From: Linda K. <lin...@hp...> - 2011-04-25 22:22:33
|
The RHEL6 strict/mls policy enforces types on more ports than RHEL5, including ports in the 5000-5100 range, which were used by the networking tests. Move these to the 4000 range. Signed-off-by: Linda Knippers <lin...@hp...> --- audit/network/run.conf | 353 ++++++++++++------------ audit/utils/network-server/lblnet_tst-tcp | 8 +- audit/utils/network-server/lblnet_tst_server.c | 2 +- 3 files changed, 183 insertions(+), 180 deletions(-) diff --git a/audit/network/run.conf b/audit/network/run.conf index ebb3e76..3ae4975 100644 --- a/audit/network/run.conf +++ b/audit/network/run.conf @@ -23,6 +23,9 @@ tstsvr_lock_timeout_lspp=3000 # in seconds (50m) tstsvr_lock_timeout_capp=120 # in seconds (2m) tstsvr_lock_timeout=0 tstsvr_lock_held=0 +tst_port1=4100 # port for unlabeled traffic +tst_port2=4200 # port for netlabel traffic +tst_port3=4300 # port for labeled ipsec traffic cmd_nc="" # netcat command line @@ -310,7 +313,7 @@ function tstsvr_lock { declare rc declare str="lock:set,$tstsvr_lock_timeout;" - rc="$($cmd_nc $lblnet_svr6_host 5000 <<< $str)" + rc="$($cmd_nc $lblnet_svr6_host 4000 <<< $str)" if [[ $rc == 0 ]]; then tstsvr_lock_held=1 return 0 @@ -341,7 +344,7 @@ function tstsvr_unlock { declare str="lock:release;" if [[ $tstsvr_lock_held == 1 ]]; then - nc -w 1 $lblnet_svr6_host 5000 <<< $str + nc -w 1 $lblnet_svr6_host 4000 <<< $str fi } @@ -473,11 +476,11 @@ function setup_default { for ((loop_cnt=0; loop_cnt<=2 && rc!=0; loop_cnt++)); do case $host in remote) - rc="$($cmd_nc $lblnet_svr6_host 5000 <<< $str)" + rc="$($cmd_nc $lblnet_svr6_host 4000 <<< $str)" ;; local) # use the same port as the remote IPv4 setting - rc="$($cmd_nc ::1 5000 <<< $str)" + rc="$($cmd_nc ::1 4000 <<< $str)" ;; *) exit_fail "invalid test argument" @@ -1047,161 +1050,161 @@ done ## TESTCASE: local unlabeled IPv4, sanity check + accept \ mlsop=eq expres=success \ - host=local type=unlabeled op=sendrand_tcp ipv=ipv4 port=5100 \ + host=local type=unlabeled op=sendrand_tcp ipv=ipv4 port=$tst_port1 \ '$ipv $port' ## TESTCASE: local unlabeled IPv6, sanity check + accept \ mlsop=eq expres=success \ - host=local type=unlabeled op=sendrand_tcp ipv=ipv6 port=5100 \ + host=local type=unlabeled op=sendrand_tcp ipv=ipv6 port=$tst_port1 \ '$ipv $port' ## TESTCASE: remote unlabeled IPv4, sanity check + accept \ mlsop=eq expres=success \ - host=remote type=unlabeled op=sendrand_tcp ipv=ipv4 port=5100 \ + host=remote type=unlabeled op=sendrand_tcp ipv=ipv4 port=$tst_port1 \ '$ipv $port' ## TESTCASE: remote unlabeled IPv6, sanity check + accept \ mlsop=eq expres=success \ - host=remote type=unlabeled op=sendrand_tcp ipv=ipv6 port=5100 \ + host=remote type=unlabeled op=sendrand_tcp ipv=ipv6 port=$tst_port1 \ '$ipv $port' if [[ $PPROFILE == lspp ]]; then ## TESTCASE: local NetLabel IPv4, mac success (eq) + accept \ mlsop=eq expres=success \ - host=local type=netlabel op=sendrand_tcp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_tcp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (incomp) + accept \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=netlabel op=sendrand_tcp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_tcp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (dom) + accept \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=netlabel op=sendrand_tcp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_tcp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (domby) + accept \ mlsop=domby expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=netlabel op=sendrand_tcp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_tcp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac success (eq) + accept \ mlsop=eq expres=success \ - host=remote type=netlabel op=sendrand_tcp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_tcp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (incomp) + accept \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=netlabel op=sendrand_tcp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_tcp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (dom) + accept \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=netlabel op=sendrand_tcp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_tcp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (domby) + accept \ mlsop=domby expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=netlabel op=sendrand_tcp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_tcp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac success (eq) + accept \ mlsop=eq expres=success \ - host=local type=ipsec op=sendrand_tcp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_tcp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (incomp) + accept \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_tcp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_tcp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (dom) + accept \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_tcp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_tcp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (domby) + accept \ mlsop=domby expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_tcp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_tcp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac success (eq) + accept \ mlsop=eq expres=success \ - host=remote type=ipsec op=sendrand_tcp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_tcp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (incomp) + accept \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_tcp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_tcp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (dom) + accept \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_tcp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_tcp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (domby) + accept \ mlsop=domby expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_tcp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_tcp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac success (eq) + accept \ mlsop=eq expres=success \ - host=local type=ipsec op=sendrand_tcp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_tcp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (incomp) + accept \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_tcp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_tcp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (dom) + accept \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_tcp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_tcp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (domby) + accept \ mlsop=domby expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_tcp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_tcp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac success (eq) + accept \ mlsop=eq expres=success \ - host=remote type=ipsec op=sendrand_tcp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_tcp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (incomp) + accept \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_tcp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_tcp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (dom) + accept \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_tcp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_tcp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (domby) + accept \ mlsop=domby expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_tcp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_tcp ipv=ipv6 port=$tst_port3 \ '$ipv $port' fi @@ -1225,143 +1228,143 @@ fi ## TESTCASE: local unlabeled IPv4, sanity check + connect \ mlsop=eq expres=success \ - host=local type=unlabeled op=recv_tcp ipv=ipv4 port=5100 \ + host=local type=unlabeled op=recv_tcp ipv=ipv4 port=$tst_port1 \ '$host_remote tcp $port' ## TESTCASE: local unlabeled IPv6, sanity check + connect \ mlsop=eq expres=success \ - host=local type=unlabeled op=recv_tcp ipv=ipv6 port=5100 \ + host=local type=unlabeled op=recv_tcp ipv=ipv6 port=$tst_port1 \ '$host_remote tcp $port' ## TESTCASE: remote unlabeled IPv4, sanity check + connect \ mlsop=eq expres=success \ - host=remote type=unlabeled op=recv_tcp ipv=ipv4 port=5100 \ + host=remote type=unlabeled op=recv_tcp ipv=ipv4 port=$tst_port1 \ '$host_remote tcp $port' ## TESTCASE: remote unlabeled IPv6, sanity check + connect \ mlsop=eq expres=success \ - host=remote type=unlabeled op=recv_tcp ipv=ipv6 port=5100 \ + host=remote type=unlabeled op=recv_tcp ipv=ipv6 port=$tst_port1 \ '$host_remote tcp $port' if [[ $PPROFILE == lspp ]]; then ## TESTCASE: local NetLabel IPv4, mac success (eq) + connect \ mlsop=eq expres=success \ - host=local type=netlabel op=recv_tcp ipv=ipv4 port=5200 \ + host=local type=netlabel op=recv_tcp ipv=ipv4 port=$tst_port2 \ '$host_remote tcp $port' ## TESTCASE: local NetLabel IPv4, mac failure (incomp) + connect \ mlsop=incomp expres=fail err=EHOSTUNREACH \ - host=local type=netlabel op=recv_tcp ipv=ipv4 port=5200 \ + host=local type=netlabel op=recv_tcp ipv=ipv4 port=$tst_port2 \ '$host_remote tcp $port' ## TESTCASE: local NetLabel IPv4, mac failure (dom) + connect \ mlsop=dom expres=fail err=EHOSTUNREACH \ - host=local type=netlabel op=recv_tcp ipv=ipv4 port=5200 \ + host=local type=netlabel op=recv_tcp ipv=ipv4 port=$tst_port2 \ '$host_remote tcp $port' ## TESTCASE: local NetLabel IPv4, mac failure (domby) + connect \ mlsop=domby expres=fail err=EHOSTUNREACH \ - host=local type=netlabel op=recv_tcp ipv=ipv4 port=5200 \ + host=local type=netlabel op=recv_tcp ipv=ipv4 port=$tst_port2 \ '$host_remote tcp $port' ## TESTCASE: remote NetLabel IPv4, mac success (eq) + connect \ mlsop=eq expres=success \ - host=remote type=netlabel op=recv_tcp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=recv_tcp ipv=ipv4 port=$tst_port2 \ '$host_remote tcp $port' ## TESTCASE: remote NetLabel IPv4, mac failure (incomp) + connect \ mlsop=incomp expres=fail err=EHOSTUNREACH \ - host=remote type=netlabel op=recv_tcp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=recv_tcp ipv=ipv4 port=$tst_port2 \ '$host_remote tcp $port' ## TESTCASE: remote NetLabel IPv4, mac failure (dom) + connect \ mlsop=dom expres=fail err=EHOSTUNREACH \ - host=remote type=netlabel op=recv_tcp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=recv_tcp ipv=ipv4 port=$tst_port2 \ '$host_remote tcp $port' ## TESTCASE: remote NetLabel IPv4, mac failure (domby) + connect \ mlsop=domby expres=fail err=EHOSTUNREACH \ - host=remote type=netlabel op=recv_tcp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=recv_tcp ipv=ipv4 port=$tst_port2 \ '$host_remote tcp $port' ## TESTCASE: local IPsec IPv4, mac success (eq) + connect \ mlsop=eq expres=success \ - host=local type=ipsec op=recv_tcp ipv=ipv4 port=5300 \ + host=local type=ipsec op=recv_tcp ipv=ipv4 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: local IPsec IPv4, mac failure (incomp) + connect \ mlsop=incomp expres=fail err=ECONNREFUSED \ - host=local type=ipsec op=recv_tcp ipv=ipv4 port=5300 \ + host=local type=ipsec op=recv_tcp ipv=ipv4 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: local IPsec IPv4, mac failure (dom) + connect \ mlsop=dom expres=fail err=ECONNREFUSED \ - host=local type=ipsec op=recv_tcp ipv=ipv4 port=5300 \ + host=local type=ipsec op=recv_tcp ipv=ipv4 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: local IPsec IPv4, mac failure (domby) + connect \ mlsop=domby expres=fail err=ECONNREFUSED \ - host=local type=ipsec op=recv_tcp ipv=ipv4 port=5300 \ + host=local type=ipsec op=recv_tcp ipv=ipv4 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: remote IPsec IPv4, mac success (eq) + connect \ mlsop=eq expres=success \ - host=remote type=ipsec op=recv_tcp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=recv_tcp ipv=ipv4 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: remote IPsec IPv4, mac failure (incomp) + connect \ mlsop=incomp expres=fail err=ECONNREFUSED \ - host=remote type=ipsec op=recv_tcp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=recv_tcp ipv=ipv4 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: remote IPsec IPv4, mac failure (dom) + connect \ mlsop=dom expres=fail err=ECONNREFUSED \ - host=remote type=ipsec op=recv_tcp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=recv_tcp ipv=ipv4 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: remote IPsec IPv4, mac failure (domby) + connect \ mlsop=domby expres=fail err=ECONNREFUSED \ - host=remote type=ipsec op=recv_tcp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=recv_tcp ipv=ipv4 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: local IPsec IPv6, mac success (eq) + connect \ mlsop=eq expres=success \ - host=local type=ipsec op=recv_tcp ipv=ipv6 port=5300 \ + host=local type=ipsec op=recv_tcp ipv=ipv6 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: local IPsec IPv6, mac failure (incomp) + connect \ mlsop=incomp expres=fail err=ECONNREFUSED \ - host=local type=ipsec op=recv_tcp ipv=ipv6 port=5300 \ + host=local type=ipsec op=recv_tcp ipv=ipv6 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: local IPsec IPv6, mac failure (dom) + connect \ mlsop=dom expres=fail err=ECONNREFUSED \ - host=local type=ipsec op=recv_tcp ipv=ipv6 port=5300 \ + host=local type=ipsec op=recv_tcp ipv=ipv6 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: local IPsec IPv6, mac failure (domby) + connect \ mlsop=domby expres=fail err=ECONNREFUSED \ - host=local type=ipsec op=recv_tcp ipv=ipv6 port=5300 \ + host=local type=ipsec op=recv_tcp ipv=ipv6 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: remote IPsec IPv6, mac success (eq) + connect \ mlsop=eq expres=success \ - host=remote type=ipsec op=recv_tcp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=recv_tcp ipv=ipv6 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: remote IPsec IPv6, mac failure (incomp) + connect \ mlsop=incomp expres=fail err=ECONNREFUSED \ - host=remote type=ipsec op=recv_tcp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=recv_tcp ipv=ipv6 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: remote IPsec IPv6, mac failure (dom) + connect \ mlsop=dom expres=fail err=ECONNREFUSED \ - host=remote type=ipsec op=recv_tcp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=recv_tcp ipv=ipv6 port=$tst_port3 \ '$host_remote tcp $port' ## TESTCASE: remote IPsec IPv6, mac failure (domby) + connect \ mlsop=domby expres=fail err=ECONNREFUSED \ - host=remote type=ipsec op=recv_tcp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=recv_tcp ipv=ipv6 port=$tst_port3 \ '$host_remote tcp $port' fi @@ -1387,157 +1390,157 @@ fi ## TESTCASE: local unlabeled IPv4, sanity check + recvfrom \ mlsop=eq expres=success \ - host=local type=unlabeled op=sendrand_udp ipv=ipv4 port=5100 \ + host=local type=unlabeled op=sendrand_udp ipv=ipv4 port=$tst_port1 \ '$ipv $port' ## TESTCASE: local unlabeled IPv6, sanity check + recvfrom \ mlsop=eq expres=success \ - host=local type=unlabeled op=sendrand_udp ipv=ipv6 port=5100 \ + host=local type=unlabeled op=sendrand_udp ipv=ipv6 port=$tst_port1 \ '$ipv $port' ## TESTCASE: remote unlabeled IPv4, sanity check + recvfrom \ mlsop=eq expres=success \ - host=remote type=unlabeled op=sendrand_udp ipv=ipv4 port=5100 \ + host=remote type=unlabeled op=sendrand_udp ipv=ipv4 port=$tst_port1 \ '$ipv $port' ## TESTCASE: remote unlabeled IPv6, sanity check + recvfrom \ mlsop=eq expres=success \ - host=remote type=unlabeled op=sendrand_udp ipv=ipv6 port=5100 \ + host=remote type=unlabeled op=sendrand_udp ipv=ipv6 port=$tst_port1 \ '$ipv $port' if [[ $PPROFILE == lspp ]]; then ## TESTCASE: local NetLabel IPv4, mac success (eq) + recvfrom \ mlsop=eq expres=success \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (incomp) + recvfrom \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (dom) + recvfrom \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (domby) + recvfrom \ mlsop=domby expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac success (eq) + recvfrom \ mlsop=eq expres=success \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (incomp) + recvfrom \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (dom) + recvfrom \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (domby) + recvfrom \ mlsop=domby expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac success (eq) + recvfrom \ mlsop=eq expres=success \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (incomp) + recvfrom \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (dom) + recvfrom \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (domby) + recvfrom \ mlsop=domby expres=fail err=EINTR \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac success (eq) + recvfrom \ mlsop=eq expres=success \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (incomp) + recvfrom \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (dom) + recvfrom \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (domby) + recvfrom \ mlsop=domby expres=fail err=EINTR \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac success (eq) + recvfrom \ mlsop=eq expres=success \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (incomp) + recvfrom \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (dom) + recvfrom \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (domby) + recvfrom \ mlsop=domby expres=fail err=EINTR \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac success (eq) + recvfrom \ mlsop=eq expres=success \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (incomp) + recvfrom \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (dom) + recvfrom \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (domby) + recvfrom \ mlsop=domby expres=fail err=EINTR \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' fi @@ -1563,157 +1566,157 @@ fi ## TESTCASE: local unlabeled IPv4, sanity check + recvmsg \ mlsop=eq expres=success \ - host=local type=unlabeled op=sendrand_udp ipv=ipv4 port=5100 \ + host=local type=unlabeled op=sendrand_udp ipv=ipv4 port=$tst_port1 \ '$ipv $port' ## TESTCASE: local unlabeled IPv6, sanity check + recvmsg \ mlsop=eq expres=success \ - host=local type=unlabeled op=sendrand_udp ipv=ipv6 port=5100 \ + host=local type=unlabeled op=sendrand_udp ipv=ipv6 port=$tst_port1 \ '$ipv $port' ## TESTCASE: remote unlabeled IPv4, sanity check + recvmsg \ mlsop=eq expres=success \ - host=remote type=unlabeled op=sendrand_udp ipv=ipv4 port=5100 \ + host=remote type=unlabeled op=sendrand_udp ipv=ipv4 port=$tst_port1 \ '$ipv $port' ## TESTCASE: remote unlabeled IPv6, sanity check + recvmsg \ mlsop=eq expres=success \ - host=remote type=unlabeled op=sendrand_udp ipv=ipv6 port=5100 \ + host=remote type=unlabeled op=sendrand_udp ipv=ipv6 port=$tst_port1 \ '$ipv $port' if [[ $PPROFILE == lspp ]]; then ## TESTCASE: local NetLabel IPv4, mac success (eq) + recvmsg \ mlsop=eq expres=success \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (incomp) + recvmsg \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (dom) + recvmsg \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (domby) + recvmsg \ mlsop=domby expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac success (eq) + recvmsg \ mlsop=eq expres=success \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (incomp) + recvmsg \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (dom) + recvmsg \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (domby) + recvmsg \ mlsop=domby expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac success (eq) + recvmsg \ mlsop=eq expres=success \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (incomp) + recvmsg \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (dom) + recvmsg \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (domby) + recvmsg \ mlsop=domby expres=fail err=EINTR \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac success (eq) + recvmsg \ mlsop=eq expres=success \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (incomp) + recvmsg \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (dom) + recvmsg \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (domby) + recvmsg \ mlsop=domby expres=fail err=EINTR \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac success (eq) + recvmsg \ mlsop=eq expres=success \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (incomp) + recvmsg \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (dom) + recvmsg \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (domby) + recvmsg \ mlsop=domby expres=fail err=EINTR \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac success (eq) + recvmsg \ mlsop=eq expres=success \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (incomp) + recvmsg \ mlsop=incomp expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (dom) + recvmsg \ mlsop=dom expres=fail err=EINTR \ augrokfunc=augrok_default_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (domby) + recvmsg \ mlsop=domby expres=fail err=EINTR \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' fi @@ -1737,38 +1740,38 @@ fi ## TESTCASE: local unlabeled IPv4, sanity check + sendmsg \ mlsop=eq expres=success \ - host=local type=unlabeled op=recv_udp ipv=ipv4 port=5100 \ + host=local type=unlabeled op=recv_udp ipv=ipv4 port=$tst_port1 \ '$host_remote $port' ## TESTCASE: local unlabeled IPv6, sanity check + sendmsg \ mlsop=eq expres=success \ - host=local type=unlabeled op=recv_udp ipv=ipv6 port=5100 \ + host=local type=unlabeled op=recv_udp ipv=ipv6 port=$tst_port1 \ '$host_remote $port' ## TESTCASE: remote unlabeled IPv4, sanity check + sendmsg \ mlsop=eq expres=success \ - host=remote type=unlabeled op=recv_udp ipv=ipv4 port=5100 \ + host=remote type=unlabeled op=recv_udp ipv=ipv4 port=$tst_port1 \ '$host_remote $port' ## TESTCASE: remote unlabeled IPv6, sanity check + sendmsg \ mlsop=eq expres=success \ - host=remote type=unlabeled op=recv_udp ipv=ipv6 port=5100 \ + host=remote type=unlabeled op=recv_udp ipv=ipv6 port=$tst_port1 \ '$host_remote $port' if [[ $PPROFILE == lspp ]]; then ## TESTCASE: local IPsec IPv4, mac success (eq) + sendmsg \ mlsop=eq expres=success \ - host=local type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv4, mac failure (incomp) + sendmsg \ mlsop=incomp expres=fail err=EPERM \ - host=local type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv4, mac failure (dom) + sendmsg \ mlsop=dom expres=fail err=EPERM \ - host=local type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv4, mac failure (domby) + sendmsg \ @@ -1778,17 +1781,17 @@ if [[ $PPROFILE == lspp ]]; then ## TESTCASE: remote IPsec IPv4, mac success (eq) + sendmsg \ mlsop=eq expres=success \ - host=remote type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv4, mac failure (incomp) + sendmsg \ mlsop=incomp expres=fail err=EPERM \ - host=remote type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv4, mac failure (dom) + sendmsg \ mlsop=dom expres=fail err=EPERM \ - host=remote type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv4, mac failure (domby) + sendmsg \ @@ -1798,17 +1801,17 @@ if [[ $PPROFILE == lspp ]]; then ## TESTCASE: local IPsec IPv6, mac success (eq) + sendmsg \ mlsop=eq expres=success \ - host=local type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv6, mac failure (incomp) + sendmsg \ mlsop=incomp expres=fail err=EPERM \ - host=local type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv6, mac failure (dom) + sendmsg \ mlsop=dom expres=fail err=EPERM \ - host=local type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv6, mac failure (domby) + sendmsg \ @@ -1818,17 +1821,17 @@ if [[ $PPROFILE == lspp ]]; then ## TESTCASE: remote IPsec IPv6, mac success (eq) + sendmsg \ mlsop=eq expres=success \ - host=remote type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv6, mac failure (incomp) + sendmsg \ mlsop=incomp expres=fail err=EPERM \ - host=remote type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv6, mac failure (dom) + sendmsg \ mlsop=dom expres=fail err=EPERM \ - host=remote type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv6, mac failure (domby) + sendmsg \ @@ -1857,38 +1860,38 @@ fi ## TESTCASE: local unlabeled IPv4, sanity check + sendto \ mlsop=eq expres=success \ - host=local type=unlabeled op=recv_udp ipv=ipv4 port=5100 \ + host=local type=unlabeled op=recv_udp ipv=ipv4 port=$tst_port1 \ '$host_remote $port' ## TESTCASE: local unlabeled IPv6, sanity check + sendto \ mlsop=eq expres=success \ - host=local type=unlabeled op=recv_udp ipv=ipv6 port=5100 \ + host=local type=unlabeled op=recv_udp ipv=ipv6 port=$tst_port1 \ '$host_remote $port' ## TESTCASE: remote unlabeled IPv4, sanity check + sendto \ mlsop=eq expres=success \ - host=remote type=unlabeled op=recv_udp ipv=ipv4 port=5100 \ + host=remote type=unlabeled op=recv_udp ipv=ipv4 port=$tst_port1 \ '$host_remote $port' ## TESTCASE: remote unlabeled IPv6, sanity check + sendto \ mlsop=eq expres=success \ - host=remote type=unlabeled op=recv_udp ipv=ipv6 port=5100 \ + host=remote type=unlabeled op=recv_udp ipv=ipv6 port=$tst_port1 \ '$host_remote $port' if [[ $PPROFILE == lspp ]]; then ## TESTCASE: local IPsec IPv4, mac success (eq) + sendto \ mlsop=eq expres=success \ - host=local type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv4, mac failure (incomp) + sendto \ mlsop=incomp expres=fail err=EPERM \ - host=local type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv4, mac failure (dom) + sendto \ mlsop=dom expres=fail err=EPERM \ - host=local type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv4, mac failure (domby) + sendto \ @@ -1898,17 +1901,17 @@ if [[ $PPROFILE == lspp ]]; then ## TESTCASE: remote IPsec IPv4, mac success (eq) + sendto \ mlsop=eq expres=success \ - host=remote type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv4, mac failure (incomp) + sendto \ mlsop=incomp expres=fail err=EPERM \ - host=remote type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv4, mac failure (dom) + sendto \ mlsop=dom expres=fail err=EPERM \ - host=remote type=ipsec op=recv_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv4 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv4, mac failure (domby) + sendto \ @@ -1918,17 +1921,17 @@ if [[ $PPROFILE == lspp ]]; then ## TESTCASE: local IPsec IPv6, mac success (eq) + sendto \ mlsop=eq expres=success \ - host=local type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv6, mac failure (incomp) + sendto \ mlsop=incomp expres=fail err=EPERM \ - host=local type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv6, mac failure (dom) + sendto \ mlsop=dom expres=fail err=EPERM \ - host=local type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: local IPsec IPv6, mac failure (domby) + sendto \ @@ -1938,12 +1941,12 @@ if [[ $PPROFILE == lspp ]]; then ## TESTCASE: remote IPsec IPv6, mac success (eq) + sendto \ mlsop=eq expres=success \ - host=remote type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv6, mac failure (incomp) + sendto \ mlsop=incomp expres=fail err=EPERM \ - host=remote type=ipsec op=recv_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=recv_udp ipv=ipv6 port=$tst_port3 \ '$host_remote $port' ## TESTCASE: remote IPsec IPv6, mac failure (dom) + sendto \ @@ -1980,169 +1983,169 @@ fi + read \ mlsop=eq expres=success \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=local type=unlabeled op=sendrand_udp ipv=ipv4 port=5100 \ + host=local type=unlabeled op=sendrand_udp ipv=ipv4 port=$tst_port1 \ '$ipv $port' ## TESTCASE: local unlabeled IPv6, sanity check + read \ mlsop=eq expres=success \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=local type=unlabeled op=sendrand_udp ipv=ipv6 port=5100 \ + host=local type=unlabeled op=sendrand_udp ipv=ipv6 port=$tst_port1 \ '$ipv $port' ## TESTCASE: remote unlabeled IPv4, sanity check + read \ mlsop=eq expres=success \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=remote type=unlabeled op=sendrand_udp ipv=ipv4 port=5100 \ + host=remote type=unlabeled op=sendrand_udp ipv=ipv4 port=$tst_port1 \ '$ipv $port' ## TESTCASE: remote unlabeled IPv6, sanity check + read \ mlsop=eq expres=success \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=remote type=unlabeled op=sendrand_udp ipv=ipv6 port=5100 \ + host=remote type=unlabeled op=sendrand_udp ipv=ipv6 port=$tst_port1 \ '$ipv $port' if [[ $PPROFILE == lspp ]]; then ## TESTCASE: local NetLabel IPv4, mac success (eq) + read \ mlsop=eq expres=success \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (incomp) + read \ mlsop=incomp expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (dom) + read \ mlsop=dom expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local NetLabel IPv4, mac failure (domby) + read \ mlsop=domby expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=local type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=local type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac success (eq) + read \ mlsop=eq expres=success \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (incomp) + read \ mlsop=incomp expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (dom) + read \ mlsop=dom expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: remote NetLabel IPv4, mac failure (domby) + read \ mlsop=domby expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=5200 \ + host=remote type=netlabel op=sendrand_udp ipv=ipv4 port=$tst_port2 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac success (eq) + read \ mlsop=eq expres=success \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (incomp) + read \ mlsop=incomp expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (dom) + read \ mlsop=dom expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv4, mac failure (domby) + read \ mlsop=domby expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=local type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac success (eq) + read \ mlsop=eq expres=success \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (incomp) + read \ mlsop=incomp expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (dom) + read \ mlsop=dom expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv4, mac failure (domby) + read \ mlsop=domby expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv4 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac success (eq) + read \ mlsop=eq expres=success \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (incomp) + read \ mlsop=incomp expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (dom) + read \ mlsop=dom expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: local IPsec IPv6, mac failure (domby) + read \ mlsop=domby expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=local type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=local type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac success (eq) + read \ mlsop=eq expres=success \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (incomp) + read \ mlsop=incomp expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (dom) + read \ mlsop=dom expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall_inbound_rej \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' ## TESTCASE: remote IPsec IPv6, mac failure (domby) + read \ mlsop=domby expres=fail err=EINTR \ auwatchfunc=auwatch_syscall augrokfunc=augrok_syscall \ - host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=5300 \ + host=remote type=ipsec op=sendrand_udp ipv=ipv6 port=$tst_port3 \ '$ipv $port' fi diff --git a/audit/utils/network-server/lblnet_tst-tcp b/audit/utils/network-server/lblnet_tst-tcp index c06545a..d23794d 100644 --- a/audit/utils/network-server/lblnet_tst-tcp +++ b/audit/utils/network-server/lblnet_tst-tcp @@ -1,6 +1,6 @@ # LSPP labeled networking test server -# listens on IPv6/TCP port 5000 for unlabeled connections -# listens on IPv4/TCP port 5001 for labeled connections +# listens on IPv6/TCP port 4000 for unlabeled connections +# listens on IPv4/TCP port 4001 for labeled connections service lblnet_tst { @@ -15,7 +15,7 @@ service lblnet_tst socket_type = stream protocol = tcp - port = 5000 + port = 4000 server = /usr/local/eal4_testing/audit-test/utils/network-server/lblnet_tst_server server_args = -i -t 10 @@ -34,7 +34,7 @@ service lblnet_tst_labeled socket_type = stream protocol = tcp - port = 5001 + port = 4001 server = /usr/local/eal4_testing/audit-test/utils/network-server/lblnet_tst_server server_args = -i -t 10 diff --git a/audit/utils/network-server/lblnet_tst_server.c b/audit/utils/network-server/lblnet_tst_server.c index a282349..0c62244 100644 --- a/audit/utils/network-server/lblnet_tst_server.c +++ b/audit/utils/network-server/lblnet_tst_server.c @@ -61,7 +61,7 @@ #define LCK_FILE "/var/lock/lblnet_tst_server" /* control socket constants */ -#define CTL_SOCK_PORT_DEFAULT 5000 +#define CTL_SOCK_PORT_DEFAULT 4000 #define CTL_SOCK_LISTEN_QUEUE 1 #define CTL_SOCK_BUF_SIZE 4096 /* bytes */ -- 1.7.1 |