summaryrefslogtreecommitdiffhomepage
path: root/test/test_python_isolation.py
diff options
context:
space:
mode:
Diffstat (limited to 'test/test_python_isolation.py')
-rw-r--r--test/test_python_isolation.py76
1 files changed, 36 insertions, 40 deletions
diff --git a/test/test_python_isolation.py b/test/test_python_isolation.py
index 1a157528..680f2c03 100644
--- a/test/test_python_isolation.py
+++ b/test/test_python_isolation.py
@@ -1,31 +1,15 @@
-import shutil
import pytest
-
-from conftest import option
-from conftest import unit_run
-from conftest import unit_stop
from unit.applications.lang.python import TestApplicationPython
-from unit.feature.isolation import TestFeatureIsolation
+from unit.option import option
+from unit.utils import findmnt
+from unit.utils import waitformount
+from unit.utils import waitforunmount
class TestPythonIsolation(TestApplicationPython):
prerequisites = {'modules': {'python': 'any'}, 'features': ['isolation']}
- @classmethod
- def setup_class(cls, complete_check=True):
- check = super().setup_class(complete_check=False)
-
- unit = unit_run()
- option.temp_dir = unit['temp_dir']
-
- TestFeatureIsolation().check(option.available, unit['temp_dir'])
-
- assert unit_stop() is None
- shutil.rmtree(unit['temp_dir'])
-
- return check if not complete_check else check()
-
def test_python_isolation_rootfs(self, is_su, temp_dir):
isolation_features = option.available['features']['isolation'].keys()
@@ -79,39 +63,51 @@ class TestPythonIsolation(TestApplicationPython):
), 'application exists in rootfs'
def test_python_isolation_rootfs_no_language_deps(self, is_su, temp_dir):
- isolation_features = option.available['features']['isolation'].keys()
-
if not is_su:
- if not 'unprivileged_userns_clone' in isolation_features:
- pytest.skip('requires unprivileged userns or root')
-
- if 'user' not in isolation_features:
- pytest.skip('user namespace is not supported')
-
- if 'mnt' not in isolation_features:
- pytest.skip('mnt namespace is not supported')
-
- if 'pid' not in isolation_features:
- pytest.skip('pid namespace is not supported')
+ pytest.skip('requires root')
isolation = {
'rootfs': temp_dir,
'automount': {'language_deps': False}
}
- if not is_su:
- isolation['namespaces'] = {
- 'mount': True,
- 'credential': True,
- 'pid': True
- }
-
self.load('empty', isolation=isolation)
+ assert findmnt().find(temp_dir) == -1
assert (self.get()['status'] != 200), 'disabled language_deps'
+ assert findmnt().find(temp_dir) == -1
isolation['automount']['language_deps'] = True
self.load('empty', isolation=isolation)
+ assert findmnt().find(temp_dir) == -1
assert (self.get()['status'] == 200), 'enabled language_deps'
+ assert waitformount(temp_dir), 'language_deps mount'
+
+ self.conf({"listeners": {}, "applications": {}})
+
+ assert waitforunmount(temp_dir), 'language_deps unmount'
+
+ def test_python_isolation_procfs(self, is_su, temp_dir):
+ isolation_features = option.available['features']['isolation'].keys()
+
+ if not is_su:
+ pytest.skip('requires root')
+
+ isolation = {'rootfs': temp_dir, 'automount': {'procfs': False}}
+
+ self.load('ns_inspect', isolation=isolation)
+
+ assert (
+ self.getjson(url='/?path=/proc/self')['body']['FileExists']
+ == False
+ ), 'no /proc/self'
+
+ isolation['automount']['procfs'] = True
+
+ self.load('ns_inspect', isolation=isolation)
+
+ assert (
+ self.getjson(url='/?path=/proc/self')['body']['FileExists'] == True
+ ), '/proc/self'