summary: Test for audit filter (auditctl -F) description: | Sanity test for audit filter - auditctl "-F" option. At the moment the following filter are covered by the test: * -F pid/exe (RHEL-7.3) * -F saddr_fam (RHEL-7.7) contact: Ondrej Moris component: - audit test: ./runtest.sh require: - library(audit/testing) recommend: - audit - gcc - nc duration: 5m enabled: true tag: - CI-Tier-1 - NoRHEL4 - NoRHEL5 - NoRHEL6 - TIPpass_Security - Tier1 - Tier1security - kernel tier: '1' link: - relates: https://bugzilla.redhat.com/show_bug.cgi?id=1715852 - relates: https://bugzilla.redhat.com/show_bug.cgi?id=1135565 - relates: https://bugzilla.redhat.com/show_bug.cgi?id=1715679 adjust: - enabled: false when: distro == rhel-4, rhel-5, rhel-6 continue: false extra-nitrate: TC#0534805 extra-summary: /CoreOS/audit/Sanity/filter extra-task: /CoreOS/audit/Sanity/filter