Test reading of detached IMA signature (--sigfile). Suggested-by: Mimi Zohar <zohar@xxxxxxxxxxxxx> Signed-off-by: Vitaly Chikunov <vt@xxxxxxxxxxxx> --- tests/sign_verify.test | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/tests/sign_verify.test b/tests/sign_verify.test index 118c3f6..cddeb15 100755 --- a/tests/sign_verify.test +++ b/tests/sign_verify.test @@ -93,7 +93,8 @@ _test_sigfile() { return "$FAIL" fi - rm "$file_sig" "$file_sig2" + # Leave '$file_sig' for ima_verify --sigfile test. + rm "$file_sig2" } # Run single sign command @@ -254,9 +255,12 @@ sign_verify() { # Normal verify with proper key should pass expect_pass check_verify + expect_pass check_verify OPTS="--sigfile" # Multiple files and some don't verify expect_fail check_verify FILE="/dev/null $file" + + rm "$FILE.sig" fi TYPE=evm -- 2.11.0