bottlerocket-os / bottlerocket-os/bottlerocket-test-system
bottlerocket avc denial test
Open
bottlerocket
workload tests
- Dominant language
- Rust
- Stars
- 18
- Forks
- 27
- PR merge metrics
- No merged PRs in 30d
Description
We want to try nefarious things in an unpriviledged container an make sure selinux blocks them. This cannot happen at the same time as #432
depends on:
- #419
- #429
Contributor guide
Research direction
Review dependencies #419 and #429 first, and account for the issue's incompatibility with #432. The task is to add a test that attempts unsafe actions from an unprivileged container and verifies SELinux denies them; the specific actions and test location are not identified here.
Written by the indexing model from the issue text.
Assessment
- Domain
- operating-systems, security, testing-qa
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100