-
Notifications
You must be signed in to change notification settings - Fork 3.1k
test(e2e): add non-root sandbox smoke test #3166
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
6 commits
Select commit
Hold shift + click to select a range
308be1e
test(e2e): add non-root sandbox smoke test
hunglp6d a415211
test(e2e): fix format in pr check
hunglp6d 0af3b61
Merge branch 'main' into test/e2e-non-root-sandbox-smoke-test
hunglp6d ec88ca5
test(e2e): drop temporary verbose helpers
hunglp6d 2e45e59
Merge branch 'main' into test/e2e-non-root-sandbox-smoke-test
hunglp6d 4e2437a
Merge branch 'main' into test/e2e-non-root-sandbox-smoke-test
hunglp6d File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,100 @@ | ||
| #!/usr/bin/env bash | ||
| # SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. | ||
| # SPDX-License-Identifier: Apache-2.0 | ||
| # | ||
| # E2E smoke test for non-root sandbox execution under | ||
| # --security-opt no-new-privileges (issue #2571). | ||
| # | ||
| # Replicates Brev Launchable / DGX Spark's PR_SET_NO_NEW_PRIVS constraint | ||
| # in CI to catch regressions of: | ||
| # | ||
| # - #2472 (2026-04-25): non-root entrypoint crashed when install_configure_guard | ||
| # wrote to ~/.bashrc/.profile under Landlock + `set -e` — 5-day outage | ||
| # invisible to CI. Architecturally gone after #2741 (rc files are now | ||
| # root:root 444 static shims); this test guards the symptom — entrypoint | ||
| # exits non-zero under no-new-privileges. | ||
| # | ||
| # (#2482-class detection — `openclaw tui` "Missing gateway auth token" — is | ||
| # deferred to a follow-up PR after #2485 merges, since current main has no | ||
| # token-generation code path in the standalone container.) | ||
| # | ||
| # CAVEAT: no-new-privileges ≠ Landlock. We catch #2472-class bugs only | ||
| # when they manifest as a non-zero entrypoint exit; the original ~/.bashrc | ||
| # write under Landlock is not reproduced. A real Landlock ruleset is future | ||
| # work (#2571). | ||
| # | ||
| # How: ENTRYPOINT=`nemoclaw-start`, CMD=`["/bin/bash"]`. Passing a command | ||
| # to `docker run` overrides CMD; the entrypoint captures it into NEMOCLAW_CMD | ||
| # and exec's it *after* setup (nemoclaw-start.sh:1508 non-root / :1613 root). | ||
| # We pass `true` (Test 1) so setup runs end-to-end without entering the | ||
| # gateway-launch path (which needs OpenShell). | ||
| # | ||
| # Requires: docker | ||
|
|
||
| set -euo pipefail | ||
|
|
||
| IMAGE="${NEMOCLAW_TEST_IMAGE:-nemoclaw-production}" | ||
|
|
||
| RED='\033[0;31m' | ||
| GREEN='\033[0;32m' | ||
| YELLOW='\033[1;33m' | ||
| NC='\033[0m' | ||
|
|
||
| pass() { | ||
| echo -e "${GREEN}PASS${NC}: $1" | ||
| PASSED=$((PASSED + 1)) | ||
| } | ||
| fail() { | ||
| echo -e "${RED}FAIL${NC}: $1" | ||
| FAILED=$((FAILED + 1)) | ||
| } | ||
| info() { echo -e "${YELLOW}TEST${NC}: $1"; } | ||
|
|
||
| PASSED=0 | ||
| FAILED=0 | ||
|
|
||
| if ! docker image inspect "$IMAGE" >/dev/null 2>&1; then | ||
| fail "Image $IMAGE not found — load it before running this test" | ||
| exit 1 | ||
| fi | ||
|
|
||
| # Helper: run the entrypoint under --security-opt no-new-privileges with | ||
| # a final command of the caller's choice. The command is captured by | ||
| # nemoclaw-start as NEMOCLAW_CMD and exec'd after entrypoint setup. | ||
| # Returns combined stdout+stderr; caller checks $? and/or output. | ||
| run_under_nnp() { | ||
| docker run --rm --security-opt no-new-privileges "$IMAGE" "$@" 2>&1 || return $? | ||
| } | ||
|
|
||
| # ── Test 1: Entrypoint setup completes under no-new-privileges (#2472) ── | ||
|
|
||
| info "1. Entrypoint setup chain completes under --security-opt no-new-privileges" | ||
| RC=0 | ||
| OUT=$(run_under_nnp true) || RC=$? | ||
| if [ "$RC" -eq 0 ]; then | ||
| pass "entrypoint exited 0 under no-new-privileges (#2472 setup chain healthy)" | ||
| else | ||
| fail "entrypoint exited $RC under no-new-privileges — likely #2472-class regression" | ||
| echo "$OUT" | tail -20 | sed 's/^/ /' | ||
| fi | ||
|
|
||
| # ── Test 2: Kernel confirms PR_SET_NO_NEW_PRIVS is applied (sanity) ── | ||
|
|
||
| info "2. Kernel confirms NoNewPrivs=1 inside container (defends against silent flag typos)" | ||
| NNP=$(docker run --rm --security-opt no-new-privileges --entrypoint "" "$IMAGE" \ | ||
| sh -c 'grep ^NoNewPrivs /proc/self/status' 2>/dev/null \ | ||
| | awk '{print $2}' || echo "") | ||
| if [ "$NNP" = "1" ]; then | ||
| pass "kernel confirms NoNewPrivs=1" | ||
| else | ||
| fail "expected NoNewPrivs=1 inside container, got '${NNP:-<empty>}'" | ||
| fi | ||
|
|
||
| # ── Summary ───────────────────────────────────────────────────── | ||
|
|
||
| echo "" | ||
| echo -e "${GREEN}========================================${NC}" | ||
| echo -e " Results: ${GREEN}$PASSED passed${NC}, ${RED}$FAILED failed${NC}" | ||
| echo -e "${GREEN}========================================${NC}" | ||
|
|
||
| [ "$FAILED" -eq 0 ] || exit 1 |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.