| |
@@ -0,0 +1,61 @@
|
| |
+ From 1ef277aa4840a72ff474f6500bcc6576f37af0af Mon Sep 17 00:00:00 2001
|
| |
+ From: Lukas Vrabec <lvrabec@redhat.com>
|
| |
+ Date: Tue, 27 Aug 2019 21:20:16 +0200
|
| |
+ Subject: [PATCH] Update tests test_basic.podman.cil, test_basic.docker.cil.
|
| |
+ Round 2
|
| |
+
|
| |
+ Because of the new versions of SELinux policy in Fedora 30 and Fedora
|
| |
+ Rawhide, also several tests in Udica needed to be fixed to use new
|
| |
+ labels.
|
| |
+ ---
|
| |
+ tests/semanage.py | 1 -
|
| |
+ tests/test_basic.docker.cil | 3 ---
|
| |
+ tests/test_basic.podman.cil | 5 +----
|
| |
+ 3 files changed, 1 insertion(+), 8 deletions(-)
|
| |
+
|
| |
+ diff --git a/tests/semanage.py b/tests/semanage.py
|
| |
+ index f64fda4..318a46a 100644
|
| |
+ --- a/tests/semanage.py
|
| |
+ +++ b/tests/semanage.py
|
| |
+ @@ -156,7 +156,6 @@ fcontexts_homedirs = [
|
| |
+ ('/var/spool/fcron/new\\.systab', 'system_u:object_r:system_cron_spool_t:s0'),
|
| |
+ ('/var/spool/fcron/systab\\.orig', 'system_u:object_r:system_cron_spool_t:s0'),
|
| |
+ ('/var/spool/postfix/etc/localtime', 'system_u:object_r:locale_t:s0'),
|
| |
+ - ('/var/spool/cron', 'system_u:object_r:user_cron_spool_t:s0'),
|
| |
+ ('/var/spool/cron/user', 'system_u:object_r:user_cron_spool_t:s0')
|
| |
+ ]
|
| |
+
|
| |
+ diff --git a/tests/test_basic.docker.cil b/tests/test_basic.docker.cil
|
| |
+ index b29cb32..220c53b 100644
|
| |
+ --- a/tests/test_basic.docker.cil
|
| |
+ +++ b/tests/test_basic.docker.cil
|
| |
+ @@ -285,9 +285,6 @@
|
| |
+ (allow process user_cron_spool_t ( dir ( open read getattr lock search ioctl add_name remove_name write )))
|
| |
+ (allow process user_cron_spool_t ( file ( getattr read write append ioctl lock map open create )))
|
| |
+ (allow process user_cron_spool_t ( sock_file ( getattr read write append open )))
|
| |
+ - (allow process user_cron_spool_t ( dir ( open read getattr lock search ioctl add_name remove_name write )))
|
| |
+ - (allow process user_cron_spool_t ( file ( getattr read write append ioctl lock map open create )))
|
| |
+ - (allow process user_cron_spool_t ( sock_file ( getattr read write append open )))
|
| |
+ (allow process var_spool_t ( dir ( open read getattr lock search ioctl add_name remove_name write )))
|
| |
+ (allow process var_spool_t ( file ( getattr read write append ioctl lock map open create )))
|
| |
+ (allow process var_spool_t ( sock_file ( getattr read write append open )))
|
| |
+ diff --git a/tests/test_basic.podman.cil b/tests/test_basic.podman.cil
|
| |
+ index 06b44e3..618fe07 100644
|
| |
+ --- a/tests/test_basic.podman.cil
|
| |
+ +++ b/tests/test_basic.podman.cil
|
| |
+ @@ -287,10 +287,7 @@
|
| |
+ (allow process user_cron_spool_t ( dir ( open read getattr lock search ioctl add_name remove_name write )))
|
| |
+ (allow process user_cron_spool_t ( file ( getattr read write append ioctl lock map open create )))
|
| |
+ (allow process user_cron_spool_t ( sock_file ( getattr read write append open )))
|
| |
+ - (allow process user_cron_spool_t ( dir ( open read getattr lock search ioctl add_name remove_name write )))
|
| |
+ - (allow process user_cron_spool_t ( file ( getattr read write append ioctl lock map open create )))
|
| |
+ - (allow process user_cron_spool_t ( sock_file ( getattr read write append open )))
|
| |
+ (allow process var_spool_t ( dir ( open read getattr lock search ioctl add_name remove_name write )))
|
| |
+ (allow process var_spool_t ( file ( getattr read write append ioctl lock map open create )))
|
| |
+ (allow process var_spool_t ( sock_file ( getattr read write append open )))
|
| |
+ -)
|
| |
+ \ No newline at end of file
|
| |
+ +)
|
| |
+ --
|
| |
+ 2.21.0
|
| |
+
|
| |
None