Changeset 2186

Show
Ignore:
Timestamp:
05/27/08 10:16:47 (6 months ago)
Author:
dsugar
Message:

Updates so the ipsec test cases now run in enforcing

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • trunk/test/test0119/expected.ipsec

    r2148 r2186  
     1add 172.16.133.129[3490] 172.16.133.131 esp 0x6789 -m transport -ctx 1 1 "system_u:system_r:server_t:s0-s0:c0.c1023"  -E 3des-cbc "012345678901234567890123" -A hmac-md5 "0123456789012345"; 
    12add 172.16.133.131 172.16.133.129[3490] esp 0x5678 -m transport -ctx 1 1 "system_u:system_r:client_t:s0-s0:c0.c1023"  -E 3des-cbc "012345678901234567890123" -A hmac-md5 "0123456789012345"; 
    23add 172.16.133.129[3490] 172.16.133.131 esp 0x6789 -m transport -ctx 1 1 "system_u:system_r:server_t:s0-s0:c0.c1023"  -E 3des-cbc "012345678901234567890123" -A hmac-md5 "0123456789012345"; 
     4add 172.16.133.131 172.16.133.129[3490] esp 0x5678 -m transport -ctx 1 1 "system_u:system_r:client_t:s0-s0:c0.c1023"  -E 3des-cbc "012345678901234567890123" -A hmac-md5 "0123456789012345"; 
  • trunk/test/test0119/expected.te

    r2148 r2186  
    77#Framework ability: tcp_server 
    88allow server_t self :tcp_socket { accept append bind create getopt listen name_bind node_bind read setopt write }; 
     9corenet_tcp_bind_all_ports(server_t) 
     10corenet_tcp_bind_generic_port(server_t) 
     11corenet_tcp_bind_inaddr_any_node(server_t) 
     12corenet_tcp_bind_generic_node(server_t) 
    913#End of Framework ability: tcp_server 
    1014optional_policy(` 
     
    2327SEFramework_entrypoint(server_exe_t) 
    2428SEFramework_files_type(server_exe_t) 
     29SEFramework_ipsec_endpoint(server_t) 
    2530# CDSFramework access (domain resource verb): server net1 readwrite 
    2631# remote types of data coming over the wire (Labeled Networking) 
    2732type client_t; 
    2833SEFramework_domain(client_t) 
     34SEFramework_ipsec_endpoint(client_t) 
    2935framework_ipsec_readwrite_connrw(server_t,self) 
    3036allow server_t client_t:association { recvfrom sendto }; 
     
    3844        allow server_t tmp_t:dir { search }; 
    3945# CDSFramework access (domain baseresource verb): server selinux read 
    40 seutil_read_config(server_t) 
    4146selinux_getattr_fs(server_t) 
    4247selinux_validate_context(server_t) 
     48seutil_read_config(server_t) 
     49# CDSFramework access (domain baseresource verb): server terminal readwrite 
     50term_use_all_user_ptys(server_t) 
     51term_use_all_terms(server_t) 
     52term_use_generic_ptys(server_t) 
    4353# CDSFramework enter (domain domain entrypoint): unconfined server server_exe 
    4454optional_policy(` 
  • trunk/test/test0119/tcp_server.flnk

    r2148 r2186  
    11ability tcp_server 
    2 [ desc:" " ] 
     2[ desc:"Domain that communicates over the network as a TCP Server" ] 
    33{ 
     4        corenet_tcp_bind_all_ports($) 
     5        corenet_tcp_bind_generic_port($) 
     6        corenet_tcp_bind_inaddr_any_node($) 
     7        corenet_tcp_bind_generic_node($) 
    48        self 
    59        { 
  • trunk/test/test0119/test.fpol

    r2148 r2186  
    44baseresource selinux from "selinux.flnk"; 
    55ability tcp_server from "tcp_server.flnk"; 
     6baseresource terminal from "terminal.flnk"; 
    67 
    78resource res1 { file }; 
     
    1314access server res1 write; 
    1415access server selinux read; 
     16access server terminal readwrite; 
    1517 
    1618entrypoint server_exe; 
  • trunk/test/test0121/expected.ipsec

    r2148 r2186  
     1add 172.16.133.129[3490] 172.16.133.131 esp 0x6789 -m transport -ctx 1 1 "system_u:system_r:server_t:s0-s0:c0.c1023"  -E 3des-cbc "012345678901234567890123" -A hmac-md5 "0123456789012345"; 
    12add 172.16.133.131 172.16.133.129[3490] esp 0x5678 -m transport -ctx 1 1 "system_u:system_r:client_t:s0-s0:c0.c1023"  -E 3des-cbc "012345678901234567890123" -A hmac-md5 "0123456789012345"; 
    23add 172.16.133.129[3490] 172.16.133.131 esp 0x6789 -m transport -ctx 1 1 "system_u:system_r:server_t:s0-s0:c0.c1023"  -E 3des-cbc "012345678901234567890123" -A hmac-md5 "0123456789012345"; 
     4add 172.16.133.131 172.16.133.129[3490] esp 0x5678 -m transport -ctx 1 1 "system_u:system_r:client_t:s0-s0:c0.c1023"  -E 3des-cbc "012345678901234567890123" -A hmac-md5 "0123456789012345"; 
  • trunk/test/test0121/expected.te

    r2148 r2186  
    77#Framework ability: tcp_client 
    88allow client_t self :tcp_socket { connect create getopt name_connect node_bind read setopt write }; 
     9corenet_tcp_connect_all_ports(client_t) 
    910#End of Framework ability: tcp_client 
    1011optional_policy(` 
     
    2324SEFramework_entrypoint(client_exe_t) 
    2425SEFramework_files_type(client_exe_t) 
     26SEFramework_ipsec_endpoint(client_t) 
    2527# CDSFramework access (domain resource verb): client net1 readwrite 
    2628# remote types of data coming over the wire (Labeled Networking) 
    2729type server_t; 
    2830SEFramework_domain(server_t) 
     31SEFramework_ipsec_endpoint(server_t) 
    2932framework_ipsec_readwrite_connrw(client_t,self) 
    3033allow client_t self:association { recvfrom sendto }; 
     
    3841        allow client_t tmp_t:dir { search }; 
    3942# CDSFramework access (domain baseresource verb): client selinux read 
    40 seutil_read_config(client_t) 
    4143selinux_getattr_fs(client_t) 
    4244selinux_validate_context(client_t) 
     45seutil_read_config(client_t) 
    4346# CDSFramework access (domain baseresource verb): client sysnetwork read 
    4447sysnet_read_config(client_t) 
     48# CDSFramework access (domain baseresource verb): client terminal readwrite 
     49term_use_all_user_ptys(client_t) 
     50term_use_all_terms(client_t) 
     51term_use_generic_ptys(client_t) 
    4552# CDSFramework enter (domain domain entrypoint): unconfined client client_exe 
    4653optional_policy(` 
  • trunk/test/test0121/tcp_client.flnk

    r2148 r2186  
    22[ desc:"Domain that communicates over the network as a TCP Client " ] 
    33{ 
     4        corenet_tcp_connect_all_ports($) 
    45        self 
    56        { 
  • trunk/test/test0121/test.fpol

    r2148 r2186  
    55baseresource sysnetwork from "sysnetwork.flnk"; 
    66ability tcp_client from "tcp_client.flnk"; 
     7baseresource terminal from "terminal.flnk"; 
    78 
    89resource res2 { file }; 
     
    1516access client selinux read ; 
    1617access client sysnetwork read; 
     18access client terminal readwrite; 
    1719 
    1820entrypoint client_exe;