From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: Stefan Agner Date: Fri, 5 Aug 2022 13:03:21 +0200 Subject: [PATCH] Add integration tests for device updates Signed-off-by: Stefan Agner --- tests/integration/update.bats | 62 +++++++++++++++++++++++++++++++++++ 1 file changed, 62 insertions(+) diff --git a/tests/integration/update.bats b/tests/integration/update.bats index 68e0fdd3..4478a7dd 100644 --- a/tests/integration/update.bats +++ b/tests/integration/update.bats @@ -854,6 +854,68 @@ EOF [ -z "$(<"$CONTAINER_OUTPUT")" ] } +@test "update devices" { + requires root + + # Create a container without access to /dev/kmsg. Verify that accessing fails + # and update the container to add access from it. + # + # Finally, remove access again by passing an empty array of devices. + update_config ' .linux.resources.devices = [{"allow": false, "access": "rwm"}] + | .linux.devices = [{"path": "/dev/kmsg", "type": "c", "major": 1, "minor": 11}] + | .process.capabilities.bounding += ["CAP_SYSLOG"] + | .process.capabilities.effective += ["CAP_SYSLOG"] + | .process.capabilities.inheritable += ["CAP_SYSLOG"] + | .process.capabilities.permitted += ["CAP_SYSLOG"]' + + # Run the container in the background. + runc run -d --console-socket "$CONSOLE_SOCKET" test_update_devices + [ "$status" -eq 0 ] + + runc exec test_update_devices head -c 100 /dev/kmsg + [ "$status" -eq 1 ] + + # Make sure default devices still work + runc exec test_update_devices cat /dev/null + [ "$status" -eq 0 ] + + runc update --resources - test_update_devices <