diff options
Diffstat (limited to 'internal/workflows')
| -rw-r--r-- | internal/workflows/doc.go | 4 | ||||
| -rw-r--r-- | internal/workflows/seccomp.patch | 18 | ||||
| -rw-r--r-- | internal/workflows/step.go | 4 | ||||
| -rw-r--r-- | internal/workflows/test.go | 6 |
4 files changed, 25 insertions, 7 deletions
diff --git a/internal/workflows/doc.go b/internal/workflows/doc.go index a8f18ab4..24e86b8c 100644 --- a/internal/workflows/doc.go +++ b/internal/workflows/doc.go @@ -126,8 +126,8 @@ first workflow job is started and re-populate it after every cmd/mbf update. # Configuring the kernel In order to attach to the container process, the sysctl kernel.yama.ptrace_scope -must be set to 0. After which, apply the patch test/sandbox/seccomp.patch to -your kernel sources, compile and install the new kernel. Refer to +must be set to 0. After which, apply the patch internal/workflows/seccomp.patch +to your kernel sources, compile and install the new kernel. Refer to https://wiki.alpinelinux.org/wiki/Custom_Kernel if the guest runs Alpine Linux. If running podman or docker as root, the patch is not required. Do not apply this patch on a system meant to be secure. diff --git a/internal/workflows/seccomp.patch b/internal/workflows/seccomp.patch new file mode 100644 index 00000000..ddabc71e --- /dev/null +++ b/internal/workflows/seccomp.patch @@ -0,0 +1,18 @@ +diff --git a/kernel/seccomp.c b/kernel/seccomp.c +index 25f62867a16d..7b63ccc8daf4 100644 +--- a/kernel/seccomp.c ++++ b/kernel/seccomp.c +@@ -2216,8 +2216,12 @@ long seccomp_get_filter(struct task_struct *task, unsigned long filter_off, + struct seccomp_filter *filter; + struct sock_fprog_kern *fprog; + long ret; ++ struct user_namespace *user_ns = current_user_ns(); + +- if (!capable(CAP_SYS_ADMIN) || ++ if (in_userns(user_ns, task_cred_xxx(task, user_ns))) { ++ if (!ns_capable(user_ns, CAP_SYS_ADMIN)) ++ return -EACCES; ++ } else if (!capable(CAP_SYS_ADMIN) || + current->seccomp.mode != SECCOMP_MODE_DISABLED) { + return -EACCES; + } diff --git a/internal/workflows/step.go b/internal/workflows/step.go index 93d515ae..17ca25e1 100644 --- a/internal/workflows/step.go +++ b/internal/workflows/step.go @@ -68,7 +68,7 @@ func newTestsuite(name, prefix string) Step { return Step{ Name: "Compile and run test suite", Run: prefix + "rm -rf result && " + - "go run -tags=testsuite ./test/" + name, + "go run -tags=testsuite ./cmd/" + name, } } @@ -95,6 +95,6 @@ func newNixOSTest(name string) Step { "--out-link result " + "--print-out-paths " + "--print-build-logs " + - "./test/hakurei#checks.x86_64-linux." + name, + "./cmd/hakurei/testsuite#checks.x86_64-linux." + name, } } diff --git a/internal/workflows/test.go b/internal/workflows/test.go index bd74511c..41ed05c5 100644 --- a/internal/workflows/test.go +++ b/internal/workflows/test.go @@ -47,7 +47,7 @@ var _ = (&Workflow{ newCIRequest("distribution", "dist -o result", "dist"), install, - newTestsuite("sandbox", ""), + newTestsuite("hakurei/testsuite/sandbox", ""), }, }}, @@ -70,7 +70,7 @@ var _ = (&Workflow{ newCIRequest("distribution", "race -o result", "dist"), install, - newTestsuite("sandbox", ""), + newTestsuite("hakurei/testsuite/sandbox", ""), }, }}, @@ -101,7 +101,7 @@ var _ = (&Workflow{ "setuid=1023,setgid=1023 /sdcard", }, - newTestsuite("sharefs", "sharefs -V && "), + newTestsuite("sharefs/testsuite", "sharefs -V && "), newUploadArtifact("test output", "fs_mark"), }, }}, |
