Skip to content

tests/integration: Make the tests runnable on SELinux enabled daemon - #3367

Merged
vvoland merged 1 commit into
docker:mainfrom
ricardobranco777:selinux
Sep 14, 2026
Merged

vvoland merged 1 commit into
docker:mainfrom
ricardobranco777:selinux

Conversation

@ricardobranco777

@ricardobranco777 ricardobranco777 commented Oct 18, 2025 •

Copy link
Copy Markdown
Contributor

Make the tests runnable on SELinux enabled daemon.

Otherwise I get failures like these: https://openqa.opensuse.org/tests/5393787/file/python_docker-integration.txt

=================================== FAILURES ===================================
___________________ VolumeBindTest.test_create_with_binds_ro ___________________
tests/integration/api_container_test.py:511: in setUp
    self.run_with_volume(
tests/integration/api_container_test.py:636: in run_with_volume
    return self.run_container(
tests/integration/base.py:106: in run_container
    raise Exception(
E   Exception: Container exited with code 1:
E   b'touch: /mnt/shared.txt: Permission denied\n'
___________________ VolumeBindTest.test_create_with_binds_rw ___________________
tests/integration/api_container_test.py:511: in setUp
    self.run_with_volume(
tests/integration/api_container_test.py:636: in run_with_volume
    return self.run_container(
tests/integration/base.py:106: in run_container
    raise Exception(
E   Exception: Container exited with code 1:
E   b'touch: /mnt/shared.txt: Permission denied\n'
_______________ VolumeBindTest.test_create_with_binds_rw_rshared _______________
tests/integration/api_container_test.py:511: in setUp
    self.run_with_volume(
tests/integration/api_container_test.py:636: in run_with_volume
    return self.run_container(
tests/integration/base.py:106: in run_container
    raise Exception(
E   Exception: Container exited with code 1:
E   b'touch: /mnt/shared.txt: Permission denied\n'
____________________ VolumeBindTest.test_create_with_mounts ____________________
tests/integration/api_container_test.py:511: in setUp
    self.run_with_volume(
tests/integration/api_container_test.py:636: in run_with_volume
    return self.run_container(
tests/integration/base.py:106: in run_container
    raise Exception(
E   Exception: Container exited with code 1:
E   b'touch: /mnt/shared.txt: Permission denied\n'
__________________ VolumeBindTest.test_create_with_mounts_ro ___________________
tests/integration/api_container_test.py:511: in setUp
    self.run_with_volume(
tests/integration/api_container_test.py:636: in run_with_volume
    return self.run_container(
tests/integration/base.py:106: in run_container
    raise Exception(
E   Exception: Container exited with code 1:
E   b'touch: /mnt/shared.txt: Permission denied\n'
_________________ VolumeBindTest.test_create_with_volume_mount _________________
tests/integration/api_container_test.py:511: in setUp
    self.run_with_volume(
tests/integration/api_container_test.py:636: in run_with_volume
    return self.run_container(
tests/integration/base.py:106: in run_container
    raise Exception(
E   Exception: Container exited with code 1:
E   b'touch: /mnt/shared.txt: Permission denied\n'
_________________ ContainerCollectionTest.test_run_with_volume _________________
tests/integration/models_containers_test.py:58: in test_run_with_volume
    out = client.containers.run(
docker/models/containers.py:905: in run
    raise ContainerError(
E   docker.errors.ContainerError: Command 'cat /insidecontainer/test' in image 'alpine' returned non-zero exit status 1: b"cat: can't open '/insidecontainer/test': No such file or directory\n"

Signed-off-by: Ricardo Branco <rbranco@suse.de>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused test-only changes correctly address SELinux permission failures without altering library behavior.

Pull request overview

Enables volume integration tests to run against SELinux-enabled Docker daemons.

Changes:

  • Applies shared SELinux relabeling to model-level bind mounts.
  • Disables SELinux labeling where mount syntax cannot request relabeling.
File summaries
File Description
tests/integration/models_containers_test.py Adds :z to shared bind mounts.
tests/integration/api_container_test.py Adds SELinux-compatible security options to volume tests.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused test configuration changes correctly address SELinux bind-mount access failures.

Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0 new
  • Review effort level: Balanced

@vvoland
vvoland merged commit f5739cb into docker:main Sep 14, 2026
13 checks passed
@ricardobranco777
ricardobranco777 deleted the selinux branch September 14, 2026 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants