test(oci): share OCI USER and WORKDIR checks across Docker and Podman - #3931
matthewgrossman wants to merge 3 commits into
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
🌿 Preview your docs: https://nvidia-preview-pr-3931.docs.buildwithfern.com/openshell |
|
/ok to test 2fed032 |
|
Label |
|
This is great! Thanks. One expectation I had (related to #3712) would be that at least some of the tests in I don't think that that file should be removed entirely because it also includes tests for other behaviour. |
| ]) | ||
| .await | ||
| .map_err(|error| error.to_string())?; | ||
| if create.success() || create.stdout().contains("should-not-run") { |
There was a problem hiding this comment.
Any sandbox-creation failure currently passes this scenario, so an unrelated provisioning regression could produce a false success. Require the failure to identify workspace validation—preferably through a structured error, or otherwise through a stable WorkspaceValidationFailed/WorkingDir diagnostic.
33f5e2d to
9bf8773
Compare
9bf8773 to
e65a902
Compare
e65a902 to
f184d63
Compare
|
The shared Docker/Podman OCI suite would also be a useful place to pin the image identity contract discussed in #4030. Could we extend the scenarios to cover:
Each case should run on the existing Docker rootful, Podman rootful, and Podman rootless lanes. These assertions can cover the current behavior without waiting for #4030's diagnostic changes. Detailed rejection provenance belongs in resolver tests, and once-only interactive failure output needs a real PTY test alongside the #4030 fix. |
Add an oci-image feature testsuite that runs against installed artifacts. It covers custom WORKDIR placement, image content and ownership, workspace writes from the main process and exec, file transfer including directory-merge upload, OCI user identity, the managed /sandbox fallback, and rejection of an unwritable WORKDIR. CI runs the suite on the Docker rootful, Podman rootful, and Podman rootless tmachine guests. Replace the Docker-only custom_image e2e with the shared suite. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
…lback The unwritable WORKDIR scenario now requires the WorkspaceValidationFailed reason, so unrelated provisioning failures cannot pass it. The numeric USER scenario supplies a policy without a process section, so the image USER is the only source of the sandbox identity. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
The oci-image feature suite covers the sandbox identity seen by the main process and sandbox exec on Docker and Podman. The Podman e2e keeps the checks only it can make: the pinned image ID and the isolated workload/supervisor container pair. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
f184d63 to
7658c9f
Compare
|
/ok to test 7658c9f |
Summary
An image's
USERandWORKDIRshould set the sandbox's identity and workspace the same way whether a gateway uses Docker or Podman. This PR moves the existing Docker-only image checks into a shared test suite that runs through the installed OpenShell CLI, and runs it on Docker rootful, Podman rootful, and Podman rootless in CI.This is the last of four stacked PRs split out of #3801: #3979 (remove unreachable sandbox code) ← #3981 (Podman workspace volume ownership) ← #3982 (Podman OCI
WORKDIR) ← this PR. The fixes come first so each PR passes its own tests. The suite checks behavior that #3981 and #3982 add on Podman, and theWorkspaceValidationFailedreason that #3982 adds.Why this matters
Until now, a Docker-only e2e test checked what happens when an image chooses a user and a working directory. It could not catch a Podman regression in the same behavior, and it did not exercise the installed release artifacts. The new suite builds test images beside the gateway and checks that the sandbox starts as the right user, can write in its workspace, preserves image files, transfers files to the right place, and refuses a directory the user cannot write.
Related Issue
Related to #2526 (fixed by #3982). This responds to review point 3 on #3801 (run shared OCI checks against installed artifacts on each runtime) and to review feedback on this PR.
Changes
tests/suites/features/oci-imagecrate with four scenarios that run through the candidate CLI:USERwith a customWORKDIR: identity, working directory, root-owned image content left unchanged, writes from the main process andsandbox exec, upload/download relative to the workspace, and a directory upload that merges into an existing directoryUSERwhoseWORKDIRparents are private (0700) to that user. The scenario supplies a policy with noprocesssection, so the imageUSERis the only source of the sandbox identity (moved here frompodman_oci_identity).WORKDIRand no/sandboxin the image: falls back to the managed/sandboxworkspaceWORKDIRthe image user can't write: sandbox creation fails withWorkspaceValidationFailedbefore the command runsoci-imagetestsuite intests/config.nix,ociImageArchive/build-oci-image-test-archiveintests/artifacts.nix, and thetests/ansible/playbooks/features/oci-image.yamlplaybook. The playbook picksdocker,podman, orsudo -n podmanso images are built into the store the gateway reads.oci-imageonubuntu-docker-rootful,fedora-podman-rootful, andfedora-podman-rootlessto the feature-specific matrix inbranch-e2e.yml,release-dev.yml, andrelease-tag.yml.e2e/rust/tests/custom_image.rsand its[[test]]entry; the suite covers everything it checked, including the directory-merge upload.podman_oci_identityto the checks only Podman can make: the pinned image ID and the isolated workload/supervisor container pair (users, capabilities, networking, mounts). The shared suite now covers the identity that the main process andsandbox execsee, on both runtimes.TESTING.md.Testing
mise run pre-commitpassescargo fmt --checkandcargo clippy --all-targets -D warningspass foropenshell-test-feature-oci-image;openshell-e2estill builds after removingcustom_imagetests/artifacts.nixandtests/config.nixparse (nix-instantiate --parse). I couldn't evaluate the flake locally because fetching flake inputs failed TLS verification in this environment.e2e/with-podman-gateway.sh), including theWorkspaceValidationFailedassertion. The trimmedpodman_oci_identitypasses.ubuntu-docker-rootful/oci-imageCI lane is the Docker check.Checklist
TESTING.md