From 61748ce6edef251113639e03a23eea5d58821187 Mon Sep 17 00:00:00 2001 From: Kir Kolyshkin Date: Wed, 30 Sep 2026 22:02:19 -0700 Subject: [PATCH] tests/runc-integration-skip.txt: document some skips Explain why some runc integration tests are skipped, grouping the entries which fail for the same reason: - the "container" sub-cgroup used with the systemd cgroup driver; - runc specific debug messages, output format and warnings; - errors worded differently; - rootless containers with resource limits and no cgroup permission. Also explain the seccomp -ENOSYS handling skip (to be solved in libseccomp) and the mount order skips (host rootfs paths used as mount destinations by the test, and idmapped mount sources inside the container rootfs). Separate the commented entries by empty lines, so that it is clear which entries a comment applies to, and move the entries with no explanation yet to the end. Signed-off-by: Kir Kolyshkin --- tests/runc-integration-skip.txt | 159 +++++++++++++++++++++----------- 1 file changed, 106 insertions(+), 53 deletions(-) diff --git a/tests/runc-integration-skip.txt b/tests/runc-integration-skip.txt index 0beb24d960..42ad5e256c 100644 --- a/tests/runc-integration-skip.txt +++ b/tests/runc-integration-skip.txt @@ -6,98 +6,151 @@ # # The latter is for the whole file, e.g. for a feature crun does not have. # +# A comment applies to the entries below it, up to the next empty line. +# # The list is expected to shrink, as either crun or the tests get fixed. # Remove an entry once the test passes; an entry which does not match any # test (for example, because it was renamed or removed) is an error. -# Features crun does not have, and runc specific tests. # "crun events" is not implemented. events.bats + # Checks the output of runc --debug, which is runc specific. debug.bats + # "-h" is not implemented, only "--help". help.bats + # --pidfd-socket is not implemented. pidfd-socket.bats + # Checks the output format of "runc --version", which is runc specific. version.bats -# Individual tests. -capabilities.bats: runc run with unknown capability -capabilities.bats: runc exec --cap [ambient is set from spec] -capabilities.bats: runc run [ambient caps not set in inheritable result in a warning] -cgroup_delegation.bats: runc exec (cgroup v2, ro cgroupfs, new cgroupns) does not chown cgroup -cgroups.bats: runc create (rootless + limits + no cgrouppath + no permission) fails with informative error -cgroups.bats: runc create (limits + cgrouppath + permission on the cgroup dir) succeeds -cgroups.bats: runc run (per-device multiple iops via unified) -cgroups.bats: runc run (hugetlb limits) -cgroups.bats: runc run (pids.limit=0 means 1) # --ignore-paused is not implemented. cgroups.bats: runc exec --ignore-paused -cgroups.bats: runc run/create should error for a non-empty cgroup -# --lazy-pages not implemented. + +# "crun exec --additional-gids" is not implemented. +exec.bats: runc exec --additional-gids + +# "crun ps" does not run ps(1): it only lists the container PIDs, and does not +# accept ps options. +ps.bats: ps +ps.bats: ps -e -x + +# --lazy-pages is not implemented. # TODO: remove once containers/crun#2259 is merged. checkpoint.bats: checkpoint --lazy-pages and restore -cpu_affinity.bats: runc exec [CPU affinity, only initial set from process.json] -cpu_affinity.bats: runc exec [CPU affinity, initial and final set from process.json] -cpu_affinity.bats: runc exec [CPU affinity, initial and final set from config.json] -create.bats: runc create [shared pidns + rootless] + +# With the systemd cgroup driver, crun puts the container processes into the +# "container" sub-cgroup of the unit cgroup, while these tests look at the unit +# cgroup itself (its cgroup.procs, or a sub-cgroup created from the container). delete.bats: runc delete [host pidns + init gone] delete.bats: runc delete --force [host pidns + init gone] delete.bats: runc delete --force in cgroupv2 with subcgroups -exec.bats: runc exec --additional-gids + +# With the systemd cgroup driver, crun sets the limits on the "container" +# sub-cgroup of the unit cgroup, and systemd does not set the CPU period with +# no quota on the unit cgroup, which is what the tests check. +update.bats: set cpu period with no quota +update.bats: update cpu period with no previous period/quota set + +# The tests check runc specific debug messages. +cpu_affinity.bats: runc exec [CPU affinity, only initial set from process.json] +cpu_affinity.bats: runc exec [CPU affinity, initial and final set from process.json] +cpu_affinity.bats: runc exec [CPU affinity, initial and final set from config.json] exec.bats: runc --debug exec exec.bats: runc --debug --log exec -exec.bats: runc exec --cgroup subcgroup [v2] -exec.bats: runc exec [init changes cgroup] -hooks.bats: runc run [hook's argv is preserved] -hooks_so.bats: runc run (hooks library tests) -host-mntns.bats: runc run [host mount ns + hooks] -# crun keeps all idmapped mount source fds open at once (EMFILE with a low RLIMIT_NOFILE). -idmap.bats: Check mount source fds are cleaned up with idmapped mounts [userns] -# crun makes idmapped mounts private, even if another propagation is requested. -idmap.bats: idmap mount with propagation flag [userns] -kill.bats: kill detached busybox -kill.bats: kill KILL [host pidns] -kill.bats: kill KILL [host pidns + init gone] +run.bats: runc run [/proc/self/exe clone] + +# The test checks the runc specific output format of "list". list.bats: list -list.bats: list with non-existent root fails + +# The test checks for a runc specific warning ("Such configuration is strongly +# discouraged"). +create.bats: runc create [shared pidns + rootless] + +# crun fails as well, but words the error