Skip to content

[1.3] ci: fix conmon job - #5409

Open
kolyshkin wants to merge 2 commits into
opencontainers:release-1.3from
kolyshkin:1.3-5401
Open

[1.3] ci: fix conmon job#5409
kolyshkin wants to merge 2 commits into
opencontainers:release-1.3from
kolyshkin:1.3-5401

Conversation

@kolyshkin

Copy link
Copy Markdown
Contributor

Backport of #5401 to release-1.3. Original description follows.


Fixes #5399.

The validate / conmon job was mostly passing only because it failed
to pull an image (due to running a big number of parallel pulls I guess)
and skipped the test. This is being fixed in
containers/conmon#668).

Recently the pull started to succeed sometimes, which resulted in
test being actually run, and fail due to nested userns restriction
in Ubuntu, and the missing fixup for that.

This PR adds the fixup, and uses a fixed conmon tests from
containers/conmon#668.

kolyshkin and others added 2 commits August 18, 2026 14:34
On Ubuntu 24.04 runners, kernel.apparmor_restrict_unprivileged_userns is
set to 1, so an unconfined process that creates a user namespace is
transitioned to the unprivileged_userns AppArmor profile, which denies
CAP_SYS_ADMIN. As a result, rootless runc creates and maps the user
namespace fine and then fails to unshare the remaining ones:

  runc create failed: unable to start container process: can't get final
  child's PID from pipe: EOF; runc init error(s): nsexec-1: failed to
  unshare remaining namespaces: Operation not permitted

and dmesg shows:

  apparmor="AUDIT" operation="userns_create" info="Userns create -
  transitioning profile" profile="unconfined" comm="runc:[1:CHILD]"
  target="unprivileged_userns"
  apparmor="DENIED" operation="capable" profile="unprivileged_userns"
  comm="runc:[1:CHILD]" capability=21 capname="sys_admin"

Use the same workaround as in test.yml: load an AppArmor profile for the
runc binary being tested.

This went unnoticed because the conmon tests skip when the test image
can't be pulled, so the job was green whenever the pull failed, and only
red when the tests actually ran.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
(cherry picked from commit bde597a)
conmon's test suite skips its container tests when the test image can't
be pulled, and reports the run as successful, so the conmon job here was
green whenever the pull failed and red only when the tests actually ran.

Bump to conmon main, which contains
containers/conmon#668 turning that into a hard
failure, so that this job tests what it is supposed to test.

To be replaced with a conmon tag once one is released (> v2.2.1).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
(cherry picked from commit 2048d84)
@kolyshkin kolyshkin added area/ci backport/1.3-pr A backport PR to release-1.3 labels Aug 18, 2026

@thaJeztah thaJeztah left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kolyshkin kolyshkin added this to the 1.3.7 milestone Aug 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ci backport/1.3-pr A backport PR to release-1.3

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants