| Message ID | 20260716124017.1480579-1-wzh@ilbers.de |
|---|---|
| State | Superseded |
| Headers | show |
| Series | [1/2] testsuite: Support cleanup on rootless build files in test-container | expand |
On Thu, 2026-07-16 at 14:40 +0200, Zhihang Wei wrote: > When running tests with rootless builds, some files created with the user > namespace inside the container cannot be removed by the calling user after > the test-container exits without sudo. Add the `--clean-rootless-files` > option to the test-container entrypoint to clean up such files before > leaving the container. > > The cleanup is only performed for rootless builds and only removes files > that cannot be cleaned up without sudo outside the container. Other build > artifacts are left untouched so they remain available for CI artifact > collection and post-test inspection. > > Signed-off-by: Zhihang Wei <wzh@ilbers.de> > --- > .../dockerdata/test-container-entrypoint | 38 +++++++++++++++++-- > 1 file changed, 34 insertions(+), 4 deletions(-) > > diff --git a/testsuite/dockerdata/test-container-entrypoint b/testsuite/dockerdata/test-container-entrypoint > index e4714942..9bddbb18 100755 > --- a/testsuite/dockerdata/test-container-entrypoint > +++ b/testsuite/dockerdata/test-container-entrypoint > @@ -17,6 +17,8 @@ else > shift 1 > fi > > +clean_rootless_files=0 > + > export args="--max-parallel-tasks=1 --disable-sysinfo" > for arg in $*; do > case "$arg" in > @@ -29,15 +31,19 @@ for arg in $*; do > --shell) > export start_shell=1 > ;; > + --clean-rootless-files) > + clean_rootless_files=1 > + ;; > --help) > cat <<EOF > Usage: run-tests.sh [params] ... > > Supported parameters: > - --clean Purge results of previous test runs before starting. > - --debug Use '--show=app,test' log settings for avocado. > - --shell Drop into shell rather than starting tests. > - --help Show this help message. > + --clean Purge results of previous test runs before starting. > + --debug Use '--show=app,test' log settings for avocado. > + --shell Drop into shell rather than starting tests. > + --clean-rootless-files Clean up files created by rootless builds with unshare after the tests finish. > + --help Show this help message. > > Any other parameters are passed to "avocado run". Its usage is: > > @@ -59,6 +65,15 @@ case "$args" in > ;; > esac > > +case "$args" in > + *"-p rootless=1"*) > + ;; > + *) > + clean_rootless_files=0 > + ;; > +esac > +export clean_rootless_files > + > mkdir /isar > > busybox syslogd > @@ -72,6 +87,21 @@ echo exit | /container-entrypoint > gosu builder sh -c ' > set -e > > +cleanup_rootless_files() > +{ > + rc=$? > + > + if [ "${clean_rootless_files}" = 1 ]; then > + find build \ > + \( ! -user "$(whoami)" -type d -prune \) \ > + -exec unshare --map-auto --map-root-user --keep-caps rm -rf {} \; We can reuse the ./scripts/isar-clean-builddir script which was written exactly for cleaning up the leftover files. Apart from that, the change is fine. Felix > + fi > + > + exit ${rc} > +} > + > +trap cleanup_rootless_files EXIT > + > base_dir=/work/build/testsuite > > mkdir -p ${base_dir}/overlay/upper > -- > 2.39.5 > > -- > You received this message because you are subscribed to the Google Groups "isar-users" group. > To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. > To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260716124017.1480579-1-wzh%40ilbers.de.
