Skip to content

Commit 98cd6bb

Browse files
committed
fix(testing): prepare native shell isolation on Linux
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
1 parent 82c04e0 commit 98cd6bb

2 files changed

Lines changed: 21 additions & 0 deletions

File tree

‎.github/workflows/python-tests.yml‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -284,6 +284,23 @@ jobs:
284284
run: |
285285
python -m pip install --disable-pip-version-check -e ".[test]"
286286
npm ci --ignore-scripts
287+
- name: Prepare native shell isolation
288+
# Ubuntu 24.04 may need an executable-scoped userns profile for bwrap.
289+
# Do not disable AppArmor or the system-wide unprivileged-userns guard.
290+
run: |
291+
sudo apt-get update
292+
sudo apt-get install -y bubblewrap
293+
if ! bwrap --unshare-all --ro-bind / / /bin/true; then
294+
sudo tee /etc/apparmor.d/loopx-qualification-bwrap >/dev/null <<'PROFILE'
295+
abi <abi/4.0>,
296+
include <tunables/global>
297+
profile loopx-qualification-bwrap /usr/bin/bwrap flags=(unconfined) {
298+
userns,
299+
}
300+
PROFILE
301+
sudo apparmor_parser -r /etc/apparmor.d/loopx-qualification-bwrap
302+
fi
303+
bwrap --unshare-all --ro-bind / / /bin/true
287304
- name: Run test shard
288305
# Split the whole collection, not a hand-maintained list of directories.
289306
# Without timing history least_duration alternates equal-weight tests.

‎loopx/control_plane/testing/vision_shell_host.py‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -99,6 +99,10 @@ def _sandbox(self) -> list[str]:
9999
argv = [str(shutil.which("bwrap")), "--unshare-all", "--die-with-parent", "--new-session", "--proc", "/proc", "--dev", "/dev"]
100100
for path in dict.fromkeys(readable):
101101
argv += ["--ro-bind", str(path), str(path)]
102+
# usr-merged Linux needs the original loader and shell aliases too.
103+
for name in ("/bin", "/sbin", "/lib", "/lib64"):
104+
if Path(name).is_symlink():
105+
argv += ["--symlink", os.readlink(name), name]
102106
argv += ["--bind", str(self.project), str(self.project)]
103107
for path in self.originals:
104108
argv += ["--ro-bind", str(path), str(path)]

0 commit comments

Comments
 (0)