fix: keep isolated backend tests hermetic and disk-backed

This commit is contained in:
archipelago
2026-10-09 09:09:16 -04:00
parent e2d926f5e0
commit 846b316d72
4 changed files with 20 additions and 10 deletions
@@ -257,6 +257,12 @@ impl RpcHandler {
}
}
// Unit tests deliberately construct a handler without an orchestrator.
// Never let that mock cross into a real Podman command on the host.
if cfg!(test) && self.orchestrator.is_none() {
return Ok(serde_json::json!([]));
}
let output = tokio::process::Command::new("podman")
.args(["ps", "-a", "--format", "json"])
.output()
@@ -1979,9 +1979,9 @@ pub(super) fn manifest_apps_dirs() -> Vec<std::path::PathBuf> {
if let Some(root) = std::env::var_os("ARCHIPELAGO_APPS_DIR") {
dirs.push(root.into());
}
if let Ok(manifest_dir) = std::env::var("CARGO_MANIFEST_DIR") {
dirs.push(Path::new(&manifest_dir).join("../../apps"));
}
// Cargo exposes this at compile time, not when an already-built isolated
// test executable is launched from a different working directory.
dirs.push(Path::new(env!("CARGO_MANIFEST_DIR")).join("../../apps"));
dirs.extend([
Path::new("apps").to_path_buf(),
Path::new("/opt/archipelago/apps").to_path_buf(),
+3 -3
View File
@@ -119,9 +119,9 @@ fn apps_dirs() -> Vec<PathBuf> {
if let Some(root) = std::env::var_os("ARCHIPELAGO_APPS_DIR") {
dirs.push(root.into());
}
if let Ok(manifest_dir) = std::env::var("CARGO_MANIFEST_DIR") {
dirs.push(PathBuf::from(manifest_dir).join("../../apps"));
}
// Preserve source discovery after the prebuilt test binary moves into its
// networkless execution container.
dirs.push(PathBuf::from(env!("CARGO_MANIFEST_DIR")).join("../../apps"));
dirs.extend([
PathBuf::from("apps"),
PathBuf::from("/opt/archipelago/apps"),
+8 -4
View File
@@ -19,6 +19,8 @@ if [[ ${ARCHY_TEST_ISOLATOR:-systemd} == podman ]]; then
cargo_home=$(mkdir -p "$cargo_home" && cd "$cargo_home" && pwd)
artifacts=$(mktemp -d)
trap 'rm -rf -- "$artifacts"' EXIT
install -d "$artifacts/runtime/archipelago" "$artifacts/runtime/containers" \
"$artifacts/runtime/tmp"
podman run --rm \
--cpus="${ARCHY_TEST_CPUS:-4}" --memory="${ARCHY_TEST_MEMORY:-4g}" --pids-limit=2048 \
@@ -54,10 +56,12 @@ PY
podman run --rm \
--cpus="${ARCHY_TEST_CPUS:-4}" --memory="${ARCHY_TEST_MEMORY:-4g}" --pids-limit=1024 \
--cap-drop=all --security-opt=no-new-privileges --read-only \
--tmpfs /tmp:rw,size=512m --tmpfs /run:rw,size=64m \
--tmpfs /var/lib/archipelago:rw,size=256m --tmpfs /var/lib/containers:rw,size=256m \
--tmpfs /root:rw,size=64m --network=none \
--cap-drop=all --cap-add=chown --cap-add=fowner --cap-add=setuid --cap-add=setgid \
--security-opt=no-new-privileges --read-only \
--tmpfs /run:rw,size=64m --tmpfs /root:rw,size=64m --network=none \
--volume "$artifacts/runtime/tmp:/tmp:rw,Z" \
--volume "$artifacts/runtime/archipelago:/var/lib/archipelago:rw,Z" \
--volume "$artifacts/runtime/containers:/var/lib/containers:rw,Z" \
--volume "$REPO:/workspace:ro,Z" --workdir /workspace/core \
--env ARCHY_TEST_ISOLATED=1 \
"$image" "$executable" --test-threads="${ARCHY_TEST_THREADS:-4}" "$@"