[PATCH v11 10/12] selftests/landlock: Add 11 new test suites dedicated to network

Günther Noack gnoack3000 at gmail.com
Sat Jul 1 19:07:12 UTC 2023


Hi!

On Tue, May 16, 2023 at 12:13:37AM +0800, Konstantin Meskhidze wrote:
> +TEST_F(inet, bind)

If you are using TEST_F() and you are enforcing a Landlock ruleset
within that test, doesn't that mean that the same Landlock ruleset is
now also enabled on other tests that get run after that test?

Most of the other Landlock selftests use TEST_F_FORK() for that
reason, so that the Landlock enforcement stays local to the specific
test, and does not accidentally influence the observed behaviour in
other tests.

The same question applies to other test functions in this file as
well.

–Günther



More information about the Linux-security-module-archive mailing list