summaryrefslogtreecommitdiff
path: root/test/e2e/run_seccomp_test.go
diff options
context:
space:
mode:
authorOpenShift Merge Robot <openshift-merge-robot@users.noreply.github.com>2020-11-17 22:42:21 +0100
committerGitHub <noreply@github.com>2020-11-17 22:42:21 +0100
commit0f745272e79daa496e541ff18bc6e21339559f38 (patch)
treefdb9285047a73f6516796f97969c237f359b1194 /test/e2e/run_seccomp_test.go
parent770b03a50cbffbf1ad1d40a8c9ea72860727acea (diff)
parentd4446501f3245a87a605bea403710954f0400fb5 (diff)
downloadpodman-0f745272e79daa496e541ff18bc6e21339559f38.tar.gz
podman-0f745272e79daa496e541ff18bc6e21339559f38.tar.bz2
podman-0f745272e79daa496e541ff18bc6e21339559f38.zip
Merge pull request #8381 from Luap99/rename-test-files
Rename e2e test files to include _test.go suffix
Diffstat (limited to 'test/e2e/run_seccomp_test.go')
-rw-r--r--test/e2e/run_seccomp_test.go68
1 files changed, 68 insertions, 0 deletions
diff --git a/test/e2e/run_seccomp_test.go b/test/e2e/run_seccomp_test.go
new file mode 100644
index 000000000..7d04cc60a
--- /dev/null
+++ b/test/e2e/run_seccomp_test.go
@@ -0,0 +1,68 @@
+package integration
+
+import (
+ "os"
+
+ . "github.com/containers/podman/v2/test/utils"
+ . "github.com/onsi/ginkgo"
+ . "github.com/onsi/gomega"
+)
+
+var _ = Describe("Podman run", func() {
+ var (
+ tempdir string
+ err error
+ podmanTest *PodmanTestIntegration
+ )
+
+ BeforeEach(func() {
+ tempdir, err = CreateTempDirInTempDir()
+ if err != nil {
+ os.Exit(1)
+ }
+ podmanTest = PodmanTestCreate(tempdir)
+ podmanTest.Setup()
+ podmanTest.SeedImages()
+ })
+
+ AfterEach(func() {
+ podmanTest.Cleanup()
+ f := CurrentGinkgoTestDescription()
+ processTestResult(f)
+
+ })
+
+ It("podman run --seccomp-policy default", func() {
+ session := podmanTest.Podman([]string{"run", "--seccomp-policy", "default", alpineSeccomp, "ls"})
+ session.WaitWithDefaultTimeout()
+ Expect(session.ExitCode()).To(Equal(0))
+ })
+
+ It("podman run --seccomp-policy ''", func() {
+ // Empty string is interpreted as "default".
+ session := podmanTest.Podman([]string{"run", "--seccomp-policy", "", alpineSeccomp, "ls"})
+ session.WaitWithDefaultTimeout()
+ Expect(session.ExitCode()).To(Equal(0))
+ })
+
+ It("podman run --seccomp-policy invalid", func() {
+ session := podmanTest.Podman([]string{"run", "--seccomp-policy", "invalid", alpineSeccomp, "ls"})
+ session.WaitWithDefaultTimeout()
+ Expect(session.ExitCode()).ToNot(Equal(0))
+ })
+
+ It("podman run --seccomp-policy image (block all syscalls)", func() {
+ session := podmanTest.Podman([]string{"run", "--seccomp-policy", "image", alpineSeccomp, "ls"})
+ session.WaitWithDefaultTimeout()
+ // TODO: we're getting a "cannot start a container that has
+ // stopped" error which seems surprising. Investigate
+ // why that is so.
+ Expect(session.ExitCode()).ToNot(Equal(0))
+ })
+
+ It("podman run --seccomp-policy image (bogus profile)", func() {
+ session := podmanTest.Podman([]string{"run", "--seccomp-policy", "image", alpineBogusSeccomp, "ls"})
+ session.WaitWithDefaultTimeout()
+ Expect(session.ExitCode()).To(Equal(125))
+ })
+})