1 ;;; GNU Guix --- Functional package management for GNU
2 ;;; Copyright © 2015 David Thompson <davet@gnu.org>
4 ;;; This file is part of GNU Guix.
6 ;;; GNU Guix is free software; you can redistribute it and/or modify it
7 ;;; under the terms of the GNU General Public License as published by
8 ;;; the Free Software Foundation; either version 3 of the License, or (at
9 ;;; your option) any later version.
11 ;;; GNU Guix is distributed in the hope that it will be useful, but
12 ;;; WITHOUT ANY WARRANTY; without even the implied warranty of
13 ;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 ;;; GNU General Public License for more details.
16 ;;; You should have received a copy of the GNU General Public License
17 ;;; along with GNU Guix. If not, see <http://www.gnu.org/licenses/>.
19 (define-module (test-containers)
20 #:use-module (guix utils)
21 #:use-module (guix build syscalls)
22 #:use-module (gnu build linux-container)
23 #:use-module (srfi srfi-64)
24 #:use-module (ice-9 match))
26 (define (assert-exit x)
27 (primitive-exit (if x 0 1)))
29 ;; Skip these tests unless user namespaces are available and the setgroups
30 ;; file (introduced in Linux 3.19 to address a security issue) exists.
31 (unless (and (file-exists? "/proc/self/ns/user")
32 (file-exists? "/proc/self/setgroups"))
35 (test-begin "containers")
37 (test-assert "call-with-container, exit with 0 when there is no error"
39 (call-with-container '() (const #t) #:namespaces '(user))))
41 (test-assert "call-with-container, user namespace"
43 (call-with-container '()
45 ;; The user is root within the new user namespace.
46 (assert-exit (and (zero? (getuid)) (zero? (getgid)))))
47 #:namespaces '(user))))
49 (test-assert "call-with-container, uts namespace"
51 (call-with-container '()
53 ;; The user is root within the container and should be able to change
54 ;; the hostname of that container.
55 (sethostname "test-container")
57 #:namespaces '(user uts))))
59 (test-assert "call-with-container, pid namespace"
61 (call-with-container '()
63 (match (primitive-fork)
65 ;; The first forked process in the new pid namespace is pid 2.
66 (assert-exit (= 2 (getpid))))
71 (status:exit-val status)))))))
72 #:namespaces '(user pid))))
74 (test-assert "call-with-container, mnt namespace"
76 (call-with-container '(("none" device "/testing" "tmpfs" () #f #f))
78 (assert-exit (file-exists? "/testing")))
79 #:namespaces '(user mnt))))
81 (test-assert "call-with-container, all namespaces"
83 (call-with-container '()
85 (primitive-exit 0)))))
87 (test-assert "container-excursion"
88 (call-with-temporary-directory
90 ;; Two pipes: One for the container to signal that the test can begin,
91 ;; and one for the parent to signal to the container that the test is
93 (match (list (pipe) (pipe))
94 (((start-in . start-out) (end-in . end-out))
98 ;; Signal for the test to start.
99 (write 'ready start-out)
101 ;; Wait for test completion.
105 (define (namespaces pid)
106 (let ((pid (number->string pid)))
108 (readlink (string-append "/proc/" pid "/ns/" ns)))
109 '("user" "ipc" "uts" "net" "pid" "mnt"))))
111 (let* ((pid (run-container root '() %namespaces 1 container))
112 (container-namespaces (namespaces pid))
116 ;; Wait for container to be ready.
119 (container-excursion pid
121 ;; Fork again so that the pid is within the context of
122 ;; the joined pid namespace instead of the original pid
124 (match (primitive-fork)
126 ;; Check that all of the namespace identifiers are
127 ;; the same as the container process.
129 (equal? container-namespaces
130 (namespaces (getpid)))))
132 (match (waitpid fork-pid)
135 (status:exit-val status)))))))))))
137 ;; Stop the container.
138 (write 'done end-out)
146 (exit (= (test-runner-fail-count (test-runner-current)) 0))