bottlerocket-os / bottlerocket-os/bottlerocket-test-system
bottlerocket avc denial absence test
Open
bottlerocket
workload tests
- Dominant language
- Rust
- Stars
- 18
- Forks
- 27
- PR merge metrics
- No merged PRs in 30d
Description
When running a normal container workload we want to check and make sure no selinux avc denials occur. This probably needs to be modeled as a workload test, and it cannot happen on the same node as a test that is checking that avc denials *do* occur (#433).
depends on:
- #419
- #429
Contributor guide
Research direction
Start by reviewing how workload tests are modeled and the dependency issues #419 and #429. Compare the intended absence check with the denial-producing test in #433, ensuring the two tests do not share a node. Done means a normal container workload verifies that no SELinux AVC denials occur.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- operating-systems, testing-qa
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100