Skip to content

Run the test suite as root in CI and mark the install tests as needing root - #194

Merged
laffer1 merged 1 commit into
mainfrom
ci-run-tests-as-root
Sep 8, 2026
Merged

laffer1 merged 1 commit into
mainfrom
ci-run-tests-as-root

Conversation

@laffer1

@laffer1 laffer1 commented Sep 8, 2026 •

Copy link
Copy Markdown
Member

Problem

The CI job has never passed since mport_install_test was added in July. Every case there performs a real install into a scratch root, and installing chowns each extracted file to root:wheel (bundle_read_install_pkg.c:960). In ci.yml only the atf install step ran under sudo; kyua test ran as the unprivileged VM user, so all six cases failed with "Unable to set permissions on file". The latest run on main before #190 shows the same five failures and nothing else.

Change

  • ci.yml: run kyua test under sudo, so the install tests are actually exercised in CI.
  • tests/mport_install_test.c: declare require.user = root on each case, so an unprivileged local run reports them as skipped rather than failed.
  • libmport/mport_private.h: bump MPORT_VERSION to 2.8.2, since 2.8.1 is already released.

Verified

  • As root: all six cases pass under kyua.
  • As nobody, running the built program under kyua from a copy in /tmp: all six are reported skipped: Requires root privileges.
  • The precommit script reports only the pre-existing cppcheck warning on mport_install_test.c:115.

🤖 Generated with Claude Code

https://claude.ai/code/session_01VqVYKWFCX58Cb5NiGHHjzo

Summary by Sourcery

Run privileged installation tests correctly in CI and identify their root requirement while advancing the mport version.

Bug Fixes:

  • Run the install test suite with root privileges in CI so package installation cases can complete successfully.

Enhancements:

  • Mark all package installation tests as requiring root, allowing unprivileged runs to skip them cleanly.

CI:

  • Execute Kyua tests under sudo in the CI workflow.

Chores:

  • Bump the mport version to 2.8.2.

…g root

Every case in mport_install_test performs a real install into a scratch
root, and installing chowns each extracted file to root:wheel. The CI
job ran kyua as the unprivileged VM user, so all six cases failed with
"Unable to set permissions on file" on every run since the program was
added; only the atf install step used sudo. Run kyua under sudo so the
install tests are actually exercised, and declare require.user=root on
each case so an unprivileged local run reports them as skipped rather
than failed.

Bump MPORT_VERSION to 2.8.2; 2.8.1 has already been released.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VqVYKWFCX58Cb5NiGHHjzo
AI-Assisted-By: Claude Fable 5.1
@sourcery-ai

sourcery-ai Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

The PR aligns test execution with the install tests’ root requirement by running Kyua as root in CI and declaring root prerequisites on all six cases, while bumping the library version to 2.8.2.

Sequence diagram for root-required install tests in CI

sequenceDiagram
    participant CI as CI runner
    participant Kyua as kyua
    participant Tests as mport_install_test
    participant ScratchRoot as Scratch install root

    CI->>Kyua: sudo kyua test -k tests/Kyuafile
    Kyua->>Tests: run install test cases as root
    Tests->>ScratchRoot: install files and set root:wheel ownership
    ScratchRoot-->>Tests: installation succeeds
    Tests-->>Kyua: test results
Loading

Flow diagram for non-root handling of install tests

flowchart LR
    User[Unprivileged user] --> Kyua[kyua test]
    Kyua --> Requirement{require.user = root}
    Requirement -->|root unavailable| Skipped[Tests skipped]
    Requirement -->|running as root| Executed[Install tests execute]
Loading

File-Level Changes

Change Details Files
Run privileged install tests in CI and explicitly gate them on root privileges.
  • Execute the Kyua suite via sudo in the CI workflow.
  • Add ATF root requirements to all six install-related test cases so non-root runs skip them instead of failing.
.github/workflows/ci.yml
tests/mport_install_test.c
Bump the library version for the new release.
  • Update MPORT_VERSION from 2.8.1 to 2.8.2.
libmport/mport_private.h

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@github-actions

github-actions Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Claude finished @laffer1's task in 55s —— View job


Review: Run the test suite as root in CI (#194)

  • Gather context (diff, changed files)
  • Review .github/workflows/ci.yml change
  • Review tests/mport_install_test.c change
  • Review libmport/mport_private.h version bump
  • Post review feedback

Verdict: LGTM. Small, well-scoped fix; verified each claim against the diff and repo history.

.github/workflows/ci.yml — adding sudo to kyua test is correct and consistent with the earlier sudo mport install atf step in the same job. Since this is the job's only step (no separate kyua report/artifact-upload step reads the results afterward), root-owned kyua result files aren't a problem here.

tests/mport_install_test.c — confirmed all 6 ATF_TC_WITH_CLEANUP cases in the file (install_replaces_previous_os_release, install_same_os_release_is_rejected, force_reinstall_over_orphaned_rows, failed_install_registers_nothing, failed_delete_rolls_back, install_from_verified_fd) now carry require.user = root, and none were missed. This matches the PR's description that every case in this file does a real install into a scratch root under /tmp (TEST_ROOT_TEMPLATE), which chowns extracted files to root:wheel — the actual cause of the CI failures the PR fixes.

libmport/mport_private.h — bump to MPORT_VERSION "2.8.2" is justified; 2.8.1 is already tagged in repo history, so this avoids re-publishing under an existing version string.

No correctness, memory-safety, SQL-injection, or path-traversal concerns — this PR only adds test metadata annotations and a CI/version constant change, touching no runtime logic.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@laffer1
laffer1 merged commit c4d64d6 into main Sep 8, 2026
5 of 6 checks passed
@laffer1
laffer1 deleted the ci-run-tests-as-root branch September 8, 2026 21:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant