mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
test(sandbox): darwin end-to-end lockdown enforcement test (#374)
This commit is contained in:
@@ -765,7 +765,11 @@ func TestTranslateNetworkLockdown(t *testing.T) {
|
||||
proxyAllow := `(allow network-outbound (remote ip "localhost:54321"))`
|
||||
blanketAllow := "(allow network-outbound)\n"
|
||||
dnsAllow := `(allow network-outbound (remote unix-socket (path-literal "/var/run/mDNSResponder")))`
|
||||
dnsAllowPrivate := `(allow network-outbound (remote unix-socket (path-literal "/private/var/run/mDNSResponder")))`
|
||||
dnsMachAllow := `(allow mach-lookup (global-name "com.apple.dnssd.service"))`
|
||||
dnsPortAllow := `(allow network-outbound (remote ip "*:53"))`
|
||||
bindRule := `(allow network* (local ip "localhost:*"))`
|
||||
loopbackOutboundAllow := `(allow network-outbound (remote ip "localhost:*"))`
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
@@ -785,11 +789,14 @@ func TestTranslateNetworkLockdown(t *testing.T) {
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "allow_direct_dns reopens mDNSResponder",
|
||||
name: "allow_direct_dns reopens mDNSResponder and port 53",
|
||||
rt: rt,
|
||||
mutate: func(p *sandbox.SandboxPolicy) { p.AllowDirectDNS = utils.PtrTo(true) },
|
||||
assert: func(t *testing.T, out string) {
|
||||
assert.Contains(t, out, dnsAllow)
|
||||
assert.Contains(t, out, dnsAllowPrivate)
|
||||
assert.Contains(t, out, dnsMachAllow)
|
||||
assert.Contains(t, out, dnsPortAllow)
|
||||
},
|
||||
},
|
||||
{
|
||||
@@ -799,10 +806,11 @@ func TestTranslateNetworkLockdown(t *testing.T) {
|
||||
assert: func(t *testing.T, out string) {
|
||||
assert.Contains(t, out, denyMarker)
|
||||
assert.Contains(t, out, bindRule)
|
||||
assert.Contains(t, out, loopbackOutboundAllow)
|
||||
denyIdx := strings.Index(out, denyMarker)
|
||||
bindIdx := strings.Index(out, bindRule)
|
||||
require.GreaterOrEqual(t, denyIdx, 0)
|
||||
assert.Greater(t, bindIdx, denyIdx, "bind rules must come after the lockdown deny (SBPL last-match-wins)")
|
||||
assert.Greater(t, strings.Index(out, bindRule), denyIdx, "bind rules must come after the lockdown deny (SBPL last-match-wins)")
|
||||
assert.Greater(t, strings.Index(out, loopbackOutboundAllow), denyIdx, "loopback outbound allow must come after the lockdown deny")
|
||||
},
|
||||
},
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user