linux-integrity.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Roberto Sassu <roberto.sassu@huawei.com>
To: <zohar@linux.ibm.com>
Cc: <pvorel@suse.cz>, <vt@altlinux.org>,
	<linux-integrity@vger.kernel.org>,
	Roberto Sassu <roberto.sassu@huawei.com>
Subject: [RFC][PATCH ima-evm-utils 2/7] Download mount-idmapped
Date: Thu, 22 Jul 2021 19:34:09 +0200	[thread overview]
Message-ID: <20210722173414.1738041-3-roberto.sassu@huawei.com> (raw)
In-Reply-To: <20210722173414.1738041-1-roberto.sassu@huawei.com>

mount-idmapped is a tool to create idmapped mounts, a feature recently
integrated in kernel 5.12 and that allows processes to see a different UID
and GID on that mount.

This patch downloads (errors are ignored) an artifact from
$MOUNT_IDMAPPED_URL/mount-idmapped, where MOUNT_IDMAPPED_URL is an
environment variable to be set in the configuration of the testing platform
(for Github Actions, the variable should be added in an environment named
'test').

Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
---
 .github/workflows/ci.yml | 4 ++++
 .travis.yml              | 5 +++++
 2 files changed, 9 insertions(+)

diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
index 51f7dbe0aaa6..4cfffbbd85f7 100644
--- a/.github/workflows/ci.yml
+++ b/.github/workflows/ci.yml
@@ -140,6 +140,10 @@ jobs:
         if [ -f linux ]; then
                 chmod +x linux
         fi
+        curl -L ${{ secrets.MOUNT_IDMAPPED_URL }}/mount-idmapped -s -f --output mount-idmapped || echo
+        if [ -f mount-idmapped ]; then
+                chmod +x mount-idmapped
+        fi
 
     - name: Compiler version
       run: $CC --version
diff --git a/.travis.yml b/.travis.yml
index 23c220e857b6..f3e3d93e1907 100644
--- a/.travis.yml
+++ b/.travis.yml
@@ -104,6 +104,11 @@ before_install:
         if [ -f "linux" ]; then
                 chmod +x linux
         fi
+    - curl -L $MOUNT_IDMAPPED_URL/mount-idmapped -s -f --output mount-idmapped || echo
+    - >
+        if [ -f "mount-idmapped" ]; then
+                chmod +x mount-idmapped
+        fi
     - $CONTAINER build $CONTAINER_ARGS -t ima-evm-utils .
 
 script:
-- 
2.25.1


  parent reply	other threads:[~2021-07-22 17:34 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-07-22 17:34 [RFC][PATCH ima-evm-utils 0/7] ima-evm-utils: Add UML support and tests for EVM portable signatures Roberto Sassu
2021-07-22 17:34 ` [RFC][PATCH ima-evm-utils 1/7] Download UML kernel and signing key Roberto Sassu
2021-07-22 17:34 ` Roberto Sassu [this message]
2021-07-22 17:34 ` [RFC][PATCH ima-evm-utils 3/7] Add additional options to the container engine Roberto Sassu
2021-07-22 17:34 ` [RFC][PATCH ima-evm-utils 4/7] Add functions to the testing library to run a test script with UML Roberto Sassu
2021-07-22 17:34 ` [RFC][PATCH ima-evm-utils 5/7] Signal failures of tests executed by UML kernel with unclean shutdown Roberto Sassu
2021-07-22 17:34 ` [RFC][PATCH ima-evm-utils 6/7] Introduce TST_LIST variable to select a test to execute Roberto Sassu
2021-07-22 17:34 ` [RFC][PATCH ima-evm-utils 7/7] Add tests for EVM portable signatures Roberto Sassu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20210722173414.1738041-3-roberto.sassu@huawei.com \
    --to=roberto.sassu@huawei.com \
    --cc=linux-integrity@vger.kernel.org \
    --cc=pvorel@suse.cz \
    --cc=vt@altlinux.org \
    --cc=zohar@linux.ibm.com \
    --subject='Re: [RFC][PATCH ima-evm-utils 2/7] Download mount-idmapped' \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).