicy-manpage/main.fmf
@@ -6,7 +6,7 @@ component:
framework: beakerlib
recommend:
- /usr/bin/sepolicy
-duration: 20m
+duration: 1h
enabled: true
tier: 3
link:
diff --git a/selinux-policy/Library/common/lib.sh b/selinux-policy/Library/common/lib.sh
old mode 100644
new mode 100755
diff --git a/selinux-policy/hostapd-and-similar/runtest.sh b/selinux-policy/hostapd-and-similar/runtest.sh
index c2323e0..9947d64 100755
--- a/selinux-policy/hostapd-and-similar/runtest.sh
+++ b/selinux-policy/hostapd-and-similar/runtest.sh
@@ -47,6 +47,7 @@ rlJournalStart
rlAssertRpm ${SERVICE_PACKAGE}
rlRun "rpm -qa kernel\*"
rlRun "uname -a"
+ rlRun "yum -y install kernel-modules-internal-`uname -r` --enablerepo '*'"
rlServiceStop ${SERVICE_NAME}
rlFileBackup /etc/shadow
rlFileBackup /etc/hostapd/hostapd.conf
@@ -111,7 +112,7 @@ rlJournalStart
PROCESS_CONTEXT="unconfined_service_t"
fi
rlSEService ${ROOT_PASSWORD} ${SERVICE_NAME} ${PROCESS_NAME} ${PROCESS_CONTEXT} "start status" 1
- rlRun "restorecon -Rv /run /var"
+ rlRun "restorecon -Rv /run /var -e /var/ARTIFACTS" 0-255
rlRun "hostapd_cli all_sta"
rlSEService ${ROOT_PASSWORD} ${SERVICE_NAME} ${PROCESS_NAME} ${PROCESS_CONTEXT} "restart status stop status" 1
rlPhaseEnd
diff --git a/selinux-policy/kernel-confined-exec/main.fmf b/selinux-policy/kernel-confined-exec/main.fmf
index 17584b2..33ab76f 100644
--- a/selinux-policy/kernel-confined-exec/main.fmf
+++ b/selinux-policy/kernel-confined-exec/main.fmf
@@ -1,9 +1,9 @@
summary: Test that kernel cannot execute arbitrary helper binaries
description: |
- Ensures that the kernel is not allowed to execute unauthorized binaries
- and that a transition to a confined domain is enforced on those that it
- can execute, so that overwriting usermode helper paths doesn't lead to
- an exploitable privilege escalation.
+ Ensures that the kernel is not allowed to execute unauthorized binaries
+ and that a transition to a confined domain is enforced on those that it
+ can execute, so that overwriting usermode helper paths doesn't lead to
+ an exploitable privilege escalation.
contact: Ondrej Mosnacek <omosnace@redhat.com>
component:
- selinux-policy
@@ -13,7 +13,7 @@ require:
- policycoreutils
- gcc
environment:
- AVC_ERROR: +no_avc_check
+ AVC_ERROR: +no_avc_check
duration: 20m
tier: 2
enabled: true
@@ -23,3 +23,4 @@ adjust:
because: This hardening applies only to F38+
link:
- verifies: https://bugzilla.redhat.com/show_bug.cgi?id=2068579
+extra-nitrate: TC#0614676
diff --git a/selinux-policy/ladvd/main.fmf b/selinux-policy/ladvd/main.fmf
index 7fae35a..ad60ea2 100644
--- a/selinux-policy/ladvd/main.fmf
+++ b/selinux-policy/ladvd/main.fmf
@@ -26,5 +26,10 @@ duration: 1h
link:
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=1834325
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=1855163
+adjust:
+ - enabled: false
+ when: distro == rhel-4, rhel-5, rhel-6, rhel-7, rhel-8, rhel-9
+ because: the ladvd package is not available there
extra-summary: /CoreOS/selinux-policy/Regression/ladvd
extra-task: /CoreOS/selinux-policy/Regression/ladvd
+extra-nitrate: TC#0614606
diff --git a/selinux-policy/nasd-and-similar/Makefile b/selinux-policy/nasd-and-similar/Makefile
index ed1c757..3d9f93c 100644
--- a/selinux-policy/nasd-and-similar/Makefile
+++ b/selinux-policy/nasd-and-similar/Makefile
@@ -55,14 +55,14 @@ $(METADATA): Makefile
@echo "TestTime: 10m" >> $(METADATA)
@echo "RunFor: nas" >> $(METADATA)
@echo "RunFor: selinux-policy" >> $(METADATA)
- @echo "Requires: audit libselinux libselinux-utils policycoreutils selinux-policy selinux-policy-targeted setools-console nas /usr/sbin/service" >> $(METADATA)
+ @echo "Requires: audit libselinux libselinux-utils policycoreutils selinux-policy selinux-policy-targeted setools-console nas /usr/sbin/service perl-Perl4-CoreLibs" >> $(METADATA)
@echo "RhtsRequires: library(selinux-policy/common)" >> $(METADATA)
@echo "Environment: AVC_ERROR=+no_avc_check" >> $(METADATA)
@echo "Priority: Normal" >> $(METADATA)
@echo "License: GPLv2" >> $(METADATA)
@echo "Confidential: no" >> $(METADATA)
@echo "Destructive: no" >> $(METADATA)
- @echo "Releases: -RHEL4 -RHEL5 -RHEL6 -RHEL7" >> $(METADATA)
+ @echo "Releases: -RHEL4 -RHEL5 -RHEL6 -RHEL7 -RHEL8" >> $(METADATA)
rhts-lint $(METADATA)
diff --git a/selinux-policy/nasd-and-similar/main.fmf b/selinux-policy/nasd-and-similar/main.fmf
index cd0bc98..859c0af 100644
--- a/selinux-policy/nasd-and-similar/main.fmf
+++ b/selinux-policy/nasd-and-similar/main.fmf
@@ -16,9 +16,15 @@ recommend:
- selinux-policy-targeted
- setools-console
- nas
+ - perl-Perl4-CoreLibs
- /usr/sbin/service
environment:
AVC_ERROR: +no_avc_check
duration: 10m
+adjust:
+ - enabled: false
+ when: distro == rhel-4, rhel-5, rhel-6, rhel-7, rhel-8
+ because: the nas package is not available there
extra-summary: /CoreOS/selinux-policy/Regression/nasd-and-similar
extra-task: /CoreOS/selinux-policy/Regression/nasd-and-similar
+extra-nitrate: TC#0614607
diff --git a/selinux-policy/nasd-and-similar/runtest.sh b/selinux-policy/nasd-and-similar/runtest.sh
index b6f8c17..0e0a784 100755
--- a/selinux-policy/nasd-and-similar/runtest.sh
+++ b/selinux-policy/nasd-and-similar/runtest.sh
@@ -89,7 +89,7 @@ rlJournalStart
rlRun "modprobe snd_pcm_oss"
rlSEService ${ROOT_PASSWORD} ${SERVICE_NAME} ${PROCESS_NAME} ${PROCESS_CONTEXT} "start status" 1
rlRun "ls -lZ /dev/dsp*"
- rlRun "restorecon -Rv /run /var" 0-255
+ rlRun "restorecon -Rv /run /var -e /var/ARTIFACTS" 0-255
rlSEService ${ROOT_PASSWORD} ${SERVICE_NAME} ${PROCESS_NAME} ${PROCESS_CONTEXT} "restart status stop status" 1
rlPhaseEnd
diff --git a/selinux-policy/rpmdb-and-similar/runtest.sh b/selinux-policy/rpmdb-and-similar/runtest.sh
index 5fa96e0..18919be 100755
--- a/selinux-policy/rpmdb-and-similar/runtest.sh
+++ b/selinux-policy/rpmdb-and-similar/runtest.sh
@@ -70,13 +70,12 @@ rlJournalStart
rlPhaseStartTest "real scenario -- standalone service"
rlRun "touch /var/lib/rpm/.rebuilddb"
rlSEService ${ROOT_PASSWORD} ${SERVICE_NAME} - ${PROCESS_CONTEXT} "start status" 1
- rlRun "restorecon -Rv /run /var"
+ rlRun "restorecon -Rv /run /var -e /var/ARTIFACTS" 0-255
rlRun "touch /var/lib/rpm/.rebuilddb"
rlSEService ${ROOT_PASSWORD} ${SERVICE_NAME} - ${PROCESS_CONTEXT} "restart status stop status" 1
rlPhaseEnd
rlPhaseStartTest "rpmdb executed by root/unconfined_t"
- rlRun "semodule -DB"
rlRun "restorecon -Rv /var/lib/rpm"
rlRun "ls -Z `which rpmdb`"
rlRun "rpmdb --help"
@@ -89,7 +88,6 @@ rlJournalStart