On 7/16/26 14:47, MOESSBAUER, Felix wrote: > On Thu, 2026-07-16 at 14:40 +0200, Zhihang Wei wrote: >> When running tests with rootless builds, some files created with the user >> namespace inside the container cannot be removed by the calling user after >> the test-container exits without sudo. Add the `--clean-rootless-files` >> option to the test-container entrypoint to clean up such files before >> leaving the container. >> >> The cleanup is only performed for rootless builds and only removes files >> that cannot be cleaned up without sudo outside the container. Other build >> artifacts are left untouched so they remain available for CI artifact >> collection and post-test inspection. >> >> Signed-off-by: Zhihang Wei <wzh@ilbers.de> >> --- >> .../dockerdata/test-container-entrypoint | 38 +++++++++++++++++-- >> 1 file changed, 34 insertions(+), 4 deletions(-) >> >> diff --git a/testsuite/dockerdata/test-container-entrypoint b/testsuite/dockerdata/test-container-entrypoint >> index e4714942..9bddbb18 100755 >> --- a/testsuite/dockerdata/test-container-entrypoint >> +++ b/testsuite/dockerdata/test-container-entrypoint >> @@ -17,6 +17,8 @@ else >> shift 1 >> fi >> >> +clean_rootless_files=0 >> + >> export args="--max-parallel-tasks=1 --disable-sysinfo" >> for arg in $*; do >> case "$arg" in >> @@ -29,15 +31,19 @@ for arg in $*; do >> --shell) >> export start_shell=1 >> ;; >> + --clean-rootless-files) >> + clean_rootless_files=1 >> + ;; >> --help) >> cat <<EOF >> Usage: run-tests.sh [params] ... >> >> Supported parameters: >> - --clean Purge results of previous test runs before starting. >> - --debug Use '--show=app,test' log settings for avocado. >> - --shell Drop into shell rather than starting tests. >> - --help Show this help message. >> + --clean Purge results of previous test runs before starting. >> + --debug Use '--show=app,test' log settings for avocado. >> + --shell Drop into shell rather than starting tests. >> + --clean-rootless-files Clean up files created by rootless builds with unshare after the tests finish. >> + --help Show this help message. >> >> Any other parameters are passed to "avocado run". Its usage is: >> >> @@ -59,6 +65,15 @@ case "$args" in >> ;; >> esac >> >> +case "$args" in >> + *"-p rootless=1"*) >> + ;; >> + *) >> + clean_rootless_files=0 >> + ;; >> +esac >> +export clean_rootless_files >> + >> mkdir /isar >> >> busybox syslogd >> @@ -72,6 +87,21 @@ echo exit | /container-entrypoint >> gosu builder sh -c ' >> set -e >> >> +cleanup_rootless_files() >> +{ >> + rc=$? >> + >> + if [ "${clean_rootless_files}" = 1 ]; then >> + find build \ >> + \( ! -user "$(whoami)" -type d -prune \) \ >> + -exec unshare --map-auto --map-root-user --keep-caps rm -rf {} \; > We can reuse the ./scripts/isar-clean-builddir script which was written > exactly for cleaning up the leftover files. > > Apart from that, the change is fine. > > Felix Hi Felix, This part was borrowed from your isar-clean-builddir script. But here I want to keep the logs and build artifacts. Thinking about it more: the files with different ownership are only in rootfs dirs. Maybe I can reuse the script to clean up rootfs only. Let me try. v8 unprivileged is on CI, we'll merge once it passes. Zhihang > >> + fi >> + >> + exit ${rc} >> +} >> + >> +trap cleanup_rootless_files EXIT >> + >> base_dir=/work/build/testsuite >> >> mkdir -p ${base_dir}/overlay/upper >> -- >> 2.39.5 >> >> -- >> You received this message because you are subscribed to the Google Groups "isar-users" group. >> To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. >> To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260716124017.1480579-1-wzh%40ilbers.de.
On Thu, 2026-07-16 at 15:06 +0200, Zhihang Wei wrote: > On 7/16/26 14:47, MOESSBAUER, Felix wrote: > > On Thu, 2026-07-16 at 14:40 +0200, Zhihang Wei wrote: > > > When running tests with rootless builds, some files created with the user > > > namespace inside the container cannot be removed by the calling user after > > > the test-container exits without sudo. Add the `--clean-rootless-files` > > > option to the test-container entrypoint to clean up such files before > > > leaving the container. > > > > > > The cleanup is only performed for rootless builds and only removes files > > > that cannot be cleaned up without sudo outside the container. Other build > > > artifacts are left untouched so they remain available for CI artifact > > > collection and post-test inspection. > > > > > > Signed-off-by: Zhihang Wei <wzh@ilbers.de> > > > --- > > > .../dockerdata/test-container-entrypoint | 38 +++++++++++++++++-- > > > 1 file changed, 34 insertions(+), 4 deletions(-) > > > > > > diff --git a/testsuite/dockerdata/test-container-entrypoint b/testsuite/dockerdata/test-container-entrypoint > > > index e4714942..9bddbb18 100755 > > > --- a/testsuite/dockerdata/test-container-entrypoint > > > +++ b/testsuite/dockerdata/test-container-entrypoint > > > @@ -17,6 +17,8 @@ else > > > shift 1 > > > fi > > > > > > +clean_rootless_files=0 > > > + > > > export args="--max-parallel-tasks=1 --disable-sysinfo" > > > for arg in $*; do > > > case "$arg" in > > > @@ -29,15 +31,19 @@ for arg in $*; do > > > --shell) > > > export start_shell=1 > > > ;; > > > + --clean-rootless-files) > > > + clean_rootless_files=1 > > > + ;; > > > --help) > > > cat <<EOF > > > Usage: run-tests.sh [params] ... > > > > > > Supported parameters: > > > - --clean Purge results of previous test runs before starting. > > > - --debug Use '--show=app,test' log settings for avocado. > > > - --shell Drop into shell rather than starting tests. > > > - --help Show this help message. > > > + --clean Purge results of previous test runs before starting. > > > + --debug Use '--show=app,test' log settings for avocado. > > > + --shell Drop into shell rather than starting tests. > > > + --clean-rootless-files Clean up files created by rootless builds with unshare after the tests finish. > > > + --help Show this help message. > > > > > > Any other parameters are passed to "avocado run". Its usage is: > > > > > > @@ -59,6 +65,15 @@ case "$args" in > > > ;; > > > esac > > > > > > +case "$args" in > > > + *"-p rootless=1"*) > > > + ;; > > > + *) > > > + clean_rootless_files=0 > > > + ;; > > > +esac > > > +export clean_rootless_files > > > + > > > mkdir /isar > > > > > > busybox syslogd > > > @@ -72,6 +87,21 @@ echo exit | /container-entrypoint > > > gosu builder sh -c ' > > > set -e > > > > > > +cleanup_rootless_files() > > > +{ > > > + rc=$? > > > + > > > + if [ "${clean_rootless_files}" = 1 ]; then > > > + find build \ > > > + \( ! -user "$(whoami)" -type d -prune \) \ > > > + -exec unshare --map-auto --map-root-user --keep-caps rm -rf {} \; > > We can reuse the ./scripts/isar-clean-builddir script which was written > > exactly for cleaning up the leftover files. > > > > Apart from that, the change is fine. > > > > Felix > > Hi Felix, > > This part was borrowed from your isar-clean-builddir script. But here I want > to keep the logs and build artifacts. > > Thinking about it more: the files with different ownership are only in > rootfs > dirs. Maybe I can reuse the script to clean up rootfs only. Let me try. Makes sense. I'm wondering if we better just call that script instead of the rm -rf {}: find ... -exec ./scripts/isar-clean-builddir {} \; The unshare mapping might change in the future (I hope not, but who knows) and we don't want to maintain that all over the place. > > v8 unprivileged is on CI, we'll merge once it passes. Sounds good. Thanks for keeping up with this. Cheers! Felix > > Zhihang > > > > > > + fi > > > + > > > + exit ${rc} > > > +} > > > + > > > +trap cleanup_rootless_files EXIT > > > + > > > base_dir=/work/build/testsuite > > > > > > mkdir -p ${base_dir}/overlay/upper > > > -- > > > 2.39.5 > > > > > > -- > > > You received this message because you are subscribed to the Google Groups "isar-users" group. > > > To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. > > > To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260716124017.1480579-1-wzh%40ilbers.de.
diff --git a/testsuite/dockerdata/test-container-entrypoint b/testsuite/dockerdata/test-container-entrypoint index e4714942..9bddbb18 100755 --- a/testsuite/dockerdata/test-container-entrypoint +++ b/testsuite/dockerdata/test-container-entrypoint @@ -17,6 +17,8 @@ else shift 1 fi +clean_rootless_files=0 + export args="--max-parallel-tasks=1 --disable-sysinfo" for arg in $*; do case "$arg" in @@ -29,15 +31,19 @@ for arg in $*; do --shell) export start_shell=1 ;; + --clean-rootless-files) + clean_rootless_files=1 + ;; --help) cat <<EOF Usage: run-tests.sh [params] ... Supported parameters: - --clean Purge results of previous test runs before starting. - --debug Use '--show=app,test' log settings for avocado. - --shell Drop into shell rather than starting tests. - --help Show this help message. + --clean Purge results of previous test runs before starting. + --debug Use '--show=app,test' log settings for avocado. + --shell Drop into shell rather than starting tests. + --clean-rootless-files Clean up files created by rootless builds with unshare after the tests finish. + --help Show this help message. Any other parameters are passed to "avocado run". Its usage is: @@ -59,6 +65,15 @@ case "$args" in ;; esac +case "$args" in + *"-p rootless=1"*) + ;; + *) + clean_rootless_files=0 + ;; +esac +export clean_rootless_files + mkdir /isar busybox syslogd @@ -72,6 +87,21 @@ echo exit | /container-entrypoint gosu builder sh -c ' set -e +cleanup_rootless_files() +{ + rc=$? + + if [ "${clean_rootless_files}" = 1 ]; then + find build \ + \( ! -user "$(whoami)" -type d -prune \) \ + -exec unshare --map-auto --map-root-user --keep-caps rm -rf {} \; + fi + + exit ${rc} +} + +trap cleanup_rootless_files EXIT + base_dir=/work/build/testsuite mkdir -p ${base_dir}/overlay/upper
When running tests with rootless builds, some files created with the user namespace inside the container cannot be removed by the calling user after the test-container exits without sudo. Add the `--clean-rootless-files` option to the test-container entrypoint to clean up such files before leaving the container. The cleanup is only performed for rootless builds and only removes files that cannot be cleaned up without sudo outside the container. Other build artifacts are left untouched so they remain available for CI artifact collection and post-test inspection. Signed-off-by: Zhihang Wei <wzh@ilbers.de> --- .../dockerdata/test-container-entrypoint | 38 +++++++++++++++++-- 1 file changed, 34 insertions(+), 4 deletions(-)