aboutsummaryrefslogtreecommitdiffstats
path: root/spec/classes/tripleo_selinux_spec.rb
blob: 301006b9ffa5b273ce81ae5390daeced82a7f63d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
# Copyright (C) 2014 eNovance SAS <licensing@enovance.com>
#
# Licensed under the Apache License, Version 2.0 (the "License"); you may
# not use this file except in compliance with the License. You may obtain
# a copy of the License at
#
#      http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
# License for the specific language governing permissions and limitations
# under the License.
#
# Unit tests for tripleo::selinux
#

require 'spec_helper'

describe 'tripleo::selinux' do

  shared_examples_for 'manage selinux' do

    context 'with selinux enforcing' do
      before :each do
        facts.merge!( :selinux_current_mode => 'enforcing' )
      end

      let :params do
        { :mode       => 'disabled',
          :booleans   => ['foo', 'bar'],
          :modules    => ['module1', 'module2'],
          :directory  => '/path/to/modules'}
      end

      it 'runs setenforce 0' do
        is_expected.to contain_exec('/sbin/setenforce 0')
      end

      it 'enables the SELinux boolean' do
        is_expected.to contain_selboolean('foo').with(
          :persistent => true,
          :value      => 'on',
        )
      end

      it 'enables the SELinux modules' do
        is_expected.to contain_selmodule('module1').with(
          :ensure       => 'present',
          :selmoduledir => '/path/to/modules',
        )
      end

    end

    context 'with selinux disabled' do
      before :each do
        facts.merge!( :selinux => 'false' )
      end

      let :params do
        { :mode       => 'enforcing',
          :booleans   => ['foo', 'bar'],
          :modules    => ['module1', 'module2'],
          :directory  => '/path/to/modules'}
      end

      it 'runs setenforce 1' do
        is_expected.to contain_exec('/sbin/setenforce 1')
      end

      it 'enables the SELinux boolean' do
        is_expected.to contain_selboolean('foo').with(
          :persistent => true,
          :value      => 'on',
        )
      end

      it 'enables the SELinux modules' do
        is_expected.to contain_selmodule('module1').with(
          :ensure       => 'present',
          :selmoduledir => '/path/to/modules',
        )
      end

    end

  end

  context 'on Debian platforms' do
    let :facts do
      { :osfamily               => 'Debian' }
    end

    it_raises 'a Puppet::Error', /OS family unsuppored yet \(Debian\), SELinux support is only limited to RedHat family OS/
  end

  context 'on RedHat platforms' do
    let :facts do
      { :osfamily => 'RedHat' }
    end

    it_configures 'manage selinux'
  end

end