rlRun "ls -dZ /var/lib/rpm | grep :rpm_var_lib_t"
rlRun "ls -Z /var/lib/rpm"
rm -f ${OUTPUT_FILE}
- rlRun "semodule -B"
rlPhaseEnd
rlPhaseStartCleanup
diff --git a/selinux-policy/systemd-homed/main.fmf b/selinux-policy/systemd-homed/main.fmf
index d74f466..3af3331 100644
--- a/selinux-policy/systemd-homed/main.fmf
+++ b/selinux-policy/systemd-homed/main.fmf
@@ -20,5 +20,10 @@ environment:
duration: 1h
link:
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=1809878
+adjust:
+ - enabled: false
+ when: distro == rhel-4, rhel-5, rhel-6, rhel-7, rhel-8, rhel-9
+ because: the systemd-homed program is not available there
extra-summary: /CoreOS/selinux-policy/Regression/systemd-homed
extra-task: /CoreOS/selinux-policy/Regression/systemd-homed
+extra-nitrate: TC#0614608
diff --git a/selinux-policy/systemd-notify-and-similar/Makefile b/selinux-policy/systemd-notify-and-similar/Makefile
index d355f29..2e2d3d3 100644
--- a/selinux-policy/systemd-notify-and-similar/Makefile
+++ b/selinux-policy/systemd-notify-and-similar/Makefile
@@ -54,7 +54,7 @@ $(METADATA): Makefile
@echo "Type: Regression" >> $(METADATA)
@echo "TestTime: 10m" >> $(METADATA)
@echo "RunFor: selinux-policy" >> $(METADATA)
- @echo "Requires: audit libselinux libselinux-utils policycoreutils selinux-policy selinux-policy-targeted setools-console systemd /usr/sbin/service" >> $(METADATA)
+ @echo "Requires: audit expect libselinux libselinux-utils policycoreutils selinux-policy selinux-policy-targeted setools-console systemd /usr/sbin/service" >> $(METADATA)
@echo "RhtsRequires: library(selinux-policy/common)" >> $(METADATA)
@echo "Environment: AVC_ERROR=+no_avc_check" >> $(METADATA)
@echo "Priority: Normal" >> $(METADATA)
diff --git a/selinux-policy/systemd-notify-and-similar/main.fmf b/selinux-policy/systemd-notify-and-similar/main.fmf
index 7474823..c587e53 100644
--- a/selinux-policy/systemd-notify-and-similar/main.fmf
+++ b/selinux-policy/systemd-notify-and-similar/main.fmf
@@ -11,6 +11,7 @@ require:
- library(selinux-policy/common)
recommend:
- audit
+ - expect
- libselinux
- libselinux-utils
- policycoreutils
diff --git a/selinux-policy/systemd-notify-and-similar/runtest.sh b/selinux-policy/systemd-notify-and-similar/runtest.sh
index a9a445a..a0dde3d 100755
--- a/selinux-policy/systemd-notify-and-similar/runtest.sh
+++ b/selinux-policy/systemd-notify-and-similar/runtest.sh
@@ -54,7 +54,7 @@ rlJournalStart
rlPhaseEnd
rlPhaseStartTest "bz#1903305"
- if rlIsFedora ">36"; then
+ if rlIsFedora "<35"; then
rlSEMatchPathCon "/usr/bin/systemd-notify" "bin_t"
else # Fedora up to 36 and RHEL
rlSEMatchPathCon "/usr/bin/systemd-notify" "systemd_notify_exec_t"
@@ -77,7 +77,7 @@ rlJournalStart
# run the local-notifier service as a system service
rlRun "systemctl start local-notifier"
sleep 2
- rlRun "systemctl status local-notifier"
+ rlRun "systemctl status local-notifier" 3
# run the same service as a user service
rlRun "setsebool ssh_sysadm_login on"
CREATED_USERS=""
reply other threads:[~2026-09-11 13:20 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178913282639.1.13073532131656857556.tests-selinux-e0866a22fe73@fedoraproject.org \
--to=mmalik@redhat.com \
--cc=git-commits@fedoraproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox