Closed weiwang-linda closed 1 month ago
Adding a ffi test to execute sysctl inside nested container running on top of QM. Test with PACKIT_COPR_PROJECT="packit/containers-qm-443", the case run passed.
out: sysctl: permission denied on key "net.ipv4.ip_forward" out: sysctl: permission denied on key "net.ipv4.conf.all.rp_filter" out: sysctl: permission denied on key "net.ipv4.tcp_max_syn_backlog" out: sysctl: permission denied on key "vm.swappiness" out: sysctl: permission denied on key "vm.overcommit_memory" out: Shared connection to xx.xx.xx.xxx closed. Copy '/var/tmp/tmt/run-003/plans/e2e/ffi/execute/data/guest/default-0/tests/ffi/sysctl-1' from the guest to '/'. Extract results of '/tests/ffi/sysctl'. Copy '/var/tmp/tmt/run-003/plans/e2e/ffi/execute/data/guest/default-0/tests/ffi/sysctl-1' from the guest to '/'. 00:02:49 pass /tests/ffi/sysctl (on default-0) [1/1] Copy '/var/tmp/tmt/run-003/plans/e2e/ffi/data' from the guest to '/'. summary: 1 test executed
@weiwang-linda Please add in the description resolve issue_id
Adding a ffi test to execute sysctl inside nested container running on top of QM. Test with PACKIT_COPR_PROJECT="packit/containers-qm-443", the case run passed.
out: sysctl: permission denied on key "net.ipv4.ip_forward" out: sysctl: permission denied on key "net.ipv4.conf.all.rp_filter" out: sysctl: permission denied on key "net.ipv4.tcp_max_syn_backlog" out: sysctl: permission denied on key "vm.swappiness" out: sysctl: permission denied on key "vm.overcommit_memory" out: Shared connection to xx.xx.xx.xxx closed. Copy '/var/tmp/tmt/run-003/plans/e2e/ffi/execute/data/guest/default-0/tests/ffi/sysctl-1' from the guest to '/'. Extract results of '/tests/ffi/sysctl'. Copy '/var/tmp/tmt/run-003/plans/e2e/ffi/execute/data/guest/default-0/tests/ffi/sysctl-1' from the guest to '/'. 00:02:49 pass /tests/ffi/sysctl (on default-0) [1/1] Copy '/var/tmp/tmt/run-003/plans/e2e/ffi/data' from the guest to '/'. summary: 1 test executed
@weiwang-linda Please add in the description resolve issue_id
Done
I do not understand what needed to be tested. It should be in description
Done!
/packit tests --identifier e2e-ffi
/packit test --identifier e2e-ffi
/packit test --identifier e2e-tiers
Adding a ffi test to execute sysctl inside nested container running on top of QM
resolve #370
Verify attempts to change OS level are denied inside QM container, like below