aboutsummaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-03-13 20:56:32 +0900
committerOphestra <cat@gensokyo.uk>2025-03-13 20:56:32 +0900
commitbeb3918809f0743e2275f6a3f358f622cea73d6b (patch)
treebd0a56756cc88f117b7e620fa3acae2a01ff136d
parent2871426df2d7d19ca6921d74a5834a627b920de5 (diff)
test: run go test under regular user
By default test vm commands run as root, this causes buildFHSEnv bwrap to cover some parts of /proc, making it impossible to mount proc in a mount namespace created under it. Running as a regular user gets around this issue. Signed-off-by: Ophestra <cat@gensokyo.uk>
-rw-r--r--test/default.nix11
-rw-r--r--test/test.py9
2 files changed, 13 insertions, 7 deletions
diff --git a/test/default.nix b/test/default.nix
index d803a235..bf3e007a 100644
--- a/test/default.nix
+++ b/test/default.nix
@@ -15,8 +15,15 @@ nixosTest {
{
environment.systemPackages = [
# For go tests:
- self.packages.${system}.fhs
- (writeShellScriptBin "fortify-src" "echo -n ${self.packages.${system}.fortify.src}")
+ (writeShellScriptBin "fortify-go-test" ''
+ set -e
+ WORK="$(mktemp -ud)"
+ cp -r "${self.packages.${system}.fortify.src}" "$WORK"
+ chmod -R +w "$WORK"
+ cd "$WORK"
+ ${self.packages.${system}.fhs}/bin/fortify-fhs -c \
+ 'go generate ./... && go test ./... && touch /tmp/go-test-ok'
+ '')
];
# Run with Go race detector:
diff --git a/test/test.py b/test/test.py
index 5a2ac246..03414a48 100644
--- a/test/test.py
+++ b/test/test.py
@@ -78,8 +78,7 @@ start_all()
machine.wait_for_unit("multi-user.target")
# Run fortify Go tests outside of nix build in the background:
-machine.succeed("rm -rf /tmp/src && cp -a \"$(fortify-src)\" /tmp/src")
-machine.succeed("fortify-fhs -c '(cd /tmp/src && go generate ./... && go test ./... && touch /tmp/success-gotest)' &> /tmp/gotest &")
+machine.succeed("sudo -u untrusted -i fortify-go-test &> /tmp/go-test &")
# To check fortify's version:
print(machine.succeed("sudo -u alice -i fortify version"))
@@ -217,6 +216,6 @@ machine.wait_for_file("/tmp/sway-exit-ok")
print(machine.succeed("find /run/user/1000/fortify"))
# Verify go test status:
-machine.wait_for_file("/tmp/gotest", timeout=5)
-print(machine.succeed("cat /tmp/gotest"))
-machine.wait_for_file("/tmp/success-gotest", timeout=5)
+machine.wait_for_file("/tmp/go-test", timeout=5)
+print(machine.succeed("cat /tmp/go-test"))
+machine.wait_for_file("/tmp/go-test-ok", timeout=5)