Blame SOURCES/0001-RHEL-only-Add-cockpit-by-default-to-some-zones.patch

e4e66d
From 52d53cc4ab0503ad484330b2121f85094a7903de Mon Sep 17 00:00:00 2001
7d5a1d
From: Eric Garver <e@erig.me>
7d5a1d
Date: Mon, 9 Jul 2018 11:29:33 -0400
e4e66d
Subject: [PATCH 1/6] RHEL only: Add cockpit by default to some zones
7d5a1d
7d5a1d
Fixes: #1581578
7d5a1d
---
7d5a1d
 config/zones/home.xml                 |  1 +
7d5a1d
 config/zones/internal.xml             |  1 +
7d5a1d
 config/zones/public.xml               |  1 +
7d5a1d
 config/zones/work.xml                 |  1 +
e4e66d
 src/tests/cli/firewall-cmd.at         | 14 +++++++++++++-
4d3a0d
 src/tests/features/helpers_custom.at  |  9 +++++++++
7d5a1d
 src/tests/features/service_include.at |  2 +-
7d5a1d
 src/tests/regression/gh366.at         |  3 +++
7d5a1d
 src/tests/regression/gh453.at         |  2 ++
7d5a1d
 src/tests/regression/rhbz1514043.at   |  2 +-
4d3a0d
 10 files changed, 33 insertions(+), 3 deletions(-)
7d5a1d
7d5a1d
diff --git a/config/zones/home.xml b/config/zones/home.xml
7d5a1d
index 42b29b2f2d50..8aa8afa0e8aa 100644
7d5a1d
--- a/config/zones/home.xml
7d5a1d
+++ b/config/zones/home.xml
7d5a1d
@@ -6,4 +6,5 @@
7d5a1d
   <service name="mdns"/>
7d5a1d
   <service name="samba-client"/>
7d5a1d
   <service name="dhcpv6-client"/>
7d5a1d
+  <service name="cockpit"/>
7d5a1d
 </zone>
7d5a1d
diff --git a/config/zones/internal.xml b/config/zones/internal.xml
7d5a1d
index e646b48c94e8..40cb7e14424b 100644
7d5a1d
--- a/config/zones/internal.xml
7d5a1d
+++ b/config/zones/internal.xml
7d5a1d
@@ -6,4 +6,5 @@
7d5a1d
   <service name="mdns"/>
7d5a1d
   <service name="samba-client"/>
7d5a1d
   <service name="dhcpv6-client"/>
7d5a1d
+  <service name="cockpit"/>
7d5a1d
 </zone>
7d5a1d
diff --git a/config/zones/public.xml b/config/zones/public.xml
7d5a1d
index 49795d8c9068..617e131a4895 100644
7d5a1d
--- a/config/zones/public.xml
7d5a1d
+++ b/config/zones/public.xml
7d5a1d
@@ -4,4 +4,5 @@
7d5a1d
   <description>For use in public areas. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description>
7d5a1d
   <service name="ssh"/>
7d5a1d
   <service name="dhcpv6-client"/>
7d5a1d
+  <service name="cockpit"/>
7d5a1d
 </zone>
7d5a1d
diff --git a/config/zones/work.xml b/config/zones/work.xml
7d5a1d
index 6ea5550a40bd..9609ee6f65c2 100644
7d5a1d
--- a/config/zones/work.xml
7d5a1d
+++ b/config/zones/work.xml
7d5a1d
@@ -4,4 +4,5 @@
7d5a1d
   <description>For use in work areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description>
7d5a1d
   <service name="ssh"/>
7d5a1d
   <service name="dhcpv6-client"/>
7d5a1d
+  <service name="cockpit"/>
7d5a1d
 </zone>
e4e66d
diff --git a/src/tests/cli/firewall-cmd.at b/src/tests/cli/firewall-cmd.at
e4e66d
index 806af74221b6..74f480f8730f 100644
e4e66d
--- a/src/tests/cli/firewall-cmd.at
e4e66d
+++ b/src/tests/cli/firewall-cmd.at
e4e66d
@@ -1285,6 +1285,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
         chain filter_IN_public_allow {
7d5a1d
         tcp dport 22 ct state new,untracked accept
7d5a1d
         ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
7d5a1d
+        tcp dport 9090 ct state new,untracked accept
7d5a1d
         tcp dport 1122 ct state new,untracked accept
7d5a1d
         tcp dport 3333 ct state new,untracked accept
7d5a1d
         tcp dport 4444 ct state new,untracked accept
e4e66d
@@ -1300,6 +1301,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
     ])
7d5a1d
     IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
7d5a1d
         ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
7d5a1d
+        ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:1122 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:3333 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:4444 ctstate NEW,UNTRACKED
e4e66d
@@ -1314,6 +1316,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
     IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
7d5a1d
         ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
