diff --git a/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.err b/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.err new file mode 100644 index 000000000..e69de29bb diff --git a/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.in b/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.in new file mode 100644 index 000000000..a574fb0d0 --- /dev/null +++ b/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.in @@ -0,0 +1 @@ +[ 176.385388] audit: type=1400 audit(1666891380.570:78): apparmor="DENIED" operation="userns_create" class="namespace" profile="/usr/bin/userns_child_exec" pid=1785 comm="userns_child_ex" requested="userns_create" denied="userns_create" diff --git a/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.out b/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.out new file mode 100644 index 000000000..3f4343626 --- /dev/null +++ b/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.out @@ -0,0 +1,13 @@ +START +File: testcase_userns_01.in +Event type: AA_RECORD_DENIED +Audit ID: 1666891380.570:78 +Operation: userns_create +Mask: userns_create +Denied Mask: userns_create +Profile: /usr/bin/userns_child_exec +Command: userns_child_ex +PID: 1785 +Class: namespace +Epoch: 1666891380 +Audit subid: 78 diff --git a/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.profile b/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.profile new file mode 100644 index 000000000..6b774549c --- /dev/null +++ b/libraries/libapparmor/testsuite/test_multi/testcase_userns_01.profile @@ -0,0 +1,4 @@ +/usr/bin/userns_child_exec { + userns create, + +} diff --git a/utils/test/test-libapparmor-test_multi.py b/utils/test/test-libapparmor-test_multi.py index 1b6973ed7..b2772bac5 100644 --- a/utils/test/test-libapparmor-test_multi.py +++ b/utils/test/test-libapparmor-test_multi.py @@ -170,6 +170,8 @@ log_to_profile_skip = [ 'testcase_changehat_01', # interactive, asks to add a hat 'testcase_dbus_09', # multiline log not currently supported + + 'testcase_userns_01', # userns currently not supported ] # tests that cause an empty log