public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/buildah] update-buildah-cve-2026-46597: [c9s] TMT: enable gating tests maintained upstream
@ 2026-08-05 18:47 Lokesh Mandvekar
  0 siblings, 0 replies; only message in thread
From: Lokesh Mandvekar @ 2026-08-05 18:47 UTC (permalink / raw)
  To: git-commits

            A new commit has been pushed.

            Repo   : rpms/buildah
            Branch : update-buildah-cve-2026-46597
            Commit : 01cb5a98d048a1006b7ea79801bdbd167bbd6c19
            Author : Lokesh Mandvekar <lsm5@fedoraproject.org>
            Date   : 2025-03-03T15:16:26+05:30
            Stats  : +83/-277 in 12 file(s)
            URL    : https://src.fedoraproject.org/rpms/buildah/c/01cb5a98d048a1006b7ea79801bdbd167bbd6c19?branch=update-buildah-cve-2026-46597

            Log:
            [c9s] TMT: enable gating tests maintained upstream

Resolves: RHEL-80816

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>

---
diff --git a/.fmf/version b/.fmf/version
new file mode 100644
index 0000000..d00491f
--- /dev/null
+++ b/.fmf/version
@@ -0,0 +1 @@
+1

diff --git a/buildah.spec b/buildah.spec
index 50f3882..fd3ba55 100644
--- a/buildah.spec
+++ b/buildah.spec
@@ -83,9 +83,7 @@ or
 Summary: Tests for %{name}
 
 Requires: %{name} = %{epoch}:%{version}-%{release}
-%if %{defined fedora}
 Requires: bats
-%endif
 Requires: bzip2
 Requires: podman
 Requires: golang
@@ -98,7 +96,8 @@ Requires: git-daemon
 %description tests
 %{summary}
 
-This package contains system tests for %{name}
+This package contains system tests for %{name}. Only intended for distro
+gating tests. End user / customer usage not supported.
 
 %prep
 %autosetup -Sgit -n %{name}-%{version}

diff --git a/gating.yaml b/gating.yaml
index e49fcf1..1fb3172 100644
--- a/gating.yaml
+++ b/gating.yaml
@@ -1,7 +1,16 @@
-# recipients: jnovy, lsm5, santiago
 --- !Policy
 product_versions:
-  - rhel-9
+  - fedora-*
+decision_contexts:
+  - bodhi_update_push_stable
+  - bodhi_update_push_testing
+subject_type: koji_build
+rules:
+  - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional}
+
+--- !Policy
+product_versions:
+  - rhel-*
 decision_context: osci_compose_gate
 rules:
   - !PassingTestCaseRule {test_case_name: osci.brew-build.tier0.functional}

diff --git a/plans/main.fmf b/plans/main.fmf
new file mode 100644
index 0000000..b982e76
--- /dev/null
+++ b/plans/main.fmf
@@ -0,0 +1,34 @@
+discover:
+    how: fmf
+
+execute:
+    how: tmt
+
+prepare:
+    - when: distro == centos-stream or distro == rhel
+      how: shell
+      script: |
+        dnf -y install https://dl.fedoraproject.org/pub/epel/epel-release-latest-$(rpm --eval '%{?rhel}').noarch.rpm
+        dnf -y config-manager --set-enabled epel
+      order: 10
+    - when: initiator == packit
+      how: shell
+      script: |
+        COPR_REPO_FILE="/etc/yum.repos.d/*podman-next*.repo"
+        if compgen -G $COPR_REPO_FILE > /dev/null; then
+            sed -i -n '/^priority=/!p;$apriority=1' $COPR_REPO_FILE
+        fi
+        dnf -y upgrade --allowerasing
+      order: 20
+
+provision:
+    how: artemis
+    hardware:
+        memory: ">= 16 GB"
+        cpu:
+            cores: ">= 4"
+            threads: ">=8"
+        disk:
+            - size: ">= 512 GB"
+
+

diff --git a/tests/roles/bats_installed/tasks/main.yml b/tests/roles/bats_installed/tasks/main.yml
deleted file mode 100644
index 20a73f3..0000000
--- a/tests/roles/bats_installed/tasks/main.yml
+++ /dev/null
@@ -1,12 +0,0 @@
----
-# Sigh; RHEL8 doesn't have BATS
-- name: bats | fetch and unpack tarball
-  unarchive:
-    src: https://github.com/bats-core/bats-core/archive/v1.9.0.tar.gz
-    dest: /root
-    remote_src: true
-
-- name: bats | install
-  command: ./install.sh /usr/local
-  args:
-    chdir: /root/bats-core-1.9.0

