A bind mount tracks the inode, not the path. When the host replaces one
of the HOST_WATCH files, the container mount keeps pointing at the
unlinked inode and findmnt reports it with a "//deleted" source. The
keepalive loop only compared file contents, so a byte-identical recreate
left the mount disconnected, and when /run/host exposed the same deleted
peer the content check could never trigger at all.
Signed-off-by: Luca Di Maio <luca.dimaio1@gmail.com>
- scripts.go: ProvisionScripts reuses the helpers if already present, else
extracts into the install dir when writable, otherwise falls back to
$XDG_DATA_HOME/distrobox. Fixes rootless create/enter for a system-wide
install (/usr/local/bin), which died with "permission denied"
- hack/test/nvidia-test.sh: run box ops rootless as the cloud user
- hack/test/vm-run.sh: bump the ubuntu image to resolute.
Signed-off-by: Luca Di Maio <luca.dimaio1@gmail.com>
The migrate command introduced a parallel insidedistrobox.ScriptsDir()
that resolved to the old v2 prerelease location
(~/.local/share/distrobox/v2), which was abandoned in 94ae7fa with a
BREAKING CHANGE note. The two resolutions only agree when
DBX_SCRIPTS_DIR is set, which is exactly what the tests do - hiding the
divergence: migrate provisioned and filtered on a different host
directory than the create command mounts into new containers.
- drop insidedistrobox.ScriptsDir(); migrate now provisions and filters
on c.cfg.ScriptsDir, the same resolution the create command uses
- set ScriptsDir on the recreated container's CreateOptions: it was
left empty, which made ProvisionScripts("") fail on real runtimes
- make the scripts-mount filter path-boundary aware
- add an end-to-end migration test driving a fake podman runtime:
v1 inspect JSON in, then compare the recreated container's create
spec to the known-good v2 layout (scripts mounted from the config
scripts dir, distrobox.version label set, v1 helper mounts gone)
Unit tests can't prove the rewritten binary actually works on each supported
distro and on both podman and docker; this exercises the real thing.
Move the tests in a set of simple scripts to run them.
Make a smaller e2e test for CLI and Images that runs on every PR
Keep the full compatibility suite in a separate job for main merge and
manual runs.
Signed-off-by: Luca Di Maio <luca.dimaio1@gmail.com>
Lock down the container-name slug, enter env allow/deny, and podman/docker
ps parsers so provider JSON drift and symlink/env edge cases fail in CI
instead of in the field. Fixtures also capture the known doc/code and
comma-in-label quirks so they're tracked rather than silently accepted.
Signed-off-by: Luca Di Maio <luca.dimaio1@gmail.com>
The harness boots real VMs, so gate it to PRs touching distrobox-init or the
test itself instead of every push.
Base images use a split cache restore/save and on failure the per-distro log
dir is uploaded so it's debuggable without a re-run.
Signed-off-by: Luca Di Maio <luca.dimaio1@gmail.com>
The --nvidia path had no automated coverage and regresses easily (silent
32/64-bit collisions, dropped files), and GPU CI runners to exercise it
don't exist. This harness needs no GPU: it installs the nvidia driver in a
throwaway VM, runs `distrobox create --nvidia` against ubuntu/fedora/arch
guests, and checks every file the host package manager ships is mirrored in
with a matching checksum and resolvable deps. The package manifest is the
source of truth, so any gap fails loudly instead of silently.
Signed-off-by: Luca Di Maio <luca.dimaio1@gmail.com>
ROCm and other GPU workloads reach the device through /dev/kfd and
/dev/dri/renderD*, which are typically owned by group render (mode 0660).
Podman keeps the invoking user's supplementary groups via the
run.oci.keep_original_groups annotation, but the docker path forwarded only
the primary gid, so the container user was not in render/video and hit EACCES.
This generally puts docker on par with podman+crun
run.oci.keep_original_groups annotation.
Signed-off-by: Luca Di Maio <luca.dimaio1@gmail.com>
The --nvidia path mapped each driver library to a guest destination by
rewriting its host path (x86_64-linux-gnu / lib64 / lib32 via sed), which is
fragile across distros and can shadow the guest's own libGL/glvnd/Mesa.
Mount libs into /usr/lib/distrobox-nvidia/{lib64,lib32} bucketed by ELF class +
one ld.so.conf, instead of guessing the guest path; 4 mount loops fold into one.
Signed-off-by: Luca Di Maio <luca.dimaio1@gmail.com>