grsecurity test: verify that the grsec device node is created

This commit is contained in:
Joachim Fasting 2016-07-17 21:38:11 +02:00
parent 96542a1b00
commit 8c8d6b4053
No known key found for this signature in database
GPG Key ID: 7544761007FE4E08

View File

@ -9,7 +9,6 @@ import ./make-test.nix ({ pkgs, ...} : {
machine = { config, pkgs, ... }:
{ security.grsecurity.enable = true;
boot.kernel.sysctl."kernel.grsecurity.deter_bruteforce" = 0;
security.apparmor.enable = true;
};
testScript = ''
@ -37,5 +36,9 @@ import ./make-test.nix ({ pkgs, ...} : {
$machine->execute("echo -e '#include <stdio.h>\nint main(void) { puts(\"hello\"); return 0; }' >main.c");
$machine->succeed("${pkgs.tinycc.bin}/bin/tcc -run main.c");
};
subtest "RBAC", sub {
$machine->succeed("[ -c /dev/grsec ]");
};
'';
})