[1/2] testsuite: Support cleanup on rootless build files in test-container

Message ID 20260716124017.1480579-1-wzh@ilbers.de
State Superseded
Headers show
Series [1/2] testsuite: Support cleanup on rootless build files in test-container | expand

Commit Message

Zhihang Wei July 16, 2026, 12:40 p.m. UTC
When running tests with rootless builds, some files created with the user
namespace inside the container cannot be removed by the calling user after
the test-container exits without sudo. Add the `--clean-rootless-files`
option to the test-container entrypoint to clean up such files before
leaving the container.

The cleanup is only performed for rootless builds and only removes files
that cannot be cleaned up without sudo outside the container. Other build
artifacts are left untouched so they remain available for CI artifact
collection and post-test inspection.

Signed-off-by: Zhihang Wei <wzh@ilbers.de>
---
 .../dockerdata/test-container-entrypoint      | 38 +++++++++++++++++--
 1 file changed, 34 insertions(+), 4 deletions(-)

Comments

Felix Moessbauer July 16, 2026, 12:47 p.m. UTC | #1
On Thu, 2026-07-16 at 14:40 +0200, Zhihang Wei wrote:
> When running tests with rootless builds, some files created with the user
> namespace inside the container cannot be removed by the calling user after
> the test-container exits without sudo. Add the `--clean-rootless-files`
> option to the test-container entrypoint to clean up such files before
> leaving the container.
> 
> The cleanup is only performed for rootless builds and only removes files
> that cannot be cleaned up without sudo outside the container. Other build
> artifacts are left untouched so they remain available for CI artifact
> collection and post-test inspection.
> 
> Signed-off-by: Zhihang Wei <wzh@ilbers.de>
> ---
>  .../dockerdata/test-container-entrypoint      | 38 +++++++++++++++++--
>  1 file changed, 34 insertions(+), 4 deletions(-)
> 
> diff --git a/testsuite/dockerdata/test-container-entrypoint b/testsuite/dockerdata/test-container-entrypoint
> index e4714942..9bddbb18 100755
> --- a/testsuite/dockerdata/test-container-entrypoint
> +++ b/testsuite/dockerdata/test-container-entrypoint
> @@ -17,6 +17,8 @@ else
>  	shift 1
>  fi
>  
> +clean_rootless_files=0
> +
>  export args="--max-parallel-tasks=1 --disable-sysinfo"
>  for arg in $*; do
>  	case "$arg" in
> @@ -29,15 +31,19 @@ for arg in $*; do
>  	--shell)
>  		export start_shell=1
>  		;;
> +	--clean-rootless-files)
> +		clean_rootless_files=1
> +		;;
>  	--help)
>  		cat <<EOF
>  Usage: run-tests.sh [params] ...
>  
>  Supported parameters:
> -  --clean		Purge results of previous test runs before starting.
> -  --debug		Use '--show=app,test' log settings for avocado.
> -  --shell		Drop into shell rather than starting tests.
> -  --help		Show this help message.
> +  --clean					Purge results of previous test runs before starting.
> +  --debug					Use '--show=app,test' log settings for avocado.
> +  --shell					Drop into shell rather than starting tests.
> +  --clean-rootless-files	Clean up files created by rootless builds with unshare after the tests finish. 
> +  --help					Show this help message.
>  
>  Any other parameters are passed to "avocado run". Its usage is:
>  
> @@ -59,6 +65,15 @@ case "$args" in
>  	;;
>  esac
>  
> +case "$args" in
> +	*"-p rootless=1"*)
> +		;;
> +	*)
> +		clean_rootless_files=0
> +		;;
> +esac
> +export clean_rootless_files
> +
>  mkdir /isar
>  
>  busybox syslogd
> @@ -72,6 +87,21 @@ echo exit | /container-entrypoint
>  gosu builder sh -c '
>  set -e
>  
> +cleanup_rootless_files()
> +{
> +	rc=$?
> +
> +	if [ "${clean_rootless_files}" = 1 ]; then
> +		find build \
> +			\( ! -user "$(whoami)" -type d -prune \) \
> +			-exec unshare --map-auto --map-root-user --keep-caps rm -rf {} \;

We can reuse the ./scripts/isar-clean-builddir script which was written
exactly for cleaning up the leftover files.