diff --git a/tests/roles/run_bats_tests/files/helper.buildah-root.sh b/tests/roles/run_bats_tests/files/helper.buildah-root.sh
deleted file mode 100644
index 118c193..0000000
--- a/tests/roles/run_bats_tests/files/helper.buildah-root.sh
+++ /dev/null
@@ -1,38 +0,0 @@
-#!/bin/bash
-#
-# setup and teardown helpers for buildah test
-#
-
-function setup() {
-    REGISTRY_FQIN=quay.io/libpod/registry:2
-
-    AUTHDIR=/tmp/buildah-tests-auth.$$
-    mkdir -p $AUTHDIR
-
-    CERT=$AUTHDIR/domain.crt
-    if [ ! -e $CERT ]; then
-        openssl req -newkey rsa:4096 -nodes -sha256 \
-                -keyout $AUTHDIR/domain.key -x509 -days 2 \
-                -out $AUTHDIR/domain.crt \
-                -subj "/C=US/ST=Foo/L=Bar/O=Red Hat, Inc./CN=registry host certificate" \
-                -addext subjectAltName=DNS:localhost
-    fi
-
-    if [ ! -e $AUTHDIR/htpasswd ]; then
-        htpasswd -Bbn testuser testpassword > $AUTHDIR/htpasswd
-    fi
-
-    podman run -d -p 5000:5000 \
-           --name registry \
-           -v $AUTHDIR:/auth:Z \
-           -e "REGISTRY_AUTH=htpasswd" \
-           -e "REGISTRY_AUTH_HTPASSWD_REALM=Registry Realm" \
-           -e REGISTRY_AUTH_HTPASSWD_PATH=/auth/htpasswd \
-           -e REGISTRY_HTTP_TLS_CERTIFICATE=/auth/domain.crt \
-           -e REGISTRY_HTTP_TLS_KEY=/auth/domain.key \
-           $REGISTRY_FQIN
-}
-
-function teardown() {
-    podman rm -f registry
-}

diff --git a/tests/roles/run_bats_tests/files/run_bats_tests.sh b/tests/roles/run_bats_tests/files/run_bats_tests.sh
deleted file mode 100755
index d5ed4ff..0000000
--- a/tests/roles/run_bats_tests/files/run_bats_tests.sh
+++ /dev/null
@@ -1,103 +0,0 @@
-#!/bin/bash
-#
-# Run bats tests for a given $TEST_PACKAGE, e.g. buildah, podman
-#
-# This is invoked by the 'run_bats_tests' role; we assume that
-# the package foo has a foo-tests subpackage which provides the
-# directory /usr/share/foo/test/system, containing one or more .bats
-# test files.
-#
-
-export PATH=/usr/local/bin:/usr/sbin:/usr/bin
-
-# Keep all logs in /tmp/artifacts - this seems to be an undocumented
-# (and therefore dangerous and unreliable) convention of the Standard
-# Test Roles package. As of 2020-05 we have to coexist with cockpit
-# which uses standard-test-basic, which means we need to conform to
-# its conventions.
-# We rely on our parent playbook to create /tmp/artifacts and make it
-# world-writable so nonroot tests can use it.
-TEST_LOG_TXT=/tmp/artifacts/test.log
-TEST_LOG_YML=/tmp/artifacts/results.yml
-
-# "podman root" -> "podman-root"
-testname_oneword=${TEST_NAME// /-}
-
-FULL_LOG=/tmp/artifacts/test.${testname_oneword}.debug.log
-BATS_LOG=/tmp/artifacts/test.${testname_oneword}.bats.log
-rm -f $FULL_LOG $BATS_LOG
-touch $FULL_LOG $BATS_LOG
-
-exec &> $FULL_LOG
-
-# Log program versions
-echo "Packages:"
-(
-    uname -r
-    rpm -qa |\
-        egrep 'buildah|conmon|container|crun|iptable|podman|runc|skopeo|slirp|systemd' |\
-        sort
-) | sed -e 's/^/  /'
-
-echo "------------------------------"
-printenv | sort
-
-testdir=/usr/share/${TEST_PACKAGE}/test/system
-
-if ! cd $testdir; then
-    echo "FAIL ${TEST_NAME} : cd $testdir"      >> $TEST_LOG_TXT
-    echo "- { test: '${TEST_NAME}', result: error, logs: [ $(basename $FULL_LOG) ] }" >> $TEST_LOG_YML
-    exit 0
-fi
-
-if [ -e /tmp/helper.sh ]; then
-    echo "------------------------------"
-    echo ". /tmp/helper.sh"
-    . /tmp/helper.sh
-fi
-
-if [ "$(type -t setup)" = "function" ]; then
-    echo "------------------------------"
-    echo "\$ setup"
-    setup
-    if [ $? -ne 0 ]; then
-        echo "FAIL ${TEST_NAME} : setup"       >> $TEST_LOG_TXT
-        echo "- { test: '${TEST_NAME}', result: error, logs: [ $(basename $FULL_LOG) ] }" >> $TEST_LOG_YML
-        exit 0
-    fi
-fi
-
-echo "------------------------------"
-echo "\$ bats ."
-bats . &> $BATS_LOG
-rc=$?
-
-echo "------------------------------"
-echo "bats completed with status $rc"
-
-status=PASS
-if [ $rc -ne 0 ]; then
-    status=FAIL
-fi
-
-echo "${status} ${TEST_NAME}" >> $TEST_LOG_TXT
-
-# Append a stanza to results.yml
-(
-    echo "- test: ${TEST_NAME}"
-    # pass/fail - the ',,' (comma comma) converts to lower-case
-    echo "  result: ${status,,}"
-    echo "  logs:"
-    echo "  - $(basename $BATS_LOG)"
-    echo "  - $(basename $FULL_LOG)"
-)  >> $TEST_LOG_YML
-
-
-if [ "$(type -t teardown)" = "function" ]; then
-    echo "------------------------------"
-    echo "\$ teardown"
-    teardown
-fi
-
-# FIXME: for CI purposes, always exit 0. This allows subsequent tests.
-exit 0

diff --git a/tests/roles/run_bats_tests/tasks/main.yml b/tests/roles/run_bats_tests/tasks/main.yml
deleted file mode 100644
index ef97d3a..0000000
--- a/tests/roles/run_bats_tests/tasks/main.yml
+++ /dev/null
@@ -1,50 +0,0 @@
----
-# Create a directory for artifacts on remote host
-- name: create remote artifacts directory
-  file:
-    path: /tmp/artifacts
-    state: directory
-    mode: 0777
-
-# Create empty results file, world-writable so rootless test can log to it
-- name: initialize test.log file
-  copy: dest=/tmp/artifacts/test.log content='' force=yes mode=0666
-
-# Same with results.yml file
-- name: initialize results.yml file
-  copy: dest=/tmp/artifacts/results.yml content='results:\n' force=yes mode=0666
-
-- name: execute tests
-  include: run_one_test.yml
-  with_items: "{{ tests }}"
-  loop_control:
-    loop_var: test
-
-- name: pull test.log and results.yml
-  fetch:
-    src: "{{ item }}"
-    dest: "{{ artifacts }}/"
-    flat: yes
-  with_items:
-    - /tmp/artifacts/test.log
-    - /tmp/artifacts/results.yml
-
-# Copied from standard-test-basic
-- name: check results
-  shell: grep "^FAIL" /tmp/artifacts/test.log
-  register: test_fails
-  # Never fail at this step. Just store result of tests.
-  failed_when: False
-
-- name: preserve results
-  set_fact:
-    role_result_failed: "{{ (test_fails.stdout|d|length > 0) or (test_fails.stderr|d|length > 0) }}"
-    role_result_msg: "{{ test_fails.stdout|d('tests failed.') }}"
-
-- name: display results
-  vars:
-    msg: |
-       Tests failed: {{ role_result_failed|d('Undefined') }}
-       Tests msg: {{ role_result_msg|d('None') }}
-  debug:
-    msg: "{{ msg.split('\n') }}"

