bottlerocket-os / bottlerocket-os/bottlerocket-test-system

bottlerocket avc denial absence test

Open
#432 1 comment 0 reactions 0 assignees View on GitHub
bottlerocket workload tests
Dominant language
Rust
Stars
18
Forks
27
PR merge metrics
No merged PRs in 30d

Description

When running a normal container workload we want to check and make sure no selinux avc denials occur. This probably needs to be modeled as a workload test, and it cannot happen on the same node as a test that is checking that avc denials *do* occur (#433).

depends on:
- #419
- #429

Contributor guide

Open the contributing guide

Research direction

Start by reviewing how workload tests are modeled and the dependency issues #419 and #429. Compare the intended absence check with the denial-producing test in #433, ensuring the two tests do not share a node. Done means a normal container workload verifies that no SELinux AVC denials occur.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
operating-systems, testing-qa
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.