differently. +kill.bats: kill detached busybox memorypolicy.bats: runc run memory policy calls syscall with invalid arguments -# As root, crun does not pass the inherited mode as a mode= mount option. -mounts.bats: runc run [tmpfs mount mode= inherit] + +# crun reports the hook exit code, not the signal ("bad system call"). +seccomp.bats: runc run [seccomp] (startContainer hook) + +# crun words the error differently ("open seccomp receiver: connect socket to ..."). +seccomp-notify.bats: runc run [seccomp] (SCMP_ACT_NOTIFY no seccompagent) + +# runc rejects the configuration, while crun fails to set the scheduler (EPERM). +scheduler.bats: scheduler vs cpus + +# crun errors out if both CPU shares and cpu.idle are set with systemd, while +# runc warns ("unable to apply both") and ignores the shares. +update.bats: update cgroup cpu.idle via systemd v252+ + +# Without the permission to use cgroups, crun ignores the resource limits of +# a rootless container, while runc fails. +cgroups.bats: runc create (rootless + limits + no cgrouppath + no permission) fails with informative error + +# The test uses "CPU", "Cpus" and "Mems" keys, which only work with runc +# because Go decodes JSON case-insensitively. +# TODO: remove once opencontainers/runc#5501 is merged. +update.bats: update cpuset parameters via resources.CPU + +# runc returns -ENOSYS for syscalls newer than any in the profile, using a +# BPF stub. This is better solved in libseccomp, see seccomp/libseccomp#457. +seccomp.bats: runc run [seccomp -ENOSYS handling] + +# The test uses host rootfs paths as mount destinations, which runc accepts for +# legacy reasons, and crun does not. +# TODO: remove once opencontainers/runc#5503 is merged. mounts.bats: runc run [mount order, container bind-mount source] mounts.bats: runc run [mount order, container bind-mount source] (userns) + +# An idmapped mount can only be created by the host, while a bind mount source +# inside the container rootfs must be opened after the preceding mounts are done +# in the container mount namespace; crun opens idmapped mount sources beforehand. mounts.bats: runc run [mount order, container idmap source] mounts.bats: runc run [mount order, container idmap source] (userns) -mounts_propagation_unsafe.bats: runc run [rootfsPropagation slave] + +# crun keeps all idmapped mount source fds open at once (EMFILE with a low +# RLIMIT_NOFILE). +idmap.bats: Check mount source fds are cleaned up with idmapped mounts [userns] + +# crun makes idmapped mounts private, even if another propagation is requested. +idmap.bats: idmap mount with propagation flag [userns] + +# As root, crun does not pass the inherited mode as a mode= mount option. +mounts.bats: runc run [tmpfs mount mode= inherit] + # With a user namespace, crun allows to explicitly clear the locked flags of # a bind mount source (and the expected error message is runc specific). mounts_sshfs.bats: runc run [explicit-rw bind mount of a ro fuse sshfs mount] mounts_sshfs.bats: runc run [dev,exec,suid,atime bind mount of a nodev,nosuid,noexec,noatime fuse sshfs mount] mounts_sshfs.bats: runc run [bind mount {no,rel,strict}atime semantics] -ps.bats: ps -ps.bats: ps -e -x + +# Not yet explained: either to be fixed in crun, or yet to be looked into. +capabilities.bats: runc run with unknown capability +capabilities.bats: runc exec --cap [ambient is set from spec] +capabilities.bats: runc run [ambient caps not set in inheritable result in a warning] +cgroup_delegation.bats: runc exec (cgroup v2, ro cgroupfs, new cgroupns) does not chown cgroup +cgroups.bats: runc create (limits + cgrouppath + permission on the cgroup dir) succeeds +cgroups.bats: runc run (per-device multiple iops via unified) +cgroups.bats: runc run (hugetlb limits) +cgroups.bats: runc run (pids.limit=0 means 1) +cgroups.bats: runc run/create should error for a non-empty cgroup +exec.bats: runc exec --cgroup subcgroup [v2] +exec.bats: runc exec [init changes cgroup] +hooks.bats: runc run [hook's argv is preserved] +hooks_so.bats: runc run (hooks library tests) +host-mntns.bats: runc run [host mount ns + hooks] +kill.bats: kill KILL [host pidns] +kill.bats: kill KILL [host pidns + init gone] +list.bats: list with non-existent root fails +mounts_propagation_unsafe.bats: runc run [rootfsPropagation slave] ps.bats: ps after the container stopped -run.bats: runc run [/proc/self/exe clone] -scheduler.bats: scheduler vs cpus -seccomp.bats: runc run [seccomp -ENOSYS handling] seccomp.bats: runc run [seccomp] (SECCOMP_FILTER_FLAG_*) -# crun reports the hook exit code, not the signal ("bad system call"). -seccomp.bats: runc run [seccomp] (startContainer hook) seccomp-notify.bats: runc run [seccomp] (SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV) -# crun words the error differently ("open seccomp receiver: connect socket to ..."). -seccomp-notify.bats: runc run [seccomp] (SCMP_ACT_NOTIFY no seccompagent) seccomp-notify.bats: runc run [seccomp] (SCMP_ACT_NOTIFY write) update.bats: update cgroup cpu limits update.bats: update pids.limit -# With systemd, crun sets the limits on a sub-cgroup of the unit one, and -# systemd does not set the CPU period with no quota; the test checks the latter. -update.bats: set cpu period with no quota -update.bats: update cpu period with no previous period/quota set -# crun errors out if both CPU shares and cpu.idle are set with systemd, while -# runc warns ("unable to apply both") and ignores the shares. -update.bats: update cgroup cpu.idle via systemd v252+ -# The test uses "CPU", "Cpus" and "Mems" keys, which only work with runc -# because Go decodes JSON case-insensitively. -update.bats: update cpuset parameters via resources.CPU update.bats: update per-device iops/bps values