Apart from that, the change is fine.

Felix

> +	fi
> +
> +	exit ${rc}
> +}
> +
> +trap cleanup_rootless_files EXIT
> +
>  base_dir=/work/build/testsuite
>  
>  mkdir -p ${base_dir}/overlay/upper
> -- 
> 2.39.5
> 
> -- 
> You received this message because you are subscribed to the Google Groups "isar-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
> To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260716124017.1480579-1-wzh%40ilbers.de.
Zhihang Wei July 16, 2026, 1:06 p.m. UTC | #2
On 7/16/26 14:47, MOESSBAUER, Felix wrote:
> On Thu, 2026-07-16 at 14:40 +0200, Zhihang Wei wrote:
>> When running tests with rootless builds, some files created with the user
>> namespace inside the container cannot be removed by the calling user after
>> the test-container exits without sudo. Add the `--clean-rootless-files`
>> option to the test-container entrypoint to clean up such files before
>> leaving the container.
>>
>> The cleanup is only performed for rootless builds and only removes files
>> that cannot be cleaned up without sudo outside the container. Other build
>> artifacts are left untouched so they remain available for CI artifact
>> collection and post-test inspection.
>>
>> Signed-off-by: Zhihang Wei <wzh@ilbers.de>
>> ---
>>   .../dockerdata/test-container-entrypoint      | 38 +++++++++++++++++--
>>   1 file changed, 34 insertions(+), 4 deletions(-)
>>
>> diff --git a/testsuite/dockerdata/test-container-entrypoint b/testsuite/dockerdata/test-container-entrypoint
>> index e4714942..9bddbb18 100755
>> --- a/testsuite/dockerdata/test-container-entrypoint
>> +++ b/testsuite/dockerdata/test-container-entrypoint
>> @@ -17,6 +17,8 @@ else
>>   	shift 1
>>   fi
>>   
>> +clean_rootless_files=0
>> +
>>   export args="--max-parallel-tasks=1 --disable-sysinfo"
>>   for arg in $*; do
>>   	case "$arg" in
>> @@ -29,15 +31,19 @@ for arg in $*; do
>>   	--shell)
>>   		export start_shell=1
>>   		;;
>> +	--clean-rootless-files)
>> +		clean_rootless_files=1
>> +		;;
>>   	--help)
>>   		cat <<EOF
>>   Usage: run-tests.sh [params] ...
>>   
>>   Supported parameters:
>> -  --clean		Purge results of previous test runs before starting.
>> -  --debug		Use '--show=app,test' log settings for avocado.
>> -  --shell		Drop into shell rather than starting tests.
>> -  --help		Show this help message.
>> +  --clean					Purge results of previous test runs before starting.
>> +  --debug					Use '--show=app,test' log settings for avocado.
>> +  --shell					Drop into shell rather than starting tests.
>> +  --clean-rootless-files	Clean up files created by rootless builds with unshare after the tests finish.
>> +  --help					Show this help message.
>>   
>>   Any other parameters are passed to "avocado run". Its usage is:
>>   
>> @@ -59,6 +65,15 @@ case "$args" in
>>   	;;
>>   esac
>>   
>> +case "$args" in
>> +	*"-p rootless=1"*)
>> +		;;
>> +	*)
>> +		clean_rootless_files=0
>> +		;;
>> +esac
>> +export clean_rootless_files
>> +
>>   mkdir /isar
>>   
>>   busybox syslogd
>> @@ -72,6 +87,21 @@ echo exit | /container-entrypoint
>>   gosu builder sh -c '
>>   set -e
>>   
>> +cleanup_rootless_files()
>> +{
>> +	rc=$?
>> +
>> +	if [ "${clean_rootless_files}" = 1 ]; then
>> +		find build \
>> +			\( ! -user "$(whoami)" -type d -prune \) \
>> +			-exec unshare --map-auto --map-root-user --keep-caps rm -rf {} \;
> We can reuse the ./scripts/isar-clean-builddir script which was written
> exactly for cleaning up the leftover files.
>
> Apart from that, the change is fine.
>
> Felix

Hi Felix,

This part was borrowed from your isar-clean-builddir script. But here I want
to keep the logs and build artifacts.

