Project

General

Profile

Actions

action #174175

open

[security][tumbleweed] Add setroubleshootd tests

Added by tjyrinki_suse 15 days ago. Updated 8 days ago.

Status:
Blocked
Priority:
Normal
Assignee:
Category:
-
Target version:
-
Start date:
Due date:
% Done:

20%

Estimated time:
8.00 h
Difficulty:
Tags:

Description

Motivation

We need to be able to test setroubleshoot automatically so we could catch downgrades or issues in advance to bring better usability to the users.

What should be tested:

  • setroubleshootd
    • systemd service has no issue when called
    • daemon is dbus activated
    • policykit restrict direct usage only to setroubleshoot user

Acceptance Criteria

  1. Create a test that runs on SELinux enabled Tumbleweed system, with auditd
  2. Install the package setroubleshoot-server, check that it installs setroubleshoot-plugins automatically
  3. Check setroubleshootd DBus activation via systemd service. Check if is-active shows inactive at first, then after restart shows active at first but after about 15 seconds it should be no longer active again.
  4. Check setroubleshootd invoking via polkit as root, see /usr/share/dbus-1/system.d/org.fedoraproject.SetroubleshootFixit.conf

Further Information

Ask for details from for example Zdenek Kubala if something is unclear, or from this ticket's author.


Related issues 1 (1 open0 closed)

Related to openQA Tests (public) - action #174178: [security][tumbleweed] Add sealert tests to setroubleshootdNew

Actions
Actions #1

Updated by tjyrinki_suse 15 days ago

  • Related to action #174178: [security][tumbleweed] Add sealert tests to setroubleshootd added
Actions #2

Updated by amanzini 10 days ago

  • Assignee set to amanzini
Actions #4

Updated by amanzini 9 days ago

  • % Done changed from 0 to 10
Actions #5

Updated by amanzini 9 days ago

  • Status changed from Workable to In Progress
Actions #6

Updated by amanzini 9 days ago ยท Edited

tests are in a good shape: https://openqa.opensuse.org/tests/4709307#step/setroubleshootd/11

waiting for clarification about the ac4 (asked on slack) and left a comment on confluence page

Actions #7

Updated by amanzini 8 days ago

  • Status changed from In Progress to Blocked
  • % Done changed from 10 to 20
Actions

Also available in: Atom PDF