Skip to content

Commit

Permalink
Add node e2e tests for hostPid
Browse files Browse the repository at this point in the history
  • Loading branch information
feiskyer committed Apr 7, 2017
1 parent 2d023d9 commit dc034fc
Show file tree
Hide file tree
Showing 3 changed files with 157 additions and 0 deletions.
17 changes: 17 additions & 0 deletions test/e2e/framework/pods.go
Expand Up @@ -202,6 +202,23 @@ func (c *PodClient) WaitForSuccess(name string, timeout time.Duration) {
)).To(Succeed(), "wait for pod %q to success", name)
}

// WaitForFinished waits for pod to be finished with success or failure.
func (c *PodClient) WaitForFinished(name string, timeout time.Duration) {
f := c.f
Expect(WaitForPodCondition(f.ClientSet, f.Namespace.Name, name, "success or failure", timeout,
func(pod *v1.Pod) (bool, error) {
switch pod.Status.Phase {
case v1.PodFailed:
return true, nil
case v1.PodSucceeded:
return true, nil
default:
return false, nil
}
},
)).To(Succeed(), "wait for pod %q to success", name)
}

// WaitForSuccess waits for pod to succeed or an error event for that pod.
func (c *PodClient) WaitForErrorEventOrSuccess(pod *v1.Pod) (*v1.Event, error) {
var ev *v1.Event
Expand Down
1 change: 1 addition & 0 deletions test/e2e_node/BUILD
Expand Up @@ -81,6 +81,7 @@ go_test(
"resource_usage_test.go",
"restart_test.go",
"runtime_conformance_test.go",
"security_context_test.go",
"summary_test.go",
"volume_manager_test.go",
],
Expand Down
139 changes: 139 additions & 0 deletions test/e2e_node/security_context_test.go
@@ -0,0 +1,139 @@
/*
Copyright 2017 The Kubernetes Authors.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

package e2e_node

import (
"fmt"
"strings"
"time"

metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"k8s.io/apimachinery/pkg/util/sets"
"k8s.io/apimachinery/pkg/util/uuid"
"k8s.io/kubernetes/pkg/api/v1"
"k8s.io/kubernetes/test/e2e/framework"

. "github.com/onsi/ginkgo"
. "github.com/onsi/gomega"
)

var _ = framework.KubeDescribe("Security Context", func() {
f := framework.NewDefaultFramework("security-context-test")
var podClient *framework.PodClient
BeforeEach(func() {
podClient = f.PodClient()
})

Context("when creating a pod in the host PID namespace", func() {
makeHostPidPod := func(podName, image string, command []string, hostPID bool) *v1.Pod {
return &v1.Pod{
ObjectMeta: metav1.ObjectMeta{
Name: podName,
},
Spec: v1.PodSpec{
RestartPolicy: v1.RestartPolicyNever,
HostPID: hostPID,
Containers: []v1.Container{
{
Image: image,
Name: podName,
Command: command,
},
},
},
}
}
createAndWaitHostPidPod := func(podName string, hostPID bool) {
podClient.Create(makeHostPidPod(podName,
"gcr.io/google_containers/busybox:1.24",
[]string{"sh", "-c", "pidof nginx"},
hostPID,
))

if hostPID {
podClient.WaitForSuccess(podName, framework.PodStartTimeout)
} else {
podClient.WaitForFinished(podName, framework.PodStartTimeout)
}

}

nginxPid := ""
BeforeEach(func() {
nginxPodName := "nginx-hostpid-" + string(uuid.NewUUID())
podClient.CreateSync(makeHostPidPod(nginxPodName,
"gcr.io/google_containers/nginx-slim:0.7",
nil,
true,
))

output := f.ExecShellInContainer(nginxPodName, nginxPodName,
"cat /var/run/nginx.pid")
nginxPid = strings.TrimSpace(output)
})

It("should show its pid in the host PID namespace", func() {
busyboxPodName := "busybox-hostpid-" + string(uuid.NewUUID())
createAndWaitHostPidPod(busyboxPodName, true)

Eventually(func() error {
logs, err := framework.GetPodLogs(f.ClientSet, f.Namespace.Name, busyboxPodName, busyboxPodName)
if err != nil {
return err
}

pids := strings.TrimSpace(logs)
framework.Logf("Got nginx's pid %q from pod %q", pids, busyboxPodName)
if pids == "" {
return fmt.Errorf("nginx's pid should be seen by hostpid containers")
}

pidSets := sets.NewString(strings.Split(pids, " ")...)
if !pidSets.Has(nginxPid) {
return fmt.Errorf("nginx's pid should be seen by hostpid containers")
}

return nil
}, time.Minute, time.Second*4).Should(BeNil())
})

It("should not show its pid in the non-hostpid containers", func() {
busyboxPodName := "busybox-non-hostpid-" + string(uuid.NewUUID())
createAndWaitHostPidPod(busyboxPodName, false)

Eventually(func() error {
logs, err := framework.GetPodLogs(f.ClientSet, f.Namespace.Name, busyboxPodName, busyboxPodName)
if err != nil {
return err
}

pids := strings.TrimSpace(logs)
framework.Logf("Got nginx's pid %q from pod %q", pids, busyboxPodName)
if pids == "" {
return nil
}

pidSets := sets.NewString(strings.Split(pids, " ")...)
if pidSets.Has(nginxPid) {
return fmt.Errorf("nginx's pid should not be seen by non-hostpid containers")
}

return nil
}, time.Minute, time.Second*4).Should(BeNil())
})
})
})

0 comments on commit dc034fc

Please sign in to comment.