1
0
mirror of https://git.FreeBSD.org/src.git synced 2024-12-18 10:35:55 +00:00
Mirror of the FreeBSD src repository https://git.FreeBSD.org/src.git .
Go to file
Enji Cooper 8ac5aef8f3 Integrate capsicum-test into the FreeBSD test suite
This change takes capsicum-test from upstream and applies some local changes to make the
tests work on FreeBSD when executed via Kyua.

The local modifications are as follows:
1. Make `OpenatTest.WithFlag` pass with the new dot-dot lookup behavior in FreeBSD 12.x+.
2. capsicum-test references a set of helper binaries: `mini-me`, `mini-me.noexec`, and
   `mini-me.setuid`, as part of the execve/fexecve tests, via execve, fexecve, and open.
   It achieves this upstream by assuming `mini-me*` is in the current directory, however,
   in order for Kyua to execute `capsicum-test`, it needs to provide a full path to
   `mini-me*`. In order to achieve this, I made `capsicum-test` cache the executable's
   path from argv[0] in main(..) and use the cached value to compute the path to
   `mini-me*` as part of the execve/fexecve testcases.
3. The capsicum-test test suite assumes that it's always being run on CAPABILITIES enabled
   kernels. However, there's a chance that the test will be run on a host without a
   CAPABILITIES enabled kernel, so we must check for the support before running the tests.
   The way to achieve this is to add the relevant `feature_present("security_capabilities")`
   check to SetupEnvironment::SetUp() and skip the tests when the support is not available.
   While here, add a check for `kern.trap_enotcap` being enabled. As noted by markj@ in
   https://github.com/google/capsicum-test/issues/23, this sysctl being enabled can trigger
   non-deterministic failures. Therefore, the tests should be skipped if this sysctl is
   enabled.

All local changes have been submitted to the capsicum-test project
(https://github.com/google/capsicum-test) and are in various stages of review.
Please see the following pull requests for more details:
1. https://github.com/google/capsicum-test/pull/35
2. https://github.com/google/capsicum-test/pull/41
3. https://github.com/google/capsicum-test/pull/42

Reviewed by:	asomers
Discussed with:	emaste, markj
Approved by:	emaste (mentor)
MFC after:	2 months
Differential Revision: https://reviews.freebsd.org/D19758
2019-04-01 21:24:50 +00:00
bin .Xr trim(8) from dd(1). 2019-03-26 15:44:06 +00:00
cddl Ensure that we use a 64-bit value for the last mmap() argument. 2019-03-20 23:35:15 +00:00
contrib Integrate capsicum-test into the FreeBSD test suite 2019-04-01 21:24:50 +00:00
crypto Add workaround for a QoS-related bug in VMWare Workstation. 2019-03-27 15:17:29 +00:00
etc Compile and install most of the googletest examples 2019-03-11 19:50:44 +00:00
gnu Fix gdb/kgdb build under WITH_PIE 2019-04-01 19:19:51 +00:00
include Add verifying manifest loader for mac_veriexec 2019-02-26 06:17:23 +00:00
kerberos5
lib Import proof-of-concept for handling GTEST_SKIP() in Environment::SetUp 2019-04-01 18:07:48 +00:00
libexec random(4): Attempt to persist entropy promptly 2019-03-31 04:57:50 +00:00
release Bump the IMAGE_SIZE for arm64 SoC images to prevent failures due 2019-03-21 14:17:55 +00:00
rescue
sbin libbe: Fix zfs_is_mounted check w/ snapshots 2019-04-01 17:44:20 +00:00
secure Add workaround for a QoS-related bug in VMWare Workstation. 2019-03-27 15:17:29 +00:00
share Allow programs to set NO_SHARED on a per-PROG basis 2019-03-30 17:23:15 +00:00
stand stand: remove CLANG_NO_IAS from zfsldr 2019-03-26 20:32:05 +00:00
sys Devices behind downstream bridges should still get DMAR protection. 2019-04-01 19:08:05 +00:00
targets
tests Integrate capsicum-test into the FreeBSD test suite 2019-04-01 21:24:50 +00:00
tools revert r302146: makeroot: zero out subsecond component of time= keywords 2019-03-27 17:28:23 +00:00
usr.bin Standardize -std=c++* as CXXSTD` 2019-03-29 18:45:27 +00:00
usr.sbin Merge ACPICA 20190329. 2019-03-29 20:21:28 +00:00
.arcconfig
.arclint
.gitattributes
.gitignore
COPYRIGHT
LOCKS
MAINTAINERS Update maintainers for libunwind and lldb. 2019-03-16 13:26:42 +00:00
Makefile
Makefile.inc1 pkgbase: Use uname as ABI_FILE 2019-03-27 17:55:39 +00:00
Makefile.libcompat
Makefile.sys.inc
ObsoleteFiles.inc Set tentative merge date, and bump __FreeBSD_version. 2019-03-04 19:23:11 +00:00
README
README.md
UPDATING Add UPDATING note for geom_uzip(4)/xz, and bump geom_uzip(4) man page date. 2019-03-23 10:13:01 +00:00

FreeBSD Source:

This is the top level of the FreeBSD source directory. This file was last revised on: FreeBSD

FreeBSD is an operating system used to power modern servers, desktops, and embedded platforms. A large community has continually developed it for more than thirty years. Its advanced networking, security, and storage features have made FreeBSD the platform of choice for many of the busiest web sites and most pervasive embedded networking and storage devices.

For copyright information, please see the file COPYRIGHT in this directory. Additional copyright information also exists for some sources in this tree - please see the specific source directories for more information.

The Makefile in this directory supports a number of targets for building components (or all) of the FreeBSD source tree. See build(7), config(8), https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html, and https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/kernelconfig.html for more information, including setting make(1) variables.

Source Roadmap:

bin		System/user commands.

cddl		Various commands and libraries under the Common Development
		and Distribution License.

contrib		Packages contributed by 3rd parties.

crypto		Cryptography stuff (see crypto/README).

etc		Template files for /etc.

gnu		Various commands and libraries under the GNU Public License.
		Please see gnu/COPYING* for more information.

include		System include files.

kerberos5	Kerberos5 (Heimdal) package.

lib		System libraries.

libexec		System daemons.

release		Release building Makefile & associated tools.

rescue		Build system for statically linked /rescue utilities.

sbin		System commands.

secure		Cryptographic libraries and commands.

share		Shared resources.

stand		Boot loader sources.

sys		Kernel sources.

sys/<arch>/conf Kernel configuration files. GENERIC is the configuration
		used in release builds. NOTES contains documentation of
		all possible entries.

tests		Regression tests which can be run by Kyua.  See tests/README
		for additional information.

tools		Utilities for regression testing and miscellaneous tasks.

usr.bin		User commands.

usr.sbin	System administration commands.

For information on synchronizing your source tree with one or more of the FreeBSD Project's development branches, please see:

https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/current-stable.html