aboutsummaryrefslogtreecommitdiffhomepage
path: root/internal
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2026-10-01 22:34:51 +0900
committerOphestra <cat@gensokyo.uk>2026-10-02 18:10:05 +0900
commit8ddc826bd02ff0d58123e1af5de2f48ae0dbc7c9 (patch)
tree74d13485a177c442154a4c343062efa128dc1ab2 /internal
parent4b19686109b0962ea68dfe58feafffe3bac9c202 (diff)
test/sandbox: migrate tests
This benefits even more than the cmd/sharefs test suite, the slow python-based test script was a major bottleneck. Replacing the nix-represented test cases with compound literals also significantly increases readability. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal')
-rw-r--r--internal/workflows/doc.go15
-rw-r--r--internal/workflows/step.go18
-rw-r--r--internal/workflows/test.go7
3 files changed, 29 insertions, 11 deletions
diff --git a/internal/workflows/doc.go b/internal/workflows/doc.go
index e34c59c8..b0dab000 100644
--- a/internal/workflows/doc.go
+++ b/internal/workflows/doc.go
@@ -67,6 +67,7 @@ Before starting the container, configure act_runner via config.yaml:
-v /var/lib/rosa:/rosa
--security-opt='unmask=/proc/*'
--cap-add=SYS_ADMIN
+ --cap-add=SYS_PTRACE
--device=/dev/kvm
--device=/dev/fuse
valid_volumes:
@@ -76,8 +77,9 @@ where /var/lib/rosa is the absolute pathname of the cache directory in the init
namespace. Setting MBF_POISON_OPEN enables cmd/mbf to run as root. It is also
a good idea here to set runner.capacity to reflect the capacity of the guest, so
jobs can be consumed quicker. Removing mount points covering /proc enables
-testing of cmd/hakurei. Exposing the fuse device and adding capability SYS_ADMIN
-enables testing of cmd/sharefs.
+testing of cmd/hakurei. Exposing the fuse device and adding capability
+CAP_SYS_ADMIN enables testing of cmd/sharefs. Adding capability CAP_SYS_PTRACE
+enables dumping seccomp filters via ptrace on the patched kernel.
Build a statically-linked cmd/mbf:
@@ -120,6 +122,15 @@ this can be achieved by the init script:
It is often a good idea to populate the cache from a mirror service before the
first workflow job is started and re-populate it after every cmd/mbf update.
+# Configuring the kernel
+
+In order to attach to the container process, the sysctl kernel.yama.ptrace_scope
+must be set to 0. After which, apply the patch test/sandbox/seccomp.patch to
+your kernel sources, compile and install the new kernel. Refer to
+https://wiki.alpinelinux.org/wiki/Custom_Kernel if the guest runs Alpine Linux.
+If running podman or docker as root, the patch is not required. Do not apply
+this patch on a system meant to be secure.
+
# Security
The design of Microsoft Github workflows is inherently insecure: it requires
diff --git a/internal/workflows/step.go b/internal/workflows/step.go
index 219ed78b..6d715196 100644
--- a/internal/workflows/step.go
+++ b/internal/workflows/step.go
@@ -55,9 +55,21 @@ func newCIRequest(display, name, id string) Step {
var install = Step{
Name: "Install hakurei",
Run: "HAKUREI_VERSION=\"$(cat cmd/dist/VERSION)-${{ steps.dist.outputs.rev }}\" && " +
- "tar xf \"result/hakurei-$HAKUREI_VERSION-amd64.tar.gz\" && " +
- "\"./hakurei-$HAKUREI_VERSION-amd64/install.sh\" && " +
- "sudo -u ubuntu hakurei version",
+ "tar xf result/hakurei-$HAKUREI_VERSION*-amd64.tar.gz && " +
+ "./hakurei-$HAKUREI_VERSION*-amd64/install.sh && " +
+ "sudo -u ubuntu hakurei version && " +
+ "echo 'Defaults closefrom_override' > " +
+ "/etc/sudoers.d/closefrom_override && " +
+ "mkdir /var/empty",
+}
+
+// newTestsuite returns a step for running an integration test suite.
+func newTestsuite(name, prefix string) Step {
+ return Step{
+ Name: "Compile and run test suite",
+ Run: prefix + "rm -rf result && " +
+ "go run -tags=testsuite ./test/" + name + " ubuntu",
+ }
}
// newNixOSTest returns a step for running the named NixOS test.
diff --git a/internal/workflows/test.go b/internal/workflows/test.go
index d3290f16..37f41e51 100644
--- a/internal/workflows/test.go
+++ b/internal/workflows/test.go
@@ -82,12 +82,7 @@ var _ = (&Workflow{
"setuid=1023,setgid=1023 /sdcard",
},
- {
- Name: "Compile and run test suite",
- Run: "sharefs -V && rm -rf result && " +
- "go run -tags=testsuite ./test/sharefs ubuntu",
- },
-
+ newTestsuite("sharefs", "sharefs -V && "),
newUploadArtifact("test output", "fs_mark"),
},
}},