Thinking about it more: the files with different ownership are only in 
rootfs
dirs. Maybe I can reuse the script to clean up rootfs only. Let me try.

v8 unprivileged is on CI, we'll merge once it passes.

Zhihang

>
>> +	fi
>> +
>> +	exit ${rc}
>> +}
>> +
>> +trap cleanup_rootless_files EXIT
>> +
>>   base_dir=/work/build/testsuite
>>   
>>   mkdir -p ${base_dir}/overlay/upper
>> -- 
>> 2.39.5
>>
>> -- 
>> You received this message because you are subscribed to the Google Groups "isar-users" group.
>> To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
>> To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260716124017.1480579-1-wzh%40ilbers.de.
Felix Moessbauer July 16, 2026, 1:29 p.m. UTC | #3
On Thu, 2026-07-16 at 15:06 +0200, Zhihang Wei wrote:
> On 7/16/26 14:47, MOESSBAUER, Felix wrote:
> > On Thu, 2026-07-16 at 14:40 +0200, Zhihang Wei wrote:
> > > When running tests with rootless builds, some files created with the user
> > > namespace inside the container cannot be removed by the calling user after
> > > the test-container exits without sudo. Add the `--clean-rootless-files`
> > > option to the test-container entrypoint to clean up such files before
> > > leaving the container.
> > > 
> > > The cleanup is only performed for rootless builds and only removes files
> > > that cannot be cleaned up without sudo outside the container. Other build
> > > artifacts are left untouched so they remain available for CI artifact
> > > collection and post-test inspection.
> > > 
> > > Signed-off-by: Zhihang Wei <wzh@ilbers.de>
> > > ---
> > >   .../dockerdata/test-container-entrypoint      | 38 +++++++++++++++++--
> > >   1 file changed, 34 insertions(+), 4 deletions(-)
> > > 
> > > diff --git a/testsuite/dockerdata/test-container-entrypoint b/testsuite/dockerdata/test-container-entrypoint
> > > index e4714942..9bddbb18 100755
> > > --- a/testsuite/dockerdata/test-container-entrypoint
> > > +++ b/testsuite/dockerdata/test-container-entrypoint
> > > @@ -17,6 +17,8 @@ else
> > >   	shift 1
> > >   fi
> > >   
> > > +clean_rootless_files=0
> > > +
> > >   export args="--max-parallel-tasks=1 --disable-sysinfo"
> > >   for arg in $*; do
> > >   	case "$arg" in
> > > @@ -29,15 +31,19 @@ for arg in $*; do
> > >   	--shell)
> > >   		export start_shell=1
> > >   		;;
> > > +	--clean-rootless-files)
> > > +		clean_rootless_files=1
> > > +		;;
> > >   	--help)
> > >   		cat <<EOF
> > >   Usage: run-tests.sh [params] ...
> > >   
> > >   Supported parameters:
> > > -  --clean		Purge results of previous test runs before starting.
> > > -  --debug		Use '--show=app,test' log settings for avocado.
> > > -  --shell		Drop into shell rather than starting tests.
> > > -  --help		Show this help message.
> > > +  --clean					Purge results of previous test runs before starting.
> > > +  --debug					Use '--show=app,test' log settings for avocado.
> > > +  --shell					Drop into shell rather than starting tests.
> > > +  --clean-rootless-files	Clean up files created by rootless builds with unshare after the tests finish.
> > > +  --help					Show this help message.
> > >   
> > >   Any other parameters are passed to "avocado run". Its usage is:
> > >   
> > > @@ -59,6 +65,15 @@ case "$args" in
> > >   	;;
> > >   esac
> > >   
> > > +case "$args" in
> > > +	*"-p rootless=1"*)
> > > +		;;
> > > +	*)
> > > +		clean_rootless_files=0
> > > +		;;
> > > +esac
> > > +export clean_rootless_files
> > > +
> > >   mkdir /isar
> > >   
> > >   busybox syslogd
> > > @@ -72,6 +87,21 @@ echo exit | /container-entrypoint
> > >   gosu builder sh -c '
> > >   set -e
> > >   
> > > +cleanup_rootless_files()
> > > +{
> > > +	rc=$?
> > > +
> > > +	if [ "${clean_rootless_files}" = 1 ]; then
> > > +		find build \
> > > +			\( ! -user "$(whoami)" -type d -prune \) \
> > > +			-exec unshare --map-auto --map-root-user --keep-caps rm -rf {} \;
> > We can reuse the ./scripts/isar-clean-builddir script which was written
> > exactly for cleaning up the leftover files.
> > 
> > Apart from that, the change is fine.
> > 
> > Felix
> 
> Hi Felix,
> 
> This part was borrowed from your isar-clean-builddir script. But here I want
> to keep the logs and build artifacts.
> 
> Thinking about it more: the files with different ownership are only in 
> rootfs
> dirs. Maybe I can reuse the script to clean up rootfs only. Let me try.