diff --git a/tests/roles/run_bats_tests/tasks/run_one_test.yml b/tests/roles/run_bats_tests/tasks/run_one_test.yml
deleted file mode 100644
index 00d5291..0000000
--- a/tests/roles/run_bats_tests/tasks/run_one_test.yml
+++ /dev/null
@@ -1,52 +0,0 @@
----
-- name: "{{ test.name }} | install test packages"
-  dnf: name="{{ test.package }}-tests" state=installed
-
-- name: "{{ test.name }} | define helper variables"
-  set_fact:
-    test_name_oneword: "{{ test.name | replace(' ','-') }}"
-
-# UGH. This is necessary because our caller sets some environment variables
-# and we need to set a few more based on other caller variables; then we
-# need to combine the two dicts when running the test. This seems to be
-# the only way to do it in ansible.
-- name: "{{ test.name }} | define local environment"
-  set_fact:
-    local_environment:
-      TEST_NAME:    "{{ test.name }}"
-      TEST_PACKAGE: "{{ test.package }}"
-      TEST_ENV:     "{{ test.environment }}"
-
-- name: "{{ test.name }} | setup/teardown helper | see if exists"
-  local_action: stat path={{ role_path }}/files/helper.{{ test_name_oneword }}.sh
-  register: helper
-
-- name: "{{ test.name }} | setup/teardown helper | install"
-  copy: src=helper.{{ test_name_oneword }}.sh dest=/tmp/helper.sh
-  when: helper.stat.exists
-
-- name: "{{ test.name }} | run test"
-  script: ./run_bats_tests.sh
-  args:
-    chdir: /usr/share/{{ test.package }}/test/system
-  become: "{{ true if test.become is defined else false }}"
-  become_user: testuser
-  environment: "{{ local_environment | combine(test.environment) }}"
-
-- name: "{{ test.name }} | pull logs"
-  fetch:
-    src: "/tmp/artifacts/test.{{ test_name_oneword }}.{{ item }}.log"
-    dest: "{{ artifacts }}/"
-    flat: yes
-  with_items:
-    - bats
-    - debug
-
-- name: "{{ test.name }} | remove remote logs and helpers"
-  file:
-    dest=/tmp/{{ item }}
-    state=absent
-  with_items:
-    - artifacts/test.{{ test_name_oneword }}.bats.log
-    - artifacts/test.{{ test_name_oneword }}.debug.log
-    - helper.sh

diff --git a/tests/tests.yml b/tests/tests.yml
deleted file mode 100644
index c1a23c9..0000000
--- a/tests/tests.yml
+++ /dev/null
@@ -1,17 +0,0 @@
----
-- hosts: localhost
-  tags:  classic
-  vars:
-  - artifacts: ./artifacts
-  roles:
-  - role: bats_installed
-  - role: run_bats_tests
-    tests:
-    - name:    buildah root
-      package: buildah
-      environment:
-        TMPDIR: /var/tmp
-        BUILDAH_BINARY: /usr/bin/buildah
-        IMGTYPE_BINARY: /usr/bin/buildah-imgtype
-        COPY_BINARY: /usr/bin/buildah-copy
-        TUTORIAL_BINARY: /usr/bin/buildah-tutorial

diff --git a/tests/tmt/system.fmf b/tests/tmt/system.fmf
new file mode 100644
index 0000000..f34f4d9
--- /dev/null
+++ b/tests/tmt/system.fmf
@@ -0,0 +1,17 @@
+require:
+    - buildah-tests
+    - git-daemon
+    - slirp4netns
+
+environment:
+    BUILDAH_BINARY: /usr/bin/buildah
+    IMGTYPE_BINARY: /usr/bin/buildah-imgtype
+    INET_BINARY: /usr/bin/buildah-inet
+    COPY_BINARY: /usr/bin/buildah-copy
+    TUTORIAL_BINARY: /usr/bin/buildah-tutorial
+    TMPDIR: /var/tmp
+
+/local/root:
+    summary: System test
+    test: bash ./system.sh
+    duration: 60m

diff --git a/tests/tmt/system.sh b/tests/tmt/system.sh
new file mode 100644
index 0000000..73553aa
--- /dev/null
+++ b/tests/tmt/system.sh
@@ -0,0 +1,18 @@
+#!/usr/bin/env bash
+
+set -exo pipefail
+
+uname -r
+
+rpm -q \
+    aardvark-dns \
+    buildah \
+    buildah-tests \
+    conmon \
+    container-selinux \
+    containers-common \
+    crun \
+    netavark \
+    systemd
+
+bats /usr/share/buildah/test/system

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-05 18:47 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-05 18:47 [rpms/buildah] update-buildah-cve-2026-46597: [c9s] TMT: enable gating tests maintained upstream Lokesh Mandvekar

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox