42dafe4b |
package main
import (
"bufio" |
7d62e40f |
"context" |
9462dbb2 |
"fmt" |
16562406 |
"os" |
42dafe4b |
"os/exec" |
9462dbb2 |
"reflect" |
f7541b00 |
"runtime" |
9462dbb2 |
"sort" |
42dafe4b |
"strings" |
9462dbb2 |
"sync" |
e25352a4 |
"testing" |
42dafe4b |
"time" |
dc944ea7 |
|
0fd5a654 |
"github.com/docker/docker/client" |
db35c2a5 |
"github.com/docker/docker/integration-cli/cli" |
50c4475d |
"github.com/docker/docker/integration-cli/cli/build" |
6345208b |
"gotest.tools/assert"
is "gotest.tools/assert/cmp" |
38457285 |
"gotest.tools/icmd" |
42dafe4b |
)
|
64a928a3 |
func (s *DockerSuite) TestExec(c *testing.T) { |
f9a3558a |
testRequires(c, DaemonIsLinux) |
0a7755ab |
out, _ := dockerCmd(c, "run", "-d", "--name", "testing", "busybox", "sh", "-c", "echo test > /tmp/file && top") |
6345208b |
assert.NilError(c, waitRun(strings.TrimSpace(out))) |
70407ce4 |
|
0a7755ab |
out, _ = dockerCmd(c, "exec", "testing", "cat", "/tmp/file") |
6345208b |
assert.Equal(c, strings.Trim(out, "\r\n"), "test") |
42dafe4b |
}
|
64a928a3 |
func (s *DockerSuite) TestExecInteractive(c *testing.T) { |
f9a3558a |
testRequires(c, DaemonIsLinux) |
668e2369 |
dockerCmd(c, "run", "-d", "--name", "testing", "busybox", "sh", "-c", "echo test > /tmp/file && top") |
42dafe4b |
execCmd := exec.Command(dockerBinary, "exec", "-i", "testing", "sh")
stdin, err := execCmd.StdinPipe() |
6345208b |
assert.NilError(c, err) |
42dafe4b |
stdout, err := execCmd.StdoutPipe() |
6345208b |
assert.NilError(c, err) |
42dafe4b |
|
9120a1fc |
err = execCmd.Start() |
6345208b |
assert.NilError(c, err) |
9120a1fc |
_, err = stdin.Write([]byte("cat /tmp/file\n")) |
6345208b |
assert.NilError(c, err) |
42dafe4b |
r := bufio.NewReader(stdout)
line, err := r.ReadString('\n') |
6345208b |
assert.NilError(c, err) |
42dafe4b |
line = strings.TrimSpace(line) |
6345208b |
assert.Equal(c, line, "test") |
9120a1fc |
err = stdin.Close() |
6345208b |
assert.NilError(c, err) |
4203230c |
errChan := make(chan error) |
42dafe4b |
go func() { |
4203230c |
errChan <- execCmd.Wait()
close(errChan) |
42dafe4b |
}()
select { |
4203230c |
case err := <-errChan: |
6345208b |
assert.NilError(c, err) |
42dafe4b |
case <-time.After(1 * time.Second): |
dc944ea7 |
c.Fatal("docker exec failed to exit on stdin close") |
42dafe4b |
}
}
|
64a928a3 |
func (s *DockerSuite) TestExecAfterContainerRestart(c *testing.T) { |
a899aa67 |
out := runSleepingContainer(c) |
475c6531 |
cleanedContainerID := strings.TrimSpace(out) |
6345208b |
assert.NilError(c, waitRun(cleanedContainerID)) |
668e2369 |
dockerCmd(c, "restart", cleanedContainerID) |
6345208b |
assert.NilError(c, waitRun(cleanedContainerID)) |
42dafe4b |
|
668e2369 |
out, _ = dockerCmd(c, "exec", cleanedContainerID, "echo", "hello") |
6345208b |
assert.Equal(c, strings.TrimSpace(out), "hello") |
42dafe4b |
}
|
64a928a3 |
func (s *DockerDaemonSuite) TestExecAfterDaemonRestart(c *testing.T) { |
a768bf86 |
// TODO Windows CI: DockerDaemonSuite doesn't run on Windows, and requires a little work to get this ported. |
c502fb49 |
s.d.StartWithBusybox(c) |
42dafe4b |
|
9120a1fc |
out, err := s.d.Cmd("run", "-d", "--name", "top", "-p", "80", "busybox:latest", "top") |
6345208b |
assert.NilError(c, err, "Could not run top: %s", out) |
42dafe4b |
|
c502fb49 |
s.d.Restart(c) |
42dafe4b |
|
9120a1fc |
out, err = s.d.Cmd("start", "top") |
6345208b |
assert.NilError(c, err, "Could not start top after daemon restart: %s", out) |
42dafe4b |
|
9120a1fc |
out, err = s.d.Cmd("exec", "top", "echo", "hello") |
6345208b |
assert.NilError(c, err, "Could not exec on container top: %s", out)
assert.Equal(c, strings.TrimSpace(out), "hello") |
42dafe4b |
} |
2bceaae4 |
|
906974b1 |
// Regression test for #9155, #9044 |
64a928a3 |
func (s *DockerSuite) TestExecEnv(c *testing.T) { |
a9379b4a |
// TODO Windows CI: This one is interesting and may just end up being a feature
// difference between Windows and Linux. On Windows, the environment is passed
// into the process that is launched, not into the machine environment. Hence
// a subsequent exec will not have LALA set/ |
f9a3558a |
testRequires(c, DaemonIsLinux) |
a9379b4a |
runSleepingContainer(c, "-e", "LALA=value1", "-e", "LALA=value2", "-d", "--name", "testing") |
6345208b |
assert.NilError(c, waitRun("testing")) |
2bceaae4 |
|
668e2369 |
out, _ := dockerCmd(c, "exec", "testing", "env") |
6345208b |
assert.Check(c, !strings.Contains(out, "LALA=value1"))
assert.Check(c, strings.Contains(out, "LALA=value2"))
assert.Check(c, strings.Contains(out, "HOME=/root")) |
2bceaae4 |
} |
90928eb1 |
|
64a928a3 |
func (s *DockerSuite) TestExecSetEnv(c *testing.T) { |
e03bf122 |
testRequires(c, DaemonIsLinux)
runSleepingContainer(c, "-e", "HOME=/root", "-d", "--name", "testing") |
6345208b |
assert.NilError(c, waitRun("testing")) |
e03bf122 |
out, _ := dockerCmd(c, "exec", "-e", "HOME=/another", "-e", "ABC=xyz", "testing", "env") |
6345208b |
assert.Check(c, !strings.Contains(out, "HOME=/root"))
assert.Check(c, strings.Contains(out, "HOME=/another"))
assert.Check(c, strings.Contains(out, "ABC=xyz")) |
e03bf122 |
}
|
64a928a3 |
func (s *DockerSuite) TestExecExitStatus(c *testing.T) { |
a9379b4a |
runSleepingContainer(c, "-d", "--name", "top") |
90928eb1 |
|
d7022f2b |
result := icmd.RunCommand(dockerBinary, "exec", "top", "sh", "-c", "exit 23") |
92427b3a |
result.Assert(c, icmd.Expected{ExitCode: 23, Error: "exit status 23"}) |
90928eb1 |
} |
1bb02117 |
|
64a928a3 |
func (s *DockerSuite) TestExecPausedContainer(c *testing.T) { |
69985e85 |
testRequires(c, IsPausable) |
1bb02117 |
|
a899aa67 |
out := runSleepingContainer(c, "-d", "--name", "testing") |
475c6531 |
ContainerID := strings.TrimSpace(out) |
1bb02117 |
|
668e2369 |
dockerCmd(c, "pause", "testing") |
73e2f555 |
out, _, err := dockerCmdWithError("exec", ContainerID, "echo", "hello") |
6345208b |
assert.ErrorContains(c, err, "", "container should fail to exec new command if it is paused") |
1bb02117 |
expected := ContainerID + " is paused, unpause the container before exec" |
6345208b |
assert.Assert(c, is.Contains(out, expected), "container should not exec new command if it is paused") |
1bb02117 |
} |
243a640d |
// regression test for #9476 |
64a928a3 |
func (s *DockerSuite) TestExecTTYCloseStdin(c *testing.T) { |
a9379b4a |
// TODO Windows CI: This requires some work to port to Windows. |
f9a3558a |
testRequires(c, DaemonIsLinux) |
668e2369 |
dockerCmd(c, "run", "-d", "-it", "--name", "exec_tty_stdin", "busybox") |
243a640d |
|
668e2369 |
cmd := exec.Command(dockerBinary, "exec", "-i", "exec_tty_stdin", "cat") |
243a640d |
stdinRw, err := cmd.StdinPipe() |
6345208b |
assert.NilError(c, err) |
243a640d |
stdinRw.Write([]byte("test"))
stdinRw.Close()
|
9120a1fc |
out, _, err := runCommandWithOutput(cmd) |
6345208b |
assert.NilError(c, err, out) |
243a640d |
|
9120a1fc |
out, _ = dockerCmd(c, "top", "exec_tty_stdin") |
243a640d |
outArr := strings.Split(out, "\n") |
6345208b |
assert.Assert(c, len(outArr) <= 3, "exec process left running")
assert.Assert(c, !strings.Contains(out, "nsenter-exec")) |
243a640d |
} |
67e3ddb7 |
|
64a928a3 |
func (s *DockerSuite) TestExecTTYWithoutStdin(c *testing.T) { |
668e2369 |
out, _ := dockerCmd(c, "run", "-d", "-ti", "busybox") |
67e3ddb7 |
id := strings.TrimSpace(out) |
6345208b |
assert.NilError(c, waitRun(id)) |
67e3ddb7 |
|
4203230c |
errChan := make(chan error) |
67e3ddb7 |
go func() { |
4203230c |
defer close(errChan) |
67e3ddb7 |
cmd := exec.Command(dockerBinary, "exec", "-ti", id, "true")
if _, err := cmd.StdinPipe(); err != nil { |
4203230c |
errChan <- err
return |
67e3ddb7 |
}
|
f7541b00 |
expected := "the input device is not a TTY"
if runtime.GOOS == "windows" {
expected += ". If you are using mintty, try prefixing the command with 'winpty'"
} |
67e3ddb7 |
if out, _, err := runCommandWithOutput(cmd); err == nil { |
4203230c |
errChan <- fmt.Errorf("exec should have failed")
return |
67e3ddb7 |
} else if !strings.Contains(out, expected) { |
4203230c |
errChan <- fmt.Errorf("exec failed with error %q: expected %q", out, expected)
return |
67e3ddb7 |
}
}()
select { |
4203230c |
case err := <-errChan: |
6345208b |
assert.NilError(c, err) |
67e3ddb7 |
case <-time.After(3 * time.Second): |
dc944ea7 |
c.Fatal("exec is running but should have failed") |
67e3ddb7 |
}
} |
7fdbd90f |
|
def13fa2 |
// FIXME(vdemeester) this should be a unit tests on cli/command/container package |
64a928a3 |
func (s *DockerSuite) TestExecParseError(c *testing.T) { |
a9379b4a |
// TODO Windows CI: Requires some extra work. Consider copying the
// runSleepingContainer helper to have an exec version. |
f9a3558a |
testRequires(c, DaemonIsLinux) |
668e2369 |
dockerCmd(c, "run", "-d", "--name", "top", "busybox", "top") |
7fdbd90f |
// Test normal (non-detached) case first |
def13fa2 |
icmd.RunCommand(dockerBinary, "exec", "top").Assert(c, icmd.Expected{
ExitCode: 1,
Error: "exit status 1",
Err: "See 'docker exec --help'",
}) |
7fdbd90f |
} |
eda92e88 |
|
64a928a3 |
func (s *DockerSuite) TestExecStopNotHanging(c *testing.T) { |
a9379b4a |
// TODO Windows CI: Requires some extra work. Consider copying the
// runSleepingContainer helper to have an exec version. |
f9a3558a |
testRequires(c, DaemonIsLinux) |
668e2369 |
dockerCmd(c, "run", "-d", "--name", "testing", "busybox", "top") |
eda92e88 |
|
617f89b9 |
result := icmd.StartCmd(icmd.Command(dockerBinary, "exec", "testing", "top"))
result.Assert(c, icmd.Success)
go icmd.WaitOnCmd(0, result) |
eda92e88 |
|
4203230c |
type dstop struct { |
617f89b9 |
out string |
4203230c |
err error
}
ch := make(chan dstop) |
eda92e88 |
go func() { |
617f89b9 |
result := icmd.RunCommand(dockerBinary, "stop", "testing")
ch <- dstop{result.Combined(), result.Error} |
4203230c |
close(ch) |
eda92e88 |
}()
select {
case <-time.After(3 * time.Second): |
dc944ea7 |
c.Fatal("Container stop timed out") |
4203230c |
case s := <-ch: |
6345208b |
assert.NilError(c, s.err) |
eda92e88 |
}
} |
9462dbb2 |
|
64a928a3 |
func (s *DockerSuite) TestExecCgroup(c *testing.T) { |
a9379b4a |
// Not applicable on Windows - using Linux specific functionality |
ea3afdad |
testRequires(c, NotUserNamespace) |
f9a3558a |
testRequires(c, DaemonIsLinux) |
668e2369 |
dockerCmd(c, "run", "-d", "--name", "testing", "busybox", "top") |
9462dbb2 |
|
668e2369 |
out, _ := dockerCmd(c, "exec", "testing", "cat", "/proc/1/cgroup")
containerCgroups := sort.StringSlice(strings.Split(out, "\n")) |
9462dbb2 |
var wg sync.WaitGroup |
dc944ea7 |
var mu sync.Mutex |
f23c00d8 |
var execCgroups []sort.StringSlice |
4203230c |
errChan := make(chan error) |
9462dbb2 |
// exec a few times concurrently to get consistent failure
for i := 0; i < 5; i++ {
wg.Add(1)
go func() { |
693ba98c |
out, _, err := dockerCmdWithError("exec", "testing", "cat", "/proc/self/cgroup") |
9462dbb2 |
if err != nil { |
4203230c |
errChan <- err
return |
9462dbb2 |
} |
668e2369 |
cg := sort.StringSlice(strings.Split(out, "\n")) |
9462dbb2 |
|
dc944ea7 |
mu.Lock() |
9462dbb2 |
execCgroups = append(execCgroups, cg) |
dc944ea7 |
mu.Unlock() |
9462dbb2 |
wg.Done()
}()
}
wg.Wait() |
4203230c |
close(errChan)
for err := range errChan { |
6345208b |
assert.NilError(c, err) |
4203230c |
} |
9462dbb2 |
for _, cg := range execCgroups {
if !reflect.DeepEqual(cg, containerCgroups) {
fmt.Println("exec cgroups:")
for _, name := range cg {
fmt.Printf(" %s\n", name)
}
fmt.Println("container cgroups:")
for _, name := range containerCgroups {
fmt.Printf(" %s\n", name)
} |
dc944ea7 |
c.Fatal("cgroups mismatched") |
9462dbb2 |
}
}
} |
957cbdbf |
|
64a928a3 |
func (s *DockerSuite) TestExecInspectID(c *testing.T) { |
a899aa67 |
out := runSleepingContainer(c, "-d") |
957cbdbf |
id := strings.TrimSuffix(out, "\n")
|
62a856e9 |
out = inspectField(c, id, "ExecIDs") |
6345208b |
assert.Equal(c, out, "[]", "ExecIDs should be empty, got: %s", out) |
957cbdbf |
|
fe6a7c8e |
// Start an exec, have it block waiting so we can do some checking
cmd := exec.Command(dockerBinary, "exec", id, "sh", "-c", |
a9379b4a |
"while ! test -e /execid1; do sleep 1; done") |
72b75cd4 |
|
62a856e9 |
err := cmd.Start() |
6345208b |
assert.NilError(c, err, "failed to start the exec cmd") |
72b75cd4 |
// Give the exec 10 chances/seconds to start then give up and stop the test
tries := 10
for i := 0; i < tries; i++ { |
f06620ec |
// Since its still running we should see exec as part of the container |
8dd8ec13 |
out = strings.TrimSpace(inspectField(c, id, "ExecIDs")) |
f06620ec |
|
72b75cd4 |
if out != "[]" && out != "<no value>" {
break
} |
