diff options
Diffstat (limited to 'tests/misc')
-rw-r--r-- | tests/misc/Makefile.am | 5 | ||||
-rwxr-xr-x | tests/misc/chcon | 73 | ||||
-rwxr-xr-x | tests/misc/chcon-fail | 41 | ||||
-rwxr-xr-x | tests/misc/mknod | 6 | ||||
-rwxr-xr-x | tests/misc/selinux | 62 |
5 files changed, 183 insertions, 4 deletions
diff --git a/tests/misc/Makefile.am b/tests/misc/Makefile.am index 4d6a754a8..e4a15cf9e 100644 --- a/tests/misc/Makefile.am +++ b/tests/misc/Makefile.am @@ -1,6 +1,6 @@ # Make miscellaneous coreutils tests. -*-Makefile-*- -# Copyright (C) 200-2007 Free Software Foundation, Inc. +# Copyright (C) 2001-2007 Free Software Foundation, Inc. # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by @@ -43,6 +43,9 @@ TESTS = \ pr \ df-P \ pwd-unreadable-parent \ + chcon \ + chcon-fail \ + selinux \ cut \ wc-files0-from \ wc-files0 \ diff --git a/tests/misc/chcon b/tests/misc/chcon new file mode 100755 index 000000000..88c009baf --- /dev/null +++ b/tests/misc/chcon @@ -0,0 +1,73 @@ +#!/bin/sh +# exercise chcon + +if test "$VERBOSE" = yes; then + set -x + chcon --version +fi + +. $srcdir/../lang-default +PRIV_CHECK_ARG=require-root . $srcdir/../priv-check + +pwd=`pwd` +t0=`echo "$0"|sed 's,.*/,,'`.tmp; tmp=$t0/$$ +trap 'status=$?; cd $pwd; chmod -R u+rwx $t0; rm -rf $t0 && exit $status' 0 +trap '(exit $?); exit $?' 1 2 13 15 + +framework_failure=0 +mkdir -p $tmp || framework_failure=1 +cd $tmp || framework_failure=1 +mkdir -p d/sub/s2 || framework_failure=1 +touch f g d/sub/1 d/sub/2 || framework_failure=1 + +if test $framework_failure = 1; then + echo "$0: failure in testing framework" 1>&2 + (exit 1); exit 1 +fi + +fail=0 + +# Set to a specified context. +u1=root +r1=object_r +t1=tmp_t +ctx=$u1:$r1:$t1 +chcon $ctx f || fail=1 +stat --printf='f|%C\n' f > out || fail=1 + +# Use --reference. +chcon --ref=f g || fail=1 +stat --printf='g|%C\n' g >> out || fail=1 + +# Change the individual parts of the context, one by one. +u2=user_u +r2=object_r +t2=file_t +l2=SystemLow-SystemHigh +for i in --user=$u2 --role=$r2 --type=$t2 --range=$l2; do + chcon $i f || fail=1 + stat --printf="f|$i|"'%C\n' f >> out || fail=1 +done + +# Same, but change back using the short-named options. +for i in -u$u1 -r$r1 -t$t1; do + chcon $i f || fail=1 + stat --printf="f|$i|"'%C\n' f >> out || fail=1 +done + +cat <<EOF > exp || fail=1 +f|$ctx +g|$ctx +f|--user=$u2|$u2:$r1:$t1 +f|--role=$r2|$u2:$r2:$t1 +f|--type=$t2|$u2:$r2:$t2 +f|--range=$l2|$u2:$r2:$t2:$l2 +f|-uroot|root:object_r:file_t:SystemLow-SystemHigh +f|-robject_r|root:object_r:file_t:SystemLow-SystemHigh +f|-ttmp_t|root:object_r:tmp_t:SystemLow-SystemHigh +EOF + +cmp out exp || fail=1 +test $fail = 1 && diff out exp 2> /dev/null + +(exit $fail); exit $fail diff --git a/tests/misc/chcon-fail b/tests/misc/chcon-fail new file mode 100755 index 000000000..d639e86b5 --- /dev/null +++ b/tests/misc/chcon-fail @@ -0,0 +1,41 @@ +#!/bin/sh +# Ensure that chcon fails when it should. +# These tests don't use any actual SE Linux syscalls. + +if test "$VERBOSE" = yes; then + set -x + chcon --version +fi + +. $srcdir/../lang-default + +pwd=`pwd` +t0=`echo "$0"|sed 's,.*/,,'`.tmp; tmp=$t0/$$ +trap 'status=$?; cd $pwd; chmod -R u+rwx $t0; rm -rf $t0 && exit $status' 0 +trap '(exit $?); exit $?' 1 2 13 15 + +framework_failure=0 +mkdir -p $tmp || framework_failure=1 +cd $tmp || framework_failure=1 + +if test $framework_failure = 1; then + echo "$0: failure in testing framework" 1>&2 + (exit 1); exit 1 +fi + +fail=0 + +# neither context nor file +chcon 2> /dev/null && fail=1 + +# No file +chcon CON 2> /dev/null && fail=1 + +# No file +touch f +chcon --reference=f 2> /dev/null && fail=1 + +# No file +chcon -u anyone 2> /dev/null && fail=1 + +(exit $fail); exit $fail diff --git a/tests/misc/mknod b/tests/misc/mknod index 12cb0a623..d7fb22eb0 100755 --- a/tests/misc/mknod +++ b/tests/misc/mknod @@ -42,15 +42,15 @@ fail=0 umask 777 mknod -m 734 f1 p || fail=1 -set _ `ls -dgo f1`; shift; mode=$1 +mode=`ls -dgo f1|cut -b-10` test $mode = prwx-wxr-- || fail=1 mkfifo -m 734 f2 || fail=1 -set _ `ls -dgo f2`; shift; mode=$1 +mode=`ls -dgo f2|cut -b-10` test $mode = prwx-wxr-- || fail=1 mkdir -m 734 f3 || fail=1 -set _ `ls -dgo f3`; shift; mode=$1 +mode=`ls -dgo f3|cut -b-10` test $mode = drwx-wxr-- || test $mode = drwx-wsr-- || fail=1 (exit $fail); exit $fail diff --git a/tests/misc/selinux b/tests/misc/selinux new file mode 100755 index 000000000..1207161fd --- /dev/null +++ b/tests/misc/selinux @@ -0,0 +1,62 @@ +#!/bin/sh +# Test SELinux-related options. + +if test "$VERBOSE" = yes; then + set -x + ls --version +fi + +. $srcdir/../envvar-check +. $srcdir/../lang-default +PRIV_CHECK_ARG=require-non-root . $srcdir/../priv-check + +test "`ls -Zd .`" = '? .' && + { + echo "$0: skipping this test; this system lacks SELinux support" 1>&2 + exit 77 + } + +pwd=`pwd` +t0=`echo "$0"|sed 's,.*/,,'`.tmp; tmp=$t0/$$ +trap 'status=$?; cd $pwd; chmod -R u+rwx $t0; rm -rf $t0 && exit $status' 0 +trap '(exit $?); exit $?' 1 2 13 15 + +framework_failure=0 +mkdir -p $tmp || framework_failure=1 +cd $tmp || framework_failure=1 + +# Create a regular file, dir, fifo. +touch f || framework_failure=1 +mkdir d s1 s2 || framework_failure=1 +mkfifo p || framework_failure=1 + +if test $framework_failure = 1; then + echo "$0: failure in testing framework" 1>&2 + (exit 1); exit 1 +fi + +fail=0 + +ctx=root:object_r:tmp_t +# FIXME, what if $ctx is no different from the default. Not likely. +# give each a different context, via chcon +chcon $ctx f d p || fail=1 +# inspect that context with both ls -Z and stat. +for i in d f p; do + c=`ls -dogZ $i|cut -d' ' -f3`; test x$c = x$ctx || fail=1 + c=`stat --printf %C $i`; test x$c = x$ctx || fail=1 +done + +# Copy each to a new directory and ensure that context is preserved. +cp -r --preserve=all d f p s1 || fail=1 +for i in d f p; do + c=`stat --printf %C s1/$i`; test x$c = x$ctx || fail=1 +done + +# Now, move each to a new directory and ensure that context is preserved. +mv d f p s2 || fail=1 +for i in d f p; do + c=`stat --printf %C s2/$i`; test x$c = x$ctx || fail=1 +done + +(exit $fail); exit $fail |