2
0
mirror of https://gitlab.com/apparmor/apparmor synced 2025-08-23 10:37:27 +00:00
apparmor/Testing/severity_test.py

72 lines
2.8 KiB
Python
Raw Normal View History

import shutil
2013-06-21 20:08:32 +05:30
import sys
import unittest
sys.path.append('../')
2013-06-21 20:08:32 +05:30
2013-07-06 18:57:06 +05:30
import apparmor.severity as severity
from apparmor.common import AppArmorException
class Test(unittest.TestCase):
def setUp(self):
#copy the local profiles to the test directory
shutil.copytree('/etc/apparmor.d/', './profiles/')
def testRank_Test(self):
#z = severity.Severity()
2013-06-21 20:08:32 +05:30
s = severity.Severity('severity.db')
rank = s.rank('/usr/bin/whatis', 'x')
self.assertEqual(rank, 5, 'Wrong rank')
rank = s.rank('/etc', 'x')
self.assertEqual(rank, 10, 'Wrong rank')
rank = s.rank('/dev/doublehit', 'x')
self.assertEqual(rank, 0, 'Wrong rank')
rank = s.rank('/dev/doublehit', 'rx')
self.assertEqual(rank, 4, 'Wrong rank')
rank = s.rank('/dev/doublehit', 'rwx')
self.assertEqual(rank, 8, 'Wrong rank')
rank = s.rank('/dev/tty10', 'rwx')
self.assertEqual(rank, 9, 'Wrong rank')
rank = s.rank('/var/adm/foo/**', 'rx')
self.assertEqual(rank, 3, 'Wrong rank')
rank = s.rank('CAP_KILL')
self.assertEqual(rank, 8, 'Wrong rank')
rank = s.rank('CAP_SETPCAP')
self.assertEqual(rank, 9, 'Wrong rank')
self.assertEqual(s.rank('/etc/apparmor/**', 'r') , 6, 'Invalid Rank')
self.assertEqual(s.rank('/etc/**', 'r') , 10, 'Invalid Rank')
# Load all variables for /sbin/klogd and test them
s.load_variables('profiles/sbin.klogd')
self.assertEqual(s.rank('@{PROC}/sys/vm/overcommit_memory', 'r'), 6, 'Invalid Rank')
self.assertEqual(s.rank('@{HOME}/sys/@{PROC}/overcommit_memory', 'r'), 10, 'Invalid Rank')
self.assertEqual(s.rank('/overco@{multiarch}mmit_memory', 'r'), 10, 'Invalid Rank')
s.unload_variables()
s.load_variables('profiles/usr.sbin.dnsmasq')
self.assertEqual(s.rank('@{PROC}/sys/@{TFTP_DIR}/overcommit_memory', 'r'), 6, 'Invalid Rank')
self.assertEqual(s.rank('@{PROC}/sys/vm/overcommit_memory', 'r'), 6, 'Invalid Rank')
self.assertEqual(s.rank('@{HOME}/sys/@{PROC}/overcommit_memory', 'r'), 10, 'Invalid Rank')
self.assertEqual(s.rank('/overco@{multiarch}mmit_memory', 'r'), 10, 'Invalid Rank')
#self.assertEqual(s.rank('/proc/@{PID}/maps', 'rw'), 9, 'Invalid Rank')
2013-06-21 20:08:32 +05:30
def testInvalid(self):
s = severity.Severity('severity.db')
rank = s.rank('/dev/doublehit', 'i')
self.assertEqual(rank, 10, 'Wrong')
try:
broken = severity.Severity('severity_broken.db')
except AppArmorException:
pass
rank = s.rank('CAP_UNKOWN')
rank = s.rank('CAP_K*')
2013-06-21 20:08:32 +05:30
if __name__ == "__main__":
#import sys;sys.argv = ['', 'Test.testName']
unittest.main()