6345208b |
assert.Check(c, i+1 != tries, "ExecIDs still empty after 10 second") |
72b75cd4 |
time.Sleep(1 * time.Second)
}
// Save execID for later
execID, err := inspectFilter(id, "index .ExecIDs 0") |
6345208b |
assert.NilError(c, err, "failed to get the exec id") |
957cbdbf |
|
fe6a7c8e |
// End the exec by creating the missing file |
6345208b |
err = exec.Command(dockerBinary, "exec", id, "sh", "-c", "touch /execid1").Run()
assert.NilError(c, err, "failed to run the 2nd exec cmd") |
fe6a7c8e |
// Wait for 1st exec to complete |
72b75cd4 |
cmd.Wait()
|
8dd8ec13 |
// Give the exec 10 chances/seconds to stop then give up and stop the test
for i := 0; i < tries; i++ {
// Since its still running we should see exec as part of the container
out = strings.TrimSpace(inspectField(c, id, "ExecIDs")) |
957cbdbf |
|
8dd8ec13 |
if out == "[]" {
break
} |
6345208b |
assert.Check(c, i+1 != tries, "ExecIDs still empty after 10 second") |
8dd8ec13 |
time.Sleep(1 * time.Second)
} |
72b75cd4 |
// But we should still be able to query the execID |
c8ff5ecc |
cli, err := client.NewClientWithOpts(client.FromEnv) |
6345208b |
assert.NilError(c, err) |
0fd5a654 |
defer cli.Close() |
4bd18952 |
|
0fd5a654 |
_, err = cli.ContainerExecInspect(context.Background(), execID) |
6345208b |
assert.NilError(c, err) |
d841b779 |
// Now delete the container and then an 'inspect' on the exec should
// result in a 404 (not 'container not running')
out, ec := dockerCmd(c, "rm", "-f", id) |
6345208b |
assert.Equal(c, ec, 0, "error removing container: %s", out) |
0fd5a654 |
_, err = cli.ContainerExecInspect(context.Background(), execID) |
6345208b |
assert.ErrorContains(c, err, "No such exec instance") |
957cbdbf |
} |
43d1c201 |
|
64a928a3 |
func (s *DockerSuite) TestLinksPingLinkedContainersOnRename(c *testing.T) { |
a9379b4a |
// Problematic on Windows as Windows does not support links |
f9a3558a |
testRequires(c, DaemonIsLinux) |
43d1c201 |
var out string |
dc944ea7 |
out, _ = dockerCmd(c, "run", "-d", "--name", "container1", "busybox", "top") |
475c6531 |
idA := strings.TrimSpace(out) |
6345208b |
assert.Assert(c, idA != "", "%s, id should not be nil", out) |
dc944ea7 |
out, _ = dockerCmd(c, "run", "-d", "--link", "container1:alias1", "--name", "container2", "busybox", "top") |
475c6531 |
idB := strings.TrimSpace(out) |
6345208b |
assert.Assert(c, idB != "", "%s, id should not be nil", out) |
43d1c201 |
|
668e2369 |
dockerCmd(c, "exec", "container2", "ping", "-c", "1", "alias1", "-W", "1") |
dc944ea7 |
dockerCmd(c, "rename", "container1", "container_new") |
668e2369 |
dockerCmd(c, "exec", "container2", "ping", "-c", "1", "alias1", "-W", "1") |
43d1c201 |
}
|
64a928a3 |
func (s *DockerSuite) TestRunMutableNetworkFiles(c *testing.T) { |
a9379b4a |
// Not applicable on Windows to Windows CI. |
43b15e92 |
testRequires(c, testEnv.IsLocalDaemon, DaemonIsLinux) |
6a2c6e97 |
for _, fn := range []string{"resolv.conf", "hosts"} { |
10e171cd |
containers := cli.DockerCmd(c, "ps", "-q", "-a").Combined()
if containers != "" {
cli.DockerCmd(c, append([]string{"rm", "-fv"}, strings.Split(strings.TrimSpace(containers), "\n")...)...)
} |
6a2c6e97 |
|
ecbb0e62 |
content := runCommandAndReadContainerFile(c, fn, dockerBinary, "run", "-d", "--name", "c1", "busybox", "sh", "-c", fmt.Sprintf("echo success >/etc/%s && top", fn)) |
6a2c6e97 |
|
6345208b |
assert.Equal(c, strings.TrimSpace(string(content)), "success", "Content was not what was modified in the container", string(content)) |
6a2c6e97 |
|
668e2369 |
out, _ := dockerCmd(c, "run", "-d", "--name", "c2", "busybox", "top") |
6a2c6e97 |
contID := strings.TrimSpace(out)
netFilePath := containerStorageFile(contID, fn)
f, err := os.OpenFile(netFilePath, os.O_WRONLY|os.O_SYNC|os.O_APPEND, 0644) |
6345208b |
assert.NilError(c, err) |
6a2c6e97 |
if _, err := f.Seek(0, 0); err != nil {
f.Close() |
dc944ea7 |
c.Fatal(err) |
6a2c6e97 |
}
if err := f.Truncate(0); err != nil {
f.Close() |
dc944ea7 |
c.Fatal(err) |
6a2c6e97 |
}
if _, err := f.Write([]byte("success2\n")); err != nil {
f.Close() |
dc944ea7 |
c.Fatal(err) |
6a2c6e97 |
}
f.Close()
|
668e2369 |
res, _ := dockerCmd(c, "exec", contID, "cat", "/etc/"+fn) |
6345208b |
assert.Equal(c, res, "success2\n") |
6a2c6e97 |
}
} |
2cce4791 |
|
64a928a3 |
func (s *DockerSuite) TestExecWithUser(c *testing.T) { |
a9379b4a |
// TODO Windows CI: This may be fixable in the future once Windows
// supports users |
f9a3558a |
testRequires(c, DaemonIsLinux) |
668e2369 |
dockerCmd(c, "run", "-d", "--name", "parent", "busybox", "top") |
2cce4791 |
|
668e2369 |
out, _ := dockerCmd(c, "exec", "-u", "1", "parent", "id") |
6345208b |
assert.Assert(c, strings.Contains(out, "uid=1(daemon) gid=1(daemon)")) |
2cce4791 |
|
668e2369 |
out, _ = dockerCmd(c, "exec", "-u", "root", "parent", "id") |
6345208b |
assert.Assert(c, strings.Contains(out, "uid=0(root) gid=0(root)"), "exec with user by id expected daemon user got %s", out) |
2cce4791 |
} |
0faa4518 |
|
64a928a3 |
func (s *DockerSuite) TestExecWithPrivileged(c *testing.T) { |
a9379b4a |
// Not applicable on Windows |
ea3afdad |
testRequires(c, DaemonIsLinux, NotUserNamespace) |
90326939 |
// Start main loop which attempts mknod repeatedly
dockerCmd(c, "run", "-d", "--name", "parent", "--cap-drop=ALL", "busybox", "sh", "-c", `while (true); do if [ -e /exec_priv ]; then cat /exec_priv && mknod /tmp/sda b 8 0 && echo "Success"; else echo "Privileged exec has not run yet"; fi; usleep 10000; done`) |
03f65b3d |
|
90326939 |
// Check exec mknod doesn't work |
ecbb0e62 |
icmd.RunCommand(dockerBinary, "exec", "parent", "sh", "-c", "mknod /tmp/sdb b 8 16").Assert(c, icmd.Expected{
ExitCode: 1,
Err: "Operation not permitted",
}) |
03f65b3d |
|
90326939 |
// Check exec mknod does work with --privileged |
ecbb0e62 |
result := icmd.RunCommand(dockerBinary, "exec", "--privileged", "parent", "sh", "-c", `echo "Running exec --privileged" > /exec_priv && mknod /tmp/sdb b 8 16 && usleep 50000 && echo "Finished exec --privileged" > /exec_priv && echo ok`)
result.Assert(c, icmd.Success) |
03f65b3d |
|
ecbb0e62 |
actual := strings.TrimSpace(result.Combined()) |
6345208b |
assert.Equal(c, actual, "ok", "exec mknod in --cap-drop=ALL container with --privileged failed, output: %q", result.Combined()) |
03f65b3d |
|
90326939 |
// Check subsequent unprivileged exec cannot mknod |
ecbb0e62 |
icmd.RunCommand(dockerBinary, "exec", "parent", "sh", "-c", "mknod /tmp/sdc b 8 32").Assert(c, icmd.Expected{
ExitCode: 1,
Err: "Operation not permitted",
}) |
90326939 |
// Confirm at no point was mknod allowed |
