aboutsummaryrefslogtreecommitdiffhomepage
path: root/internal/workflows
diff options
context:
space:
mode:
Diffstat (limited to 'internal/workflows')
-rw-r--r--internal/workflows/doc.go4
-rw-r--r--internal/workflows/seccomp.patch18
-rw-r--r--internal/workflows/step.go4
-rw-r--r--internal/workflows/test.go6
4 files changed, 25 insertions, 7 deletions
diff --git a/internal/workflows/doc.go b/internal/workflows/doc.go
index a8f18ab4..24e86b8c 100644
--- a/internal/workflows/doc.go
+++ b/internal/workflows/doc.go
@@ -126,8 +126,8 @@ first workflow job is started and re-populate it after every cmd/mbf update.
# Configuring the kernel
In order to attach to the container process, the sysctl kernel.yama.ptrace_scope
-must be set to 0. After which, apply the patch test/sandbox/seccomp.patch to
-your kernel sources, compile and install the new kernel. Refer to
+must be set to 0. After which, apply the patch internal/workflows/seccomp.patch
+to your kernel sources, compile and install the new kernel. Refer to
https://wiki.alpinelinux.org/wiki/Custom_Kernel if the guest runs Alpine Linux.
If running podman or docker as root, the patch is not required. Do not apply
this patch on a system meant to be secure.
diff --git a/internal/workflows/seccomp.patch b/internal/workflows/seccomp.patch
new file mode 100644
index 00000000..ddabc71e
--- /dev/null
+++ b/internal/workflows/seccomp.patch
@@ -0,0 +1,18 @@
+diff --git a/kernel/seccomp.c b/kernel/seccomp.c
+index 25f62867a16d..7b63ccc8daf4 100644
+--- a/kernel/seccomp.c
++++ b/kernel/seccomp.c
+@@ -2216,8 +2216,12 @@ long seccomp_get_filter(struct task_struct *task, unsigned long filter_off,
+ struct seccomp_filter *filter;
+ struct sock_fprog_kern *fprog;
+ long ret;
++ struct user_namespace *user_ns = current_user_ns();
+
+- if (!capable(CAP_SYS_ADMIN) ||
++ if (in_userns(user_ns, task_cred_xxx(task, user_ns))) {
++ if (!ns_capable(user_ns, CAP_SYS_ADMIN))
++ return -EACCES;
++ } else if (!capable(CAP_SYS_ADMIN) ||
+ current->seccomp.mode != SECCOMP_MODE_DISABLED) {
+ return -EACCES;
+ }
diff --git a/internal/workflows/step.go b/internal/workflows/step.go
index 93d515ae..17ca25e1 100644
--- a/internal/workflows/step.go
+++ b/internal/workflows/step.go
@@ -68,7 +68,7 @@ func newTestsuite(name, prefix string) Step {
return Step{
Name: "Compile and run test suite",
Run: prefix + "rm -rf result && " +
- "go run -tags=testsuite ./test/" + name,
+ "go run -tags=testsuite ./cmd/" + name,
}
}
@@ -95,6 +95,6 @@ func newNixOSTest(name string) Step {
"--out-link result " +
"--print-out-paths " +
"--print-build-logs " +
- "./test/hakurei#checks.x86_64-linux." + name,
+ "./cmd/hakurei/testsuite#checks.x86_64-linux." + name,
}
}
diff --git a/internal/workflows/test.go b/internal/workflows/test.go
index bd74511c..41ed05c5 100644
--- a/internal/workflows/test.go
+++ b/internal/workflows/test.go
@@ -47,7 +47,7 @@ var _ = (&Workflow{
newCIRequest("distribution", "dist -o result", "dist"),
install,
- newTestsuite("sandbox", ""),
+ newTestsuite("hakurei/testsuite/sandbox", ""),
},
}},
@@ -70,7 +70,7 @@ var _ = (&Workflow{
newCIRequest("distribution", "race -o result", "dist"),
install,
- newTestsuite("sandbox", ""),
+ newTestsuite("hakurei/testsuite/sandbox", ""),
},
}},
@@ -101,7 +101,7 @@ var _ = (&Workflow{
"setuid=1023,setgid=1023 /sdcard",
},
- newTestsuite("sharefs", "sharefs -V && "),
+ newTestsuite("sharefs/testsuite", "sharefs -V && "),
newUploadArtifact("test output", "fs_mark"),
},
}},