diff options
author | Ed Santiago <santiago@redhat.com> | 2020-07-29 13:26:02 -0600 |
---|---|---|
committer | Ed Santiago <santiago@redhat.com> | 2020-07-30 06:16:51 -0600 |
commit | 84f4b87c2e22afe0375c24936b1e6f15e731ea19 (patch) | |
tree | 906f6e8d4ae2c153caac0382cefb9f62bb583058 /test/system/030-run.bats | |
parent | 117043040e18e473f3b2142576303349238a36a7 (diff) | |
download | podman-84f4b87c2e22afe0375c24936b1e6f15e731ea19.tar.gz podman-84f4b87c2e22afe0375c24936b1e6f15e731ea19.tar.bz2 podman-84f4b87c2e22afe0375c24936b1e6f15e731ea19.zip |
System tests: new system-df and passwd tests
- New test for #6991 - passwd file is writable even when
run with --userns=keep-id
- Enable another keep-id test, commented out due to #6593
- New test for podman system df
Also, independently, removed this line:
apt-get -y upgrade conmon
...because it's causing CI failures, probably because of the
boothole CVE, probably because the Ubuntu grub update was
rushed out. I believe it is safe to remove this, because
both Ubuntu 19 and 20 report:
conmon is already the newest version (2.0.18~1).
Signed-off-by: Ed Santiago <santiago@redhat.com>
Diffstat (limited to 'test/system/030-run.bats')
-rw-r--r-- | test/system/030-run.bats | 16 |
1 files changed, 16 insertions, 0 deletions
diff --git a/test/system/030-run.bats b/test/system/030-run.bats index 04d1e4eac..b30c1103b 100644 --- a/test/system/030-run.bats +++ b/test/system/030-run.bats @@ -284,4 +284,20 @@ echo $rand | 0 | $rand is "$output" "root" "--user=0 overrides keep-id" } +# #6991 : /etc/passwd is modifiable +@test "podman run : --userns=keep-id: passwd file is modifiable" { + run_podman run -d --userns=keep-id $IMAGE sh -c 'while ! test -e /stop; do sleep 0.1; done' + cid="$output" + + gecos="$(random_string 6) $(random_string 8)" + run_podman exec --user root $cid adduser -D -g "$gecos" -s /bin/sh newuser3 + is "$output" "" "output from adduser" + run_podman exec $cid tail -1 /etc/passwd + is "$output" "newuser3:x:1000:1000:$gecos:/home/newuser3:/bin/sh" \ + "newuser3 added to /etc/passwd in container" + + run_podman exec $cid touch /stop + run_podman wait $cid +} + # vim: filetype=sh |