Makes sense. I'm wondering if we better just call that script instead
of the rm -rf {}:

find ... -exec ./scripts/isar-clean-builddir {} \;

The unshare mapping might change in the future (I hope not, but who
knows) and we don't want to maintain that all over the place.

> 
> v8 unprivileged is on CI, we'll merge once it passes.

Sounds good. Thanks for keeping up with this.

Cheers!
Felix

> 
> Zhihang
> 
> > 
> > > +	fi
> > > +
> > > +	exit ${rc}
> > > +}
> > > +
> > > +trap cleanup_rootless_files EXIT
> > > +
> > >   base_dir=/work/build/testsuite
> > >   
> > >   mkdir -p ${base_dir}/overlay/upper
> > > -- 
> > > 2.39.5
> > > 
> > > -- 
> > > You received this message because you are subscribed to the Google Groups "isar-users" group.
> > > To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
> > > To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260716124017.1480579-1-wzh%40ilbers.de.

Patch

diff --git a/testsuite/dockerdata/test-container-entrypoint b/testsuite/dockerdata/test-container-entrypoint
index e4714942..9bddbb18 100755
--- a/testsuite/dockerdata/test-container-entrypoint
+++ b/testsuite/dockerdata/test-container-entrypoint
@@ -17,6 +17,8 @@  else
 	shift 1
 fi
 
+clean_rootless_files=0
+
 export args="--max-parallel-tasks=1 --disable-sysinfo"
 for arg in $*; do
 	case "$arg" in
@@ -29,15 +31,19 @@  for arg in $*; do
 	--shell)
 		export start_shell=1
 		;;
+	--clean-rootless-files)
+		clean_rootless_files=1
+		;;
 	--help)
 		cat <<EOF
 Usage: run-tests.sh [params] ...
 
 Supported parameters:
-  --clean		Purge results of previous test runs before starting.
-  --debug		Use '--show=app,test' log settings for avocado.
-  --shell		Drop into shell rather than starting tests.
-  --help		Show this help message.
+  --clean					Purge results of previous test runs before starting.
+  --debug					Use '--show=app,test' log settings for avocado.
+  --shell					Drop into shell rather than starting tests.
+  --clean-rootless-files	Clean up files created by rootless builds with unshare after the tests finish. 
+  --help					Show this help message.
 
 Any other parameters are passed to "avocado run". Its usage is:
 
@@ -59,6 +65,15 @@  case "$args" in
 	;;
 esac
 
+case "$args" in
+	*"-p rootless=1"*)
+		;;
+	*)
+		clean_rootless_files=0
+		;;
+esac
+export clean_rootless_files
+
 mkdir /isar
 
 busybox syslogd
@@ -72,6 +87,21 @@  echo exit | /container-entrypoint
 gosu builder sh -c '
 set -e
 
+cleanup_rootless_files()
+{
+	rc=$?
+
+	if [ "${clean_rootless_files}" = 1 ]; then
+		find build \
+			\( ! -user "$(whoami)" -type d -prune \) \
+			-exec unshare --map-auto --map-root-user --keep-caps rm -rf {} \;
+	fi
+
+	exit ${rc}
+}
+
+trap cleanup_rootless_files EXIT
+
 base_dir=/work/build/testsuite
 
 mkdir -p ${base_dir}/overlay/upper