Skip to content

Conversation

vmojzis
Copy link

@vmojzis vmojzis commented Jul 16, 2025

Replicate two tests, but all access (including assignment to attributes
like domain) is assigned via proxy attributes -- attributes are used in
place of the original types and types used in the tests are assigned to
the proxy attributes (no access is assigned directly to the types).

The following checkpolicy patch is needed to compile the test policy:
https://lore.kernel.org/selinux/[email protected]/

Checkpolicy builds with the patch applied are available in:
https://copr.fedorainfracloud.org/coprs/vmojzis/userspace_test/

TODO: the test needs to be made conditional on userspace version

@vmojzis vmojzis force-pushed the attribute branch 4 times, most recently from 2c9bb82 to 643269d Compare July 16, 2025 11:43
vmojzis added 2 commits July 16, 2025 14:14
Replicate two tests, but all access (including assignment to attributes
like domain) is assigned via proxy attributes -- attributes are used in
place of the original types and types used in the tests are assigned to
the proxy attributes (no access is assigned directly to the types).

The following checkpolicy patch is needed to compile the test policy:
https://lore.kernel.org/selinux/[email protected]/

Checkpolicy builds with the patch applied are available in:
https://copr.fedorainfracloud.org/coprs/vmojzis/userspace_test/

TODO: the test needs to be made conditional on userspace version

Signed-off-by: Vit Mojzis <[email protected]>
@vmojzis
Copy link
Author

vmojzis commented Jul 16, 2025

@vmojzis vmojzis changed the title [DO NOT MERGE, TEST ONLY] Add test for attribute assignment to attributes [DO NOT MERGE] Add test for attribute assignment to attributes Aug 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant