Skip to content

test(ci): add rootless pasta AppArmor diagnostics - #2870

Draft
elezar wants to merge 3 commits into
mainfrom
2844-pasta-apparmor-test-guest/elezar
Draft

test(ci): add rootless pasta AppArmor diagnostics#2870
elezar wants to merge 3 commits into
mainfrom
2844-pasta-apparmor-test-guest/elezar

Conversation

@elezar

@elezar elezar commented Aug 21, 2026

Copy link
Copy Markdown
Member

Summary

Add runner-side AppArmor and process-label diagnostics to the rootless Podman E2E lane, and extend the Nix test-guest harness with an Ubuntu 26.04 rootless Podman/pasta environment for controlled follow-up investigation.

Related Issue

Related to #2844.

Changes

  • Record installed AppArmor, Podman, conmon, and passt versions; pasta profile source; loaded profiles; and live Podman/pasta process labels after rootless E2E.
  • Add a pinned Ubuntu 26.04 disposable guest plus rootless Podman/pasta/AppArmor configuration.
  • Add deterministic profile-control and upstream-rule overlay configurations with a rootless Podman API-socket probe.

Testing

  • mise run pre-commit passes
  • Nix test-guest app evaluates and lists the new guest/configurations
  • Disposable Ubuntu 26.04 guest provisions AppArmor and rootless pasta
  • The local control has not reproduced the runner denial yet; its first run confirmed a differing AppArmor label topology, which this PR's CI diagnostics are intended to capture.
  • E2E tests added/updated (CI diagnostics will run in the existing rootless E2E lane)

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)

Signed-off-by: Evan Lezar <elezar@nvidia.com>
@elezar elezar added the test:e2e Requires end-to-end coverage label Aug 21, 2026
@copy-pr-bot

copy-pr-bot Bot commented Aug 21, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@github-actions

Copy link
Copy Markdown

Label test:e2e applied, but pull-request/2870 does not exist yet. A maintainer needs to comment /ok to test 6766679f88264c1150b5e618ec6da3c73eff9afe to mirror this PR. Once the mirror exists, re-apply the label or re-run Branch E2E Checks from the Actions tab.

@elezar

elezar commented Aug 21, 2026

Copy link
Copy Markdown
Member Author

/ok-to-test 6766679

Signed-off-by: Evan Lezar <elezar@nvidia.com>
@elezar

elezar commented Aug 22, 2026

Copy link
Copy Markdown
Member Author

/ok-to-test edc832e

Signed-off-by: Evan Lezar <elezar@nvidia.com>
@elezar

elezar commented Aug 22, 2026

Copy link
Copy Markdown
Member Author

/ok

@elezar

elezar commented Aug 22, 2026

Copy link
Copy Markdown
Member Author

/ok-to-test f338c90

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant