diff mbox series

[2/2] ima-evm-utils: Add test for sigfile reading

Message ID 20200912193614.12903-2-vt@altlinux.org (mailing list archive)
State New, archived
Headers show
Series [1/2] ima-evm-utils: Fix reading of sigfile | expand

Commit Message

Vitaly Chikunov Sept. 12, 2020, 7:36 p.m. UTC
Test reading of detached IMA signature (--sigfile).

Suggested-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Vitaly Chikunov <vt@altlinux.org>
---
 tests/sign_verify.test | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

Comments

Mimi Zohar Sept. 14, 2020, 12:30 a.m. UTC | #1
On Sat, 2020-09-12 at 22:36 +0300, Vitaly Chikunov wrote:
> Test reading of detached IMA signature (--sigfile).
> 
> Suggested-by: Mimi Zohar <zohar@linux.ibm.com>
> Signed-off-by: Vitaly Chikunov <vt@altlinux.org>

Thanks,

Mimi

> ---
>  tests/sign_verify.test | 6 +++++-
>  1 file changed, 5 insertions(+), 1 deletion(-)
> 
> diff --git a/tests/sign_verify.test b/tests/sign_verify.test
> index 118c3f6..cddeb15 100755
> --- a/tests/sign_verify.test
> +++ b/tests/sign_verify.test
> @@ -93,7 +93,8 @@ _test_sigfile() {
>      return "$FAIL"
>    fi
>  
> -  rm "$file_sig" "$file_sig2"
> +  # Leave '$file_sig' for ima_verify --sigfile test.
> +  rm "$file_sig2"
>  }
>  
>  # Run single sign command
> @@ -254,9 +255,12 @@ sign_verify() {
>  
>      # Normal verify with proper key should pass
>      expect_pass check_verify
> +    expect_pass check_verify OPTS="--sigfile"
>  
>      # Multiple files and some don't verify
>      expect_fail check_verify FILE="/dev/null $file"
> +
> +    rm "$FILE.sig"
>    fi
>  
>    TYPE=evm
diff mbox series

Patch

diff --git a/tests/sign_verify.test b/tests/sign_verify.test
index 118c3f6..cddeb15 100755
--- a/tests/sign_verify.test
+++ b/tests/sign_verify.test
@@ -93,7 +93,8 @@  _test_sigfile() {
     return "$FAIL"
   fi
 
-  rm "$file_sig" "$file_sig2"
+  # Leave '$file_sig' for ima_verify --sigfile test.
+  rm "$file_sig2"
 }
 
 # Run single sign command
@@ -254,9 +255,12 @@  sign_verify() {
 
     # Normal verify with proper key should pass
     expect_pass check_verify
+    expect_pass check_verify OPTS="--sigfile"
 
     # Multiple files and some don't verify
     expect_fail check_verify FILE="/dev/null $file"
+
+    rm "$FILE.sig"
   fi
 
   TYPE=evm