mirror of
https://github.com/containers/podman.git
synced 2025-10-25 18:25:59 +08:00
rootless: fix top
join the user namespace used to create the container so that psgo can work in the same way as with root containers. Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com> Closes: #1371 Approved by: rhatdan
This commit is contained in:
committed by
Atomic Bot
parent
1789242933
commit
2ed79f6315
@ -71,6 +71,7 @@ var _ = Describe("Podman rootless", func() {
|
||||
if err != nil {
|
||||
Skip("User namespaces not supported.")
|
||||
}
|
||||
canUseExec := canExec()
|
||||
|
||||
setup := podmanTest.Podman([]string{"create", ALPINE, "ls"})
|
||||
setup.WaitWithDefaultTimeout()
|
||||
@ -121,6 +122,22 @@ var _ = Describe("Podman rootless", func() {
|
||||
cmd.WaitWithDefaultTimeout()
|
||||
Expect(cmd.ExitCode()).To(Equal(0))
|
||||
|
||||
allArgs = append([]string{"run", "-d"}, args...)
|
||||
allArgs = append(allArgs, "--security-opt", "seccomp=unconfined", "--rootfs", mountPath, "top")
|
||||
cmd = podmanTest.PodmanAsUser(allArgs, 1000, 1000, env)
|
||||
cmd.WaitWithDefaultTimeout()
|
||||
Expect(cmd.ExitCode()).To(Equal(0))
|
||||
|
||||
if canUseExec {
|
||||
cmd = podmanTest.PodmanAsUser([]string{"top", "-l"}, 1000, 1000, env)
|
||||
cmd.WaitWithDefaultTimeout()
|
||||
Expect(cmd.ExitCode()).To(Equal(0))
|
||||
}
|
||||
|
||||
cmd = podmanTest.PodmanAsUser([]string{"rm", "-l", "-f"}, 1000, 1000, env)
|
||||
cmd.WaitWithDefaultTimeout()
|
||||
Expect(cmd.ExitCode()).To(Equal(0))
|
||||
|
||||
allArgs = append([]string{"run", "-d"}, args...)
|
||||
allArgs = append(allArgs, "--security-opt", "seccomp=unconfined", "--rootfs", mountPath, "unshare", "-r", "unshare", "-r", "top")
|
||||
cmd = podmanTest.PodmanAsUser(allArgs, 1000, 1000, env)
|
||||
@ -143,7 +160,7 @@ var _ = Describe("Podman rootless", func() {
|
||||
cmd.WaitWithDefaultTimeout()
|
||||
Expect(cmd.ExitCode()).To(Equal(0))
|
||||
|
||||
if !canExec() {
|
||||
if !canUseExec {
|
||||
Skip("ioctl(NS_GET_PARENT) not supported.")
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user