Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/branch-e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -261,6 +261,7 @@ jobs:
test-matrix: >-
[
{"environment":"fedora-podman-rootful","installer":"binaries","testsuite":"driver-podman"},
{"environment":"fedora-podman-rootless","installer":"binaries","testsuite":"e2e-podman"},
{"environment":"fedora-podman-rootless","installer":"binaries","testsuite":"driver-podman"}
]

Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/prepare-integration-inputs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -106,6 +106,9 @@ jobs:
- name: Build test archives
run: nix run .#build-artifacts-test-archives

- name: Build test workload images
run: nix run .#build-artifacts-test-images

- name: Upload integration inputs
id: upload-integration-inputs
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
Expand Down
25 changes: 25 additions & 0 deletions TESTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -254,6 +254,31 @@ Rust tests that still apply. Run the Podman-backed Rust CLI e2e suite:
mise run e2e:podman
```

Run the portable subset in a disposable rootless Podman guest:

```shell
nix run .#build-artifacts
nix run .#tmachine -- test fedora-podman-rootless binaries e2e-podman
nix run .#tmachine -- test fedora-podman-rootless binaries driver-podman
```

Print the exact tmachine archive selection as a shell `PODMAN_CI_TESTS` array:

```shell
nix run .#generate-podman-e2e-ci-tests
```

The `e2e-podman` testsuite runs a nextest archive built with the corresponding
Rust feature and preloads its Python workload image into the rootless Podman
store. The separate `driver-podman` testsuite compares OpenShell and direct
Podman user-namespace mappings for the default, `auto`, `keep-id`, and private
profiles. The E2E archive excludes binaries that still depend on wrapper-owned
gateway controls, host fixtures, missing guest tools, or nondeterministic relay
setup. The `driver-podman` suite replaces the removed `podman_userns` E2E
binary. `tests/artifacts.nix` keeps the follow-up exclusions explicit and uses
the same filter for the generated inventory, so excluded binaries cannot appear
as false passes or silently re-enter the archive.

Run the VM-backed Rust CLI e2e suite:

```shell
Expand Down
5 changes: 0 additions & 5 deletions e2e/rust/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -113,11 +113,6 @@ name = "podman_resource_limits"
path = "tests/podman_resource_limits.rs"
required-features = ["e2e-podman"]

[[test]]
name = "podman_userns"
path = "tests/podman_userns.rs"
required-features = ["e2e-podman"]

[[test]]
name = "provider_refresh_handles"
path = "tests/provider_refresh_handles.rs"
Expand Down
26 changes: 20 additions & 6 deletions e2e/rust/tests/live_policy_update.rs
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,11 @@ use openshell_e2e::harness::output::{extract_field, strip_ansi};
use openshell_e2e::harness::sandbox::SandboxGuard;
use tempfile::NamedTempFile;

const SPARSE_POLICY: &str = include_str!(concat!(
env!("CARGO_MANIFEST_DIR"),
"/../../examples/policy-advisor/sandbox-policy.yaml"
));

// ---------------------------------------------------------------------------
// Policy YAML builders
// ---------------------------------------------------------------------------
Expand Down Expand Up @@ -126,6 +131,15 @@ landlock:
Ok(file)
}

fn write_sparse_policy() -> Result<NamedTempFile, String> {
let mut file = NamedTempFile::new().map_err(|e| format!("create temp policy file: {e}"))?;
file.write_all(SPARSE_POLICY.as_bytes())
.map_err(|e| format!("write temp policy file: {e}"))?;
file.flush()
.map_err(|e| format!("flush temp policy file: {e}"))?;
Ok(file)
}

// ---------------------------------------------------------------------------
// CLI helpers
// ---------------------------------------------------------------------------
Expand Down Expand Up @@ -629,18 +643,18 @@ async fn live_policy_update_from_empty_network_policies() {
/// no revision remaining `Pending` once the acknowledgement lands.
#[tokio::test]
async fn initial_sparse_policy_is_acknowledged_as_loaded() {
// Repo-relative path to the sparse network-only policy fixture.
let sparse_policy = concat!(
env!("CARGO_MANIFEST_DIR"),
"/../../examples/policy-advisor/sandbox-policy.yaml"
);
let sparse_policy = write_sparse_policy().expect("write sparse policy fixture");
let sparse_policy_path = sparse_policy
.path()
.to_str()
.expect("sparse policy path is not UTF-8");

let mut guard = SandboxGuard::create_keep_with_args(
&[
"--name",
"e2e-sparse-enrich",
"--policy",
sparse_policy,
sparse_policy_path,
"--no-tty",
],
&["sh", "-c", "echo Ready && sleep infinity"],
Expand Down
Loading
Loading