nixos/tests/dockerTools: add test for running non-root containers with buildLayeredImage

Co-authored-by: Robert Hensing <roberth@users.noreply.github.com>
This commit is contained in:
Johan Thomsen
2020-07-31 10:14:07 +02:00
co-authored by Robert Hensing
parent 9f86685cc7
commit f5db415e2f
2 changed files with 46 additions and 0 deletions
+10
View File
@@ -79,6 +79,16 @@ import ./make-test-python.nix ({ pkgs, ... }: {
"docker rmi ${examples.nix.imageName}",
)
with subtest(
"Ensure (layered) nix store has correct permissions "
"and that the container starts when its process does not have uid 0"
):
docker.succeed(
"docker load --input='${examples.bashLayeredWithUser}'",
"docker run -u somebody --rm ${examples.bashLayeredWithUser.imageName} ${pkgs.bash}/bin/bash -c 'test 555 == $(stat --format=%a /nix) && test 555 == $(stat --format=%a /nix/store)'",
"docker rmi ${examples.bashLayeredWithUser.imageName}",
)
with subtest("The nix binary symlinks are intact"):
docker.succeed(
"docker load --input='${examples.nix}'",