Home | History | Annotate | Download | only in security_DeviceJail_Filesystem
      1 # Copyright 2017 The Chromium OS Authors. All rights reserved.
      2 # Use of this source code is governed by a BSD-style license that can be
      3 # found in the LICENSE file.
      4 
      5 AUTHOR = "ejcaruso (a] chromium.org"
      6 NAME = "security_DeviceJail_Filesystem"
      7 PURPOSE = "Verify that the device jail FUSE server is functioning."
      8 TIME = "SHORT"
      9 ATTRIBUTES = "suite:security"
     10 TEST_CATEGORY = "Functional"
     11 TEST_CLASS = "security"
     12 TEST_TYPE = "client"
     13 DOC = """
     14 This test is not applicable if the jail-control device is not present.
     15 This restricts it to 3.14 or later kernels.
     16 Ensures that the only visible character devices in the device jail
     17 FUSE filesystem are explicitly whitelisted ones and USB devices, and
     18 that USB devices are not directly passed through.
     19 """
     20 
     21 job.run_test('security_DeviceJail_Filesystem')
     22