diff options
| author | Ophestra <cat@gensokyo.uk> | 2026-10-01 22:34:51 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2026-10-02 18:10:05 +0900 |
| commit | 8ddc826bd02ff0d58123e1af5de2f48ae0dbc7c9 (patch) | |
| tree | 74d13485a177c442154a4c343062efa128dc1ab2 /internal/workflows | |
| parent | 4b19686109b0962ea68dfe58feafffe3bac9c202 (diff) | |
test/sandbox: migrate tests
This benefits even more than the cmd/sharefs test suite, the slow
python-based test script was a major bottleneck. Replacing the
nix-represented test cases with compound literals also significantly
increases readability.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal/workflows')
| -rw-r--r-- | internal/workflows/doc.go | 15 | ||||
| -rw-r--r-- | internal/workflows/step.go | 18 | ||||
| -rw-r--r-- | internal/workflows/test.go | 7 |
3 files changed, 29 insertions, 11 deletions
diff --git a/internal/workflows/doc.go b/internal/workflows/doc.go index e34c59c8..b0dab000 100644 --- a/internal/workflows/doc.go +++ b/internal/workflows/doc.go @@ -67,6 +67,7 @@ Before starting the container, configure act_runner via config.yaml: -v /var/lib/rosa:/rosa --security-opt='unmask=/proc/*' --cap-add=SYS_ADMIN + --cap-add=SYS_PTRACE --device=/dev/kvm --device=/dev/fuse valid_volumes: @@ -76,8 +77,9 @@ where /var/lib/rosa is the absolute pathname of the cache directory in the init namespace. Setting MBF_POISON_OPEN enables cmd/mbf to run as root. It is also a good idea here to set runner.capacity to reflect the capacity of the guest, so jobs can be consumed quicker. Removing mount points covering /proc enables -testing of cmd/hakurei. Exposing the fuse device and adding capability SYS_ADMIN -enables testing of cmd/sharefs. +testing of cmd/hakurei. Exposing the fuse device and adding capability +CAP_SYS_ADMIN enables testing of cmd/sharefs. Adding capability CAP_SYS_PTRACE +enables dumping seccomp filters via ptrace on the patched kernel. Build a statically-linked cmd/mbf: @@ -120,6 +122,15 @@ this can be achieved by the init script: It is often a good idea to populate the cache from a mirror service before the first workflow job is started and re-populate it after every cmd/mbf update. +# Configuring the kernel + +In order to attach to the container process, the sysctl kernel.yama.ptrace_scope +must be set to 0. After which, apply the patch test/sandbox/seccomp.patch to +your kernel sources, compile and install the new kernel. Refer to +https://wiki.alpinelinux.org/wiki/Custom_Kernel if the guest runs Alpine Linux. +If running podman or docker as root, the patch is not required. Do not apply +this patch on a system meant to be secure. + # Security The design of Microsoft Github workflows is inherently insecure: it requires diff --git a/internal/workflows/step.go b/internal/workflows/step.go index 219ed78b..6d715196 100644 --- a/internal/workflows/step.go +++ b/internal/workflows/step.go @@ -55,9 +55,21 @@ func newCIRequest(display, name, id string) Step { var install = Step{ Name: "Install hakurei", Run: "HAKUREI_VERSION=\"$(cat cmd/dist/VERSION)-${{ steps.dist.outputs.rev }}\" && " + - "tar xf \"result/hakurei-$HAKUREI_VERSION-amd64.tar.gz\" && " + - "\"./hakurei-$HAKUREI_VERSION-amd64/install.sh\" && " + - "sudo -u ubuntu hakurei version", + "tar xf result/hakurei-$HAKUREI_VERSION*-amd64.tar.gz && " + + "./hakurei-$HAKUREI_VERSION*-amd64/install.sh && " + + "sudo -u ubuntu hakurei version && " + + "echo 'Defaults closefrom_override' > " + + "/etc/sudoers.d/closefrom_override && " + + "mkdir /var/empty", +} + +// newTestsuite returns a step for running an integration test suite. +func newTestsuite(name, prefix string) Step { + return Step{ + Name: "Compile and run test suite", + Run: prefix + "rm -rf result && " + + "go run -tags=testsuite ./test/" + name + " ubuntu", + } } // newNixOSTest returns a step for running the named NixOS test. diff --git a/internal/workflows/test.go b/internal/workflows/test.go index d3290f16..37f41e51 100644 --- a/internal/workflows/test.go +++ b/internal/workflows/test.go @@ -82,12 +82,7 @@ var _ = (&Workflow{ "setuid=1023,setgid=1023 /sdcard", }, - { - Name: "Compile and run test suite", - Run: "sharefs -V && rm -rf result && " + - "go run -tags=testsuite ./test/sharefs ubuntu", - }, - + newTestsuite("sharefs", "sharefs -V && "), newUploadArtifact("test output", "fs_mark"), }, }}, |
