capabilities_linux_test.go 2.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108
  1. package capabilities
  2. import (
  3. "bytes"
  4. "io"
  5. "strings"
  6. "testing"
  7. "time"
  8. "github.com/docker/docker/api/types"
  9. containertypes "github.com/docker/docker/api/types/container"
  10. "github.com/docker/docker/integration/internal/container"
  11. "github.com/docker/docker/pkg/stdcopy"
  12. "github.com/docker/docker/testutil"
  13. "github.com/docker/docker/testutil/fakecontext"
  14. "gotest.tools/v3/assert"
  15. "gotest.tools/v3/poll"
  16. )
  17. func TestNoNewPrivileges(t *testing.T) {
  18. ctx := setupTest(t)
  19. withFileCapability := `
  20. FROM debian:bullseye-slim
  21. RUN apt-get update && apt-get install -y libcap2-bin --no-install-recommends
  22. RUN setcap CAP_DAC_OVERRIDE=+eip /bin/cat
  23. RUN echo "hello" > /txt && chown 0:0 /txt && chmod 700 /txt
  24. RUN useradd -u 1500 test
  25. `
  26. imageTag := "captest"
  27. source := fakecontext.New(t, "", fakecontext.WithDockerfile(withFileCapability))
  28. defer source.Close()
  29. client := testEnv.APIClient()
  30. // Build image
  31. resp, err := client.ImageBuild(ctx,
  32. source.AsTarReader(t),
  33. types.ImageBuildOptions{
  34. Tags: []string{imageTag},
  35. })
  36. assert.NilError(t, err)
  37. _, err = io.Copy(io.Discard, resp.Body)
  38. assert.NilError(t, err)
  39. resp.Body.Close()
  40. testCases := []struct {
  41. doc string
  42. opts []func(*container.TestContainerConfig)
  43. stdOut, stdErr string
  44. }{
  45. {
  46. doc: "CapabilityRequested=true",
  47. opts: []func(*container.TestContainerConfig){
  48. container.WithUser("test"),
  49. container.WithCapability("CAP_DAC_OVERRIDE"),
  50. },
  51. stdOut: "hello",
  52. },
  53. {
  54. doc: "CapabilityRequested=false",
  55. opts: []func(*container.TestContainerConfig){
  56. container.WithUser("test"),
  57. container.WithDropCapability("CAP_DAC_OVERRIDE"),
  58. },
  59. stdErr: "exec /bin/cat: operation not permitted",
  60. },
  61. }
  62. for _, tc := range testCases {
  63. tc := tc
  64. t.Run(tc.doc, func(t *testing.T) {
  65. ctx := testutil.StartSpan(ctx, t)
  66. // Run the container with the image
  67. opts := append(tc.opts,
  68. container.WithImage(imageTag),
  69. container.WithCmd("/bin/cat", "/txt"),
  70. container.WithSecurityOpt("no-new-privileges=true"),
  71. )
  72. cid := container.Run(ctx, t, client, opts...)
  73. poll.WaitOn(t, container.IsInState(ctx, client, cid, "exited"), poll.WithDelay(100*time.Millisecond))
  74. // Assert on outputs
  75. logReader, err := client.ContainerLogs(ctx, cid, containertypes.LogsOptions{
  76. ShowStdout: true,
  77. ShowStderr: true,
  78. })
  79. assert.NilError(t, err)
  80. defer logReader.Close()
  81. var actualStdout, actualStderr bytes.Buffer
  82. _, err = stdcopy.StdCopy(&actualStdout, &actualStderr, logReader)
  83. assert.NilError(t, err)
  84. stdOut := strings.TrimSpace(actualStdout.String())
  85. stdErr := strings.TrimSpace(actualStderr.String())
  86. if stdOut != tc.stdOut {
  87. t.Fatalf("test produced invalid output: %q, expected %q. Stderr:%q", stdOut, tc.stdOut, stdErr)
  88. }
  89. if stdErr != tc.stdErr {
  90. t.Fatalf("test produced invalid error: %q, expected %q. Stdout:%q", stdErr, tc.stdErr, stdOut)
  91. }
  92. })
  93. }
  94. }