Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
225 changes: 225 additions & 0 deletions acl/tests/kola_enforcing.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,12 +10,19 @@
# platforms: [qemu, azure]
# architectures: [amd64, aarch64]
# bootloader: [grub, uki]
# imageVariants: [acl, acl-t]
# reason: human-readable explanation
#
# Logic:
# - Within a single rule, fields combine with AND (all must match).
# - Across rules, they combine with OR (any matching rule allows failure).
# - A test with no exceptions is always enforced.
# - imageVariants values match exactly ('acl' never matches 'acl-t').
# - A rule whose ONLY constraint is imageVariants also drops the test
# from kola selection on that variant (it can never pass there, so it
# is not run at all). A rule that combines imageVariants with
# platforms/architectures/bootloader keeps the test selected and only
# forgives failures at evaluation where every key matches.

version: 1

Expand All @@ -28,6 +35,13 @@ tests:
reason: 3-node etcd cluster on TCG-emulated arm64 races systemd's DefaultDeviceTimeoutSec for /dev/disk/by-label/OEM; tracked by the OEM fsck conditional dropin work
- platforms: [azure]
reason: Azure version depends on discovery.etcd.io, which is unmaintained.
- imageVariants: [acl-t]
reason: |
The test's etcd server runs in a docker container
(etcd-member.service via etcd-wrapper), and acl-t has no
docker daemon — the standalone `docker` sysext is not carried
and docker has no RPM replacement (same as docker.*) — so no
etcd server can start for the test to drive.

- name: acl.internet
exceptions:
Expand All @@ -39,12 +53,40 @@ tests:
have a Public IP (mantle PR 27413), and Azure default outbound access
does not SNAT ICMP. Revert once mantle/infra restores outbound ICMP
(NSG-on-NIC keeping the PIP, or a NAT Gateway on the kola subnet).
- imageVariants: [acl-t]
reason: |
All three subtests are non-viable on acl-t: DockerPing and
DockerEcho need the docker daemon from the standalone `docker`
sysext (same missing sysext as docker.*), and NTPDate needs
the ntpdate binary (chrony is acl-t's time daemon; same reason
as linux.ntp). Covered by the containerd and chrony follow-up
tests tracked there.

- name: acl.ignition.v1.users
- name: acl.ignition.v2.users

- name: bpf.execsnoop
exceptions:
- imageVariants: [acl-t]
reason: |
acl-t does not carry the standalone `docker` sysext, so the
docker daemon/CLI this test drives does not exist: the
flattened image replaces sysext content with signed Azure
Linux RPMs, and docker has no RPM replacement — moby-containerd
ships containerd/ctr only (containerd-only runtime, matching
AKS). containerd-native (ctr) replacement tests are tracked as
a follow-up.
- name: bpf.local-gadget
exceptions:
- imageVariants: [acl-t]
reason: |
acl-t does not carry the standalone `docker` sysext, so the
docker daemon/CLI this test drives does not exist: the
flattened image replaces sysext content with signed Azure
Linux RPMs, and docker has no RPM replacement — moby-containerd
ships containerd/ctr only (containerd-only runtime, matching
AKS). containerd-native (ctr) replacement tests are tracked as
a follow-up.

- name: cl.cloudinit.basic
- name: cl.cloudinit.multipart-mime
Expand Down Expand Up @@ -84,10 +126,25 @@ tests:
reason: Flakiness on TCG-emulated arm64, failures due to slow device enumeration.

- name: cl.etcd-member.etcdctlv3
exceptions:
- imageVariants: [acl-t]
reason: |
The test's etcd server runs in a docker container
(etcd-member.service via etcd-wrapper), and acl-t has no
docker daemon — the standalone `docker` sysext is not carried
and docker has no RPM replacement (same as docker.*) — so no
etcd server can start for the test to drive.
- name: cl.etcd-member.v2-backup-restore
exceptions:
- platforms: [azure]
reason: Azure version depends on discovery.etcd.io, which is unmaintained.
- imageVariants: [acl-t]
reason: |
The test's etcd server runs in a docker container
(etcd-member.service via etcd-wrapper), and acl-t has no
docker daemon — the standalone `docker` sysext is not carried
and docker has no RPM replacement (same as docker.*) — so no
etcd server can start for the test to drive.

- name: cl.filesystem
exceptions:
Expand Down Expand Up @@ -175,6 +232,14 @@ tests:
exceptions:
- platforms: [azure]
reason: Test uses custom OEM files and should not run on cloud platforms
- imageVariants: [acl-t]
reason: |
The test exercises the boot machinery that activates OEM
sysexts (active-oem-<id> markers, oem-<id>-<version>.raw);
acl-t provides the `oem-azure` sysext content (WALinuxAgent,
hyperv-daemons, chrony, ...) as signed Azure Linux RPMs and
deletes the .raw and marker files, so there is nothing left
for that machinery to activate.
- name: cl.users.shells
- name: cl.verity

Expand Down Expand Up @@ -209,61 +274,182 @@ tests:
- platforms: [qemu]
architectures: [aarch64]
reason: Flakiness on TCG-emulated arm64, failures due to slow device enumeration.
- imageVariants: [acl-t]
reason: |
acl-t does not carry the standalone `docker` sysext, so the
docker daemon/CLI this test drives does not exist: the
flattened image replaces sysext content with signed Azure
Linux RPMs, and docker has no RPM replacement — moby-containerd
ships containerd/ctr only (containerd-only runtime, matching
AKS). containerd-native (ctr) replacement tests are tracked as
a follow-up.
- name: docker.btrfs-storage
exceptions:
- imageVariants: [acl-t]
reason: |
acl-t does not carry the standalone `docker` sysext, so the
docker daemon/CLI this test drives does not exist: the
flattened image replaces sysext content with signed Azure
Linux RPMs, and docker has no RPM replacement — moby-containerd
ships containerd/ctr only (containerd-only runtime, matching
AKS). containerd-native (ctr) replacement tests are tracked as
a follow-up.
- name: docker.containerd-restart
exceptions:
- imageVariants: [acl-t]
reason: |
acl-t does not carry the standalone `docker` sysext, so the
docker daemon/CLI this test drives does not exist: the
flattened image replaces sysext content with signed Azure
Linux RPMs, and docker has no RPM replacement — moby-containerd
ships containerd/ctr only (containerd-only runtime, matching
AKS). containerd-native (ctr) replacement tests are tracked as
a follow-up.
- name: docker.enable-service.sysext
exceptions:
- imageVariants: [acl-t]
reason: |
acl-t does not carry the standalone `docker` sysext, so the
docker daemon/CLI this test drives does not exist: the
flattened image replaces sysext content with signed Azure
Linux RPMs, and docker has no RPM replacement — moby-containerd
ships containerd/ctr only (containerd-only runtime, matching
AKS). containerd-native (ctr) replacement tests are tracked as
a follow-up.
- name: docker.selinux
exceptions:
- platforms: [qemu]
architectures: [aarch64]
reason: Slow emulation causes this test to hit the duplicate journal entry bug (azure coverage doesn't exhibit this)
- imageVariants: [acl-t]
reason: |
acl-t does not carry the standalone `docker` sysext, so the
docker daemon/CLI this test drives does not exist: the
flattened image replaces sysext content with signed Azure
Linux RPMs, and docker has no RPM replacement — moby-containerd
ships containerd/ctr only (containerd-only runtime, matching
AKS). containerd-native (ctr) replacement tests are tracked as
a follow-up.
- name: docker.userns
exceptions:
- imageVariants: [acl-t]
reason: |
acl-t does not carry the standalone `docker` sysext, so the
docker daemon/CLI this test drives does not exist: the
flattened image replaces sysext content with signed Azure
Linux RPMs, and docker has no RPM replacement — moby-containerd
ships containerd/ctr only (containerd-only runtime, matching
AKS). containerd-native (ctr) replacement tests are tracked as
a follow-up.

- name: kubeadm.v1.32.4.calico.base
exceptions:
- platforms: [qemu]
architectures: [aarch64]
reason: kubectl wait timeouts on emulated arm64 QEMU
- imageVariants: [acl-t]
reason: |
The kubeadm cluster provisions an etcd node that runs etcd in
a docker container (etcd-member.service via etcd-wrapper);
acl-t has no docker daemon — the standalone `docker` sysext is
not carried and docker has no RPM replacement (same as
docker.*) — so the control plane cannot bootstrap.
- name: kubeadm.v1.32.4.cilium.base
exceptions:
- platforms: [qemu]
architectures: [aarch64]
reason: kubectl wait timeouts on emulated arm64 QEMU
- imageVariants: [acl-t]
reason: |
The kubeadm cluster provisions an etcd node that runs etcd in
a docker container (etcd-member.service via etcd-wrapper);
acl-t has no docker daemon — the standalone `docker` sysext is
not carried and docker has no RPM replacement (same as
docker.*) — so the control plane cannot bootstrap.
- name: kubeadm.v1.32.4.flannel.base
exceptions:
- platforms: [qemu]
architectures: [aarch64]
reason: kubectl wait timeouts on emulated arm64 QEMU
- imageVariants: [acl-t]
reason: |
The kubeadm cluster provisions an etcd node that runs etcd in
a docker container (etcd-member.service via etcd-wrapper);
acl-t has no docker daemon — the standalone `docker` sysext is
not carried and docker has no RPM replacement (same as
docker.*) — so the control plane cannot bootstrap.
- name: kubeadm.v1.33.0.calico.base
exceptions:
- platforms: [qemu]
architectures: [aarch64]
reason: kubectl wait timeouts on emulated arm64 QEMU
- imageVariants: [acl-t]
reason: |
The kubeadm cluster provisions an etcd node that runs etcd in
a docker container (etcd-member.service via etcd-wrapper);
acl-t has no docker daemon — the standalone `docker` sysext is
not carried and docker has no RPM replacement (same as
docker.*) — so the control plane cannot bootstrap.
- name: kubeadm.v1.33.0.cilium.base
exceptions:
- platforms: [qemu]
architectures: [aarch64]
reason: kubectl wait timeouts on emulated arm64 QEMU
- imageVariants: [acl-t]
reason: |
The kubeadm cluster provisions an etcd node that runs etcd in
a docker container (etcd-member.service via etcd-wrapper);
acl-t has no docker daemon — the standalone `docker` sysext is
not carried and docker has no RPM replacement (same as
docker.*) — so the control plane cannot bootstrap.
- name: kubeadm.v1.33.0.flannel.base
exceptions:
- platforms: [qemu]
architectures: [aarch64]
reason: kubectl wait timeouts on emulated arm64 QEMU
- imageVariants: [acl-t]
reason: |
The kubeadm cluster provisions an etcd node that runs etcd in
a docker container (etcd-member.service via etcd-wrapper);
acl-t has no docker daemon — the standalone `docker` sysext is
not carried and docker has no RPM replacement (same as
docker.*) — so the control plane cannot bootstrap.
- name: kubeadm.v1.34.1.calico.base
exceptions:
- platforms: [qemu]
architectures: [aarch64]
reason: kubectl wait timeouts on emulated arm64 QEMU
- imageVariants: [acl-t]
reason: |
The kubeadm cluster provisions an etcd node that runs etcd in
a docker container (etcd-member.service via etcd-wrapper);
acl-t has no docker daemon — the standalone `docker` sysext is
not carried and docker has no RPM replacement (same as
docker.*) — so the control plane cannot bootstrap.
- name: kubeadm.v1.34.1.cilium.base
exceptions:
- platforms: [qemu]
architectures: [aarch64]
reason: kubectl wait timeouts on emulated arm64 QEMU
- imageVariants: [acl-t]
reason: |
The kubeadm cluster provisions an etcd node that runs etcd in
a docker container (etcd-member.service via etcd-wrapper);
acl-t has no docker daemon — the standalone `docker` sysext is
not carried and docker has no RPM replacement (same as
docker.*) — so the control plane cannot bootstrap.
- name: kubeadm.v1.34.1.flannel.base
exceptions:
- platforms: [qemu]
architectures: [aarch64]
reason: kubectl wait timeouts on emulated arm64 QEMU
- imageVariants: [acl-t]
reason: |
The kubeadm cluster provisions an etcd node that runs etcd in
a docker container (etcd-member.service via etcd-wrapper);
acl-t has no docker daemon — the standalone `docker` sysext is
not carried and docker has no RPM replacement (same as
docker.*) — so the control plane cannot bootstrap.

- name: linux.nfs.v3
exceptions:
Expand All @@ -277,11 +463,50 @@ tests:
exceptions:
- platforms: [azure]
reason: Test starts a local NTP server, so it is not cloud-environment coverage
- imageVariants: [acl-t]
reason: |
Test hardcodes systemd-timesyncd (mantle kola/tests/misc/ntp.go
waits for "Synchronized to time server"); acl-t ships chronyd,
whose unit conflicts out timesyncd (upstream chronyd.service:
Conflicts=systemd-timesyncd.service). Daemon liveness is
covered by acl.basic/ServicesActive; a chrony-native sync test
(chronyc tracking) is tracked as a follow-up.

- name: sysext.custom-docker.sysext
exceptions:
- imageVariants: [acl-t]
reason: |
The test swaps in freshly-baked `docker` + `containerd`
sysexts and verifies docker starts working; on acl-t there is
no docker baseline and containerd is an RPM in the
verity-protected /usr rather than a swappable sysext, so the
swap scenario does not exist.
- name: sysext.disable-containerd
exceptions:
- imageVariants: [acl-t]
reason: |
The test masks the embedded `containerd` sysext and asserts
/usr/bin/containerd disappears; on acl-t containerd is the
moby-containerd RPM baked into the verity-protected /usr, so
masking is a no-op and the binary can never be absent.
- name: sysext.disable-docker
exceptions:
- imageVariants: [acl-t]
reason: |
The test masks the standalone `docker` sysext and asserts
/usr/bin/docker is absent; acl-t never carries a docker sysext
(docker is not part of the product), so there is nothing to
mask and the scenario is vacuous.
- name: sysext.simple
exceptions:
- imageVariants: [acl-t]
reason: |
The test merges a synthetic Ignition-provided extension via
systemd-sysext — no shipped sysext is involved; exempted
because sysext-delivered content is outside acl-t's supported
surface (everything comes from signed RPMs). Candidate to
re-enable if generic sysext support on acl-t becomes a
requirement.

- name: systemd.journal.remote
exceptions:
Expand Down
3 changes: 2 additions & 1 deletion build_library/disk_layout_uki.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,10 +10,11 @@
"layouts": {
"base": {
"1": {
"_comment": "128 MiB -> 192 MiB (blocks are 512-byte sectors). UKI boot keeps kernel+initramfs on the ESP, and the acl-t UKI rebuilt by Image Customizer needs more headroom than stock.",
"label": "EFI-SYSTEM",
"fs_label": "EFI-SYSTEM",
"type": "efi",
"blocks": "262144",
"blocks": "393216",
"fs_type": "vfat",
"mount": "/boot",
"features": []
Expand Down
8 changes: 6 additions & 2 deletions build_library/rpm/additional_files/99-acl.conf
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,12 @@ drivers+=" sd_mod sr_mod sg ahci ata_piix ata_generic libata "
drivers+=" nvme nvme_core "
# Force inclusion of filesystem drivers
drivers+=" ext4 vfat btrfs "
# Force inclusion of device-mapper and dm-verity kernel modules
drivers+=" dm_mod dm_verity "
# Force inclusion of device-mapper kernel modules (verity + crypt).
# Ignition formats LUKS volumes in the initramfs (kola cl.ignition.luks),
# and the arm64 kernel ships CONFIG_DM_CRYPT=m — the `crypt` dracut module
# does not reliably pull it in, so list dm_crypt and its ciphers explicitly.
drivers+=" dm_mod dm_verity dm_crypt "
drivers+=" aes_generic xts sha256_generic sha512_generic cbc "
# Install additional binaries and libraries that may be needed
install_items+=" /usr/sbin/blkid /usr/sbin/fsck /usr/sbin/fsck.ext4 /usr/sbin/e2fsck "
install_items+=" /usr/lib64/libcom_err.so.2 /usr/lib64/libe2p.so.2 /usr/lib64/libext2fs.so.2 "
Expand Down
Loading