7d5a1d
+        ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT tcp ::/0 ::/0 tcp dpt:1122 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT tcp ::/0 ::/0 tcp dpt:3333 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT tcp ::/0 ::/0 tcp dpt:4444 ctstate NEW,UNTRACKED
e4e66d
@@ -1395,6 +1398,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
         chain filter_IN_public_allow {
7d5a1d
         tcp dport 22 ct state new,untracked accept
7d5a1d
         ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
7d5a1d
+        tcp dport 9090 ct state new,untracked accept
7d5a1d
         }
7d5a1d
         }
7d5a1d
     ])
e4e66d
@@ -1498,6 +1502,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
     ])
7d5a1d
     IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
7d5a1d
         ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
7d5a1d
+        ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
7d5a1d
     ])
7d5a1d
     IPTABLES_LIST_RULES([filter], [FWDI_public_pre], 0, [dnl
7d5a1d
     ])
e4e66d
@@ -1532,6 +1537,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
     IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
7d5a1d
         ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
7d5a1d
+        ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
7d5a1d
     ])
7d5a1d
     IP6TABLES_LIST_RULES([filter], [FWDI_public_pre], 0, [dnl
7d5a1d
     ])
e4e66d
@@ -1579,6 +1585,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
         chain filter_IN_public_allow {
7d5a1d
         tcp dport 22 ct state new,untracked accept
7d5a1d
         ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
7d5a1d
+        tcp dport 9090 ct state new,untracked accept
7d5a1d
         icmp type echo-request accept
7d5a1d
         icmpv6 type echo-request accept
7d5a1d
         }
e4e66d
@@ -1619,6 +1626,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
     ])
7d5a1d
     IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
7d5a1d
         ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
7d5a1d
+        ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 icmptype 8
7d5a1d
     ])
7d5a1d
     IPTABLES_LIST_RULES([filter], [FWDI_public_pre], 0, [dnl
e4e66d
@@ -1641,6 +1649,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
     IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
7d5a1d
         ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
7d5a1d
+        ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT icmpv6 ::/0 ::/0 ipv6-icmptype 128
7d5a1d
     ])
7d5a1d
     IP6TABLES_LIST_RULES([filter], [FWDI_public_pre], 0, [dnl
e4e66d
@@ -1697,6 +1706,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
         chain filter_IN_public_allow {
7d5a1d
         tcp dport 22 ct state new,untracked accept
7d5a1d
         ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
7d5a1d
+        tcp dport 9090 ct state new,untracked accept
7d5a1d
         }
7d5a1d
         }
7d5a1d
     ])
e4e66d
@@ -1734,6 +1744,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
     ])
7d5a1d
     IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
7d5a1d
         ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
7d5a1d
+        ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
7d5a1d
     ])
7d5a1d
     IPTABLES_LIST_RULES([filter], [IN_public_deny], 0, [dnl
7d5a1d
     ])
e4e66d
@@ -1754,6 +1765,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
     IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
7d5a1d
         ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
7d5a1d
         ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
7d5a1d
+        ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
7d5a1d
     ])
7d5a1d
     IP6TABLES_LIST_RULES([filter], [IN_public_deny], 0, [dnl
7d5a1d
     ])
e4e66d
@@ -1779,7 +1791,7 @@ FWD_START_TEST([rich rules priority])
7d5a1d
         icmp-block-inversion: no
7d5a1d
         interfaces:
7d5a1d
         sources:
7d5a1d
-        services: dhcpv6-client ssh
7d5a1d
+        services: cockpit dhcpv6-client ssh
7d5a1d
         ports:
7d5a1d
         protocols:
7d5a1d
         masquerade: no
e4e66d
diff --git a/src/tests/features/helpers_custom.at b/src/tests/features/helpers_custom.at
e4e66d
index 41d0f17b1d9e..bd4b52cfb1d6 100644
e4e66d
--- a/src/tests/features/helpers_custom.at
e4e66d
+++ b/src/tests/features/helpers_custom.at
e4e66d
@@ -37,6 +37,7 @@ NFT_LIST_RULES([inet], [filter_IN_public_allow], 0, [dnl
e4e66d
         chain filter_IN_public_allow {
e4e66d
             tcp dport 22 ct state new,untracked accept
e4e66d
             ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
e4e66d
+            tcp dport 9090 ct state new,untracked accept
e4e66d
             tcp dport 2121 ct helper set "helper-ftptest-tcp"
e4e66d
             tcp dport 2121 ct state new,untracked accept
e4e66d
         }
e4e66d
@@ -47,6 +48,7 @@ IPTABLES_LIST_RULES([raw], [PRE_public_allow], 0, [dnl
e4e66d
 ])
e4e66d
 IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
e4e66d
     ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
e4e66d
+    ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:2121 ctstate NEW,UNTRACKED
e4e66d
 ])
e4e66d
 IP6TABLES_LIST_RULES([raw], [PRE_public_allow], 0, [dnl
e4e66d
@@ -55,6 +57,7 @@ IP6TABLES_LIST_RULES([raw], [PRE_public_allow], 0, [dnl
e4e66d
 IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
e4e66d
     ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
e4e66d
+    ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT tcp ::/0 ::/0 tcp dpt:2121 ctstate NEW,UNTRACKED
e4e66d
 ])
e4e66d
 
e4e66d
@@ -91,6 +94,7 @@ NFT_LIST_RULES([inet], [filter_IN_public_allow], 0, [dnl
e4e66d
         chain filter_IN_public_allow {
e4e66d
             tcp dport 22 ct state new,untracked accept
e4e66d
             ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
e4e66d
+            tcp dport 9090 ct state new,untracked accept
e4e66d
             tcp dport 2121 ct helper set "helper-ftptest-tcp"
e4e66d
             tcp dport 2121 ct state new,untracked accept
e4e66d
         }
e4e66d
@@ -101,6 +105,7 @@ IPTABLES_LIST_RULES([raw], [PRE_public_allow], 0, [dnl
e4e66d
 ])
e4e66d
 IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
e4e66d
     ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
e4e66d
+    ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:2121 ctstate NEW,UNTRACKED
e4e66d
 ])
e4e66d
 IP6TABLES_LIST_RULES([raw], [PRE_public_allow], 0, [dnl
e4e66d
@@ -109,6 +114,7 @@ IP6TABLES_LIST_RULES([raw], [PRE_public_allow], 0, [dnl
e4e66d
 IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
e4e66d
     ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
e4e66d
+    ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT tcp ::/0 ::/0 tcp dpt:2121 ctstate NEW,UNTRACKED
e4e66d
 ])
e4e66d
 
e4e66d
@@ -126,6 +132,7 @@ NFT_LIST_RULES([inet], [filter_IN_public_allow], 0, [dnl
e4e66d
         chain filter_IN_public_allow {
e4e66d
             tcp dport 22 ct state new,untracked accept
e4e66d
             ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
e4e66d
+            tcp dport 9090 ct state new,untracked accept
e4e66d
             tcp dport 21 ct helper set "helper-ftp-tcp"
e4e66d
             tcp dport 2121 ct helper set "helper-ftptest-tcp"
e4e66d
             tcp dport 2121 ct state new,untracked accept
e4e66d
@@ -139,6 +146,7 @@ IPTABLES_LIST_RULES([raw], [PRE_public_allow], 0, [dnl
e4e66d
 ])
e4e66d
 IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
e4e66d
     ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
e4e66d
+    ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:2121 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:21 ctstate NEW,UNTRACKED
e4e66d
 ])
e4e66d
@@ -149,6 +157,7 @@ IP6TABLES_LIST_RULES([raw], [PRE_public_allow], 0, [dnl
e4e66d
 IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
e4e66d
     ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
e4e66d
+    ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT tcp ::/0 ::/0 tcp dpt:2121 ctstate NEW,UNTRACKED
e4e66d
     ACCEPT tcp ::/0 ::/0 tcp dpt:21 ctstate NEW,UNTRACKED
e4e66d
 ])
e4e66d
diff --git a/src/tests/features/service_include.at b/src/tests/features/service_include.at
e4e66d
index 7f02701a9419..070f1578fc2b 100644
e4e66d
--- a/src/tests/features/service_include.at
e4e66d
+++ b/src/tests/features/service_include.at
e4e66d
@@ -120,7 +120,7 @@ FWD_CHECK([--zone=drop --list-services], 0, [dnl
e4e66d
 
e4e66d
 ])
e4e66d
 FWD_CHECK([--zone=public --list-services], 0, [dnl
e4e66d
-dhcpv6-client ssh
e4e66d
+cockpit dhcpv6-client ssh
e4e66d
 ])
e4e66d
 FWD_CHECK([-q --permanent --service=my-service-with-include --remove-include=does-not-exist])
e4e66d
 FWD_RELOAD
7d5a1d
diff --git a/src/tests/regression/gh366.at b/src/tests/regression/gh366.at
7d5a1d
index 1441a6be53bf..51ff504e6a9d 100644
7d5a1d
--- a/src/tests/regression/gh366.at
7d5a1d
+++ b/src/tests/regression/gh366.at
7d5a1d
@@ -7,6 +7,7 @@ table inet firewalld {
7d5a1d
 chain filter_IN_public_allow {
7d5a1d
 tcp dport 22 ct state new,untracked accept
7d5a1d
 ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
7d5a1d
+tcp dport 9090 ct state new,untracked accept
7d5a1d
 ip daddr 224.0.0.251 udp dport 5353 ct state new,untracked accept
7d5a1d
 ip6 daddr ff02::fb udp dport 5353 ct state new,untracked accept
7d5a1d
 }
7d5a1d
@@ -14,11 +15,13 @@ ip6 daddr ff02::fb udp dport 5353 ct state new,untracked accept
7d5a1d
 ])
7d5a1d
 IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
7d5a1d
 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
7d5a1d
+ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
7d5a1d
 ACCEPT udp -- 0.0.0.0/0 224.0.0.251 udp dpt:5353 ctstate NEW,UNTRACKED
7d5a1d
 ])
7d5a1d
 IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
7d5a1d
 ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
7d5a1d
 ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
7d5a1d
+ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
7d5a1d
 ACCEPT udp ::/0 ff02::fb udp dpt:5353 ctstate NEW,UNTRACKED
7d5a1d
 ])])
7d5a1d
 
7d5a1d
diff --git a/src/tests/regression/gh453.at b/src/tests/regression/gh453.at
e4e66d
index 36a6fce5f22a..61bc90aae673 100644
7d5a1d
--- a/src/tests/regression/gh453.at
7d5a1d
+++ b/src/tests/regression/gh453.at
7d5a1d
@@ -18,6 +18,7 @@ NFT_LIST_RULES([inet], [filter_IN_public_allow], 0, [dnl
e4e66d
     chain filter_IN_public_allow {
e4e66d
     tcp dport 22 ct state new,untracked accept
e4e66d
     ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
e4e66d
+    tcp dport 9090 ct state new,untracked accept
e4e66d
     tcp dport 21 ct helper set "helper-ftp-tcp"
e4e66d
     tcp dport 21 ct state new,untracked accept
e4e66d
     }
7d5a1d
@@ -42,6 +43,7 @@ NFT_LIST_RULES([inet], [filter_IN_public_allow], 0, [dnl
e4e66d
     chain filter_IN_public_allow {
e4e66d
     tcp dport 22 ct state new,untracked accept
e4e66d
     ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
e4e66d
+    tcp dport 9090 ct state new,untracked accept
e4e66d
     tcp dport 21 ct helper set "helper-ftp-tcp"
e4e66d
     tcp dport 21 ct state new,untracked accept
e4e66d
     tcp dport 5060 ct helper set "helper-sip-tcp"
7d5a1d
diff --git a/src/tests/regression/rhbz1514043.at b/src/tests/regression/rhbz1514043.at
4d3a0d
index efc33e09478b..241cf547f7f3 100644
7d5a1d
--- a/src/tests/regression/rhbz1514043.at
7d5a1d
+++ b/src/tests/regression/rhbz1514043.at
7d5a1d
@@ -5,7 +5,7 @@ FWD_CHECK([-q --set-log-denied=all])
7d5a1d
 FWD_CHECK([-q --permanent --zone=public --add-service=samba])
7d5a1d
 FWD_RELOAD
7d5a1d
 FWD_CHECK([--zone=public --list-all | TRIM | grep ^services], 0, [dnl
7d5a1d
-services: dhcpv6-client samba ssh
7d5a1d
+services: cockpit dhcpv6-client samba ssh
7d5a1d
 ])
4d3a0d
 
7d5a1d
 dnl check that log denied actually took effect
7d5a1d
-- 
4d3a0d
2.23.0
7d5a1d