mirror of
https://github.com/containers/podman.git
synced 2025-06-20 17:13:43 +08:00
test: add --rm to podman run commands
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
This commit is contained in:
@ -17,7 +17,7 @@ function _require_crun() {
|
|||||||
skip_if_rootless "chroot is not allowed in rootless mode"
|
skip_if_rootless "chroot is not allowed in rootless mode"
|
||||||
skip_if_remote "--group-add keep-groups not supported in remote mode"
|
skip_if_remote "--group-add keep-groups not supported in remote mode"
|
||||||
_require_crun
|
_require_crun
|
||||||
run chroot --groups 1234 / ${PODMAN} run --uidmap 0:200000:5000 --group-add keep-groups $IMAGE id
|
run chroot --groups 1234 / ${PODMAN} run --rm --uidmap 0:200000:5000 --group-add keep-groups $IMAGE id
|
||||||
is "$output" ".*65534(nobody)" "Check group leaked into user namespace"
|
is "$output" ".*65534(nobody)" "Check group leaked into user namespace"
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -25,30 +25,30 @@ function _require_crun() {
|
|||||||
skip_if_rootless "chroot is not allowed in rootless mode"
|
skip_if_rootless "chroot is not allowed in rootless mode"
|
||||||
skip_if_remote "--group-add keep-groups not supported in remote mode"
|
skip_if_remote "--group-add keep-groups not supported in remote mode"
|
||||||
_require_crun
|
_require_crun
|
||||||
run chroot --groups 1234,5678 / ${PODMAN} run --group-add keep-groups $IMAGE id
|
run chroot --groups 1234,5678 / ${PODMAN} run --rm --group-add keep-groups $IMAGE id
|
||||||
is "$output" ".*1234" "Check group leaked into container"
|
is "$output" ".*1234" "Check group leaked into container"
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "podman --group-add without keep-groups while in a userns" {
|
@test "podman --group-add without keep-groups while in a userns" {
|
||||||
skip_if_rootless "chroot is not allowed in rootless mode"
|
skip_if_rootless "chroot is not allowed in rootless mode"
|
||||||
skip_if_remote "--group-add keep-groups not supported in remote mode"
|
skip_if_remote "--group-add keep-groups not supported in remote mode"
|
||||||
run chroot --groups 1234,5678 / ${PODMAN} run --uidmap 0:200000:5000 --group-add 457 $IMAGE id
|
run chroot --groups 1234,5678 / ${PODMAN} run --rm --uidmap 0:200000:5000 --group-add 457 $IMAGE id
|
||||||
is "$output" ".*457" "Check group leaked into container"
|
is "$output" ".*457" "Check group leaked into container"
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "podman --remote --group-add keep-groups " {
|
@test "podman --remote --group-add keep-groups " {
|
||||||
if is_remote; then
|
if is_remote; then
|
||||||
run_podman 125 run --group-add keep-groups $IMAGE id
|
run_podman 125 run --rm --group-add keep-groups $IMAGE id
|
||||||
is "$output" ".*not supported in remote mode" "Remote check --group-add keep-groups"
|
is "$output" ".*not supported in remote mode" "Remote check --group-add keep-groups"
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "podman --group-add without keep-groups " {
|
@test "podman --group-add without keep-groups " {
|
||||||
run_podman run --group-add 457 $IMAGE id
|
run_podman run --rm --group-add 457 $IMAGE id
|
||||||
is "$output" ".*457" "Check group leaked into container"
|
is "$output" ".*457" "Check group leaked into container"
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "podman --group-add keep-groups plus added groups " {
|
@test "podman --group-add keep-groups plus added groups " {
|
||||||
run_podman 125 run --group-add keep-groups --group-add 457 $IMAGE id
|
run_podman 125 run --rm --group-add keep-groups --group-add 457 $IMAGE id
|
||||||
is "$output" ".*the '--group-add keep-groups' option is not allowed with any other --group-add options" "Check group leaked into container"
|
is "$output" ".*the '--group-add keep-groups' option is not allowed with any other --group-add options" "Check group leaked into container"
|
||||||
}
|
}
|
||||||
|
Reference in New Issue
Block a user