ecbb0e62 |
result = icmd.RunCommand(dockerBinary, "logs", "parent")
result.Assert(c, icmd.Success) |
6345208b |
assert.Assert(c, !strings.Contains(result.Combined(), "Success")) |
03f65b3d |
}
|
64a928a3 |
func (s *DockerSuite) TestExecWithImageUser(c *testing.T) { |
a9379b4a |
// Not applicable on Windows |
f9a3558a |
testRequires(c, DaemonIsLinux) |
0faa4518 |
name := "testbuilduser" |
50c4475d |
buildImageSuccessfully(c, name, build.WithDockerfile(`FROM busybox |
0faa4518 |
RUN echo 'dockerio:x:1001:1001::/bin:/bin/false' >> /etc/passwd |
c10f6ef4 |
USER dockerio`)) |
0faa4518 |
dockerCmd(c, "run", "-d", "--name", "dockerioexec", name, "top")
out, _ := dockerCmd(c, "exec", "dockerioexec", "whoami") |
6345208b |
assert.Assert(c, strings.Contains(out, "dockerio"), "exec with user by id expected dockerio user got %s", out) |
0faa4518 |
} |
bfc51cf6 |
|
64a928a3 |
func (s *DockerSuite) TestExecOnReadonlyContainer(c *testing.T) { |
a9379b4a |
// Windows does not support read-only |
ea3afdad |
// --read-only + userns has remount issues
testRequires(c, DaemonIsLinux, NotUserNamespace) |
bfc51cf6 |
dockerCmd(c, "run", "-d", "--read-only", "--name", "parent", "busybox", "top") |
9120a1fc |
dockerCmd(c, "exec", "parent", "true") |
bfc51cf6 |
} |
fcf9daad |
|
64a928a3 |
func (s *DockerSuite) TestExecUlimits(c *testing.T) { |
8891afd8 |
testRequires(c, DaemonIsLinux)
name := "testexeculimits" |
d4e132f8 |
runSleepingContainer(c, "-d", "--ulimit", "nofile=511:511", "--name", name) |
6345208b |
assert.NilError(c, waitRun(name)) |
8891afd8 |
|
d4e132f8 |
out, _, err := dockerCmdWithError("exec", name, "sh", "-c", "ulimit -n") |
6345208b |
assert.NilError(c, err)
assert.Equal(c, strings.TrimSpace(out), "511") |
8891afd8 |
}
|
fcf9daad |
// #15750 |
64a928a3 |
func (s *DockerSuite) TestExecStartFails(c *testing.T) { |
a9379b4a |
// TODO Windows CI. This test should be portable. Figure out why it fails
// currently. |
d9f5f195 |
testRequires(c, DaemonIsLinux) |
fcf9daad |
name := "exec-15750" |
a9379b4a |
runSleepingContainer(c, "-d", "--name", name) |
6345208b |
assert.NilError(c, waitRun(name)) |
fcf9daad |
|
9077c896 |
out, _, err := dockerCmdWithError("exec", name, "no-such-cmd") |
6345208b |
assert.ErrorContains(c, err, "", out)
assert.Assert(c, strings.Contains(out, "executable file not found")) |
fcf9daad |
} |
e880bbc4 |
// Fix regression in https://github.com/docker/docker/pull/26461#issuecomment-250287297 |
64a928a3 |
func (s *DockerSuite) TestExecWindowsPathNotWiped(c *testing.T) { |
e880bbc4 |
testRequires(c, DaemonIsWindows)
out, _ := dockerCmd(c, "run", "-d", "--name", "testing", minimalBaseImage(), "powershell", "start-sleep", "60") |
6345208b |
assert.NilError(c, waitRun(strings.TrimSpace(out))) |
e880bbc4 |
out, _ = dockerCmd(c, "exec", "testing", "powershell", "write-host", "$env:PATH")
out = strings.ToLower(strings.Trim(out, "\r\n")) |
6345208b |
assert.Assert(c, strings.Contains(out, `windowspowershell\v1.0`)) |
e880bbc4 |
} |
e9814596 |
|
64a928a3 |
func (s *DockerSuite) TestExecEnvLinksHost(c *testing.T) { |
e9814596 |
testRequires(c, DaemonIsLinux)
runSleepingContainer(c, "-d", "--name", "foo")
runSleepingContainer(c, "-d", "--link", "foo:db", "--hostname", "myhost", "--name", "bar")
out, _ := dockerCmd(c, "exec", "bar", "env") |
6345208b |
assert.Check(c, is.Contains(out, "HOSTNAME=myhost"))
assert.Check(c, is.Contains(out, "DB_NAME=/bar/db")) |
e9814596 |
} |