File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -58,7 +58,9 @@ async fn vm_overlay() {
5858 sandbox. cleanup ( ) . await ;
5959}
6060
61- const IDENTITY_MAIN : & str = "set -eu; if ! test -f /sandbox/canonical-identity; then printf '%s:%s\\ n' \" $(id -u)\" \" $(id -g)\" > /sandbox/canonical-identity; fi; echo vm-identity-ready; exec sleep infinity" ;
61+ // VM stop terminates the guest without flushing its page cache. Flush this
62+ // fixture before readiness so restart checks durable file content and ownership.
63+ const IDENTITY_MAIN : & str = "set -eu; if ! test -f /sandbox/canonical-identity; then printf '%s:%s\\ n' \" $(id -u)\" \" $(id -g)\" > /sandbox/canonical-identity; sync; fi; echo vm-identity-ready; exec sleep infinity" ;
6264
6365fn identity_policy ( user : & str , group : & str ) -> tempfile:: NamedTempFile {
6466 let file = tempfile:: NamedTempFile :: new ( ) . expect ( "temporary identity policy" ) ;
@@ -86,7 +88,7 @@ network_policies: {{}}
8688async fn assert_workload_identity ( sandbox : & SandboxGuard ) -> ( String , String ) {
8789 let output = sandbox. exec ( & [
8890 "sh" , "-c" ,
89- "set -eu; actual=$(id -u):$(id -g); test \" $(cat /sandbox/canonical-identity)\" = \" $actual \" ; test \" $ (stat -c %u:%g /sandbox/canonical-identity)\" = \" $actual\" ; printf 'identity=%s\\ n' \" $actual\" " ,
91+ "set -eu; actual=$(id -u):$(id -g); canonical= $(cat /sandbox/canonical-identity); owner=$ (stat -c %u:%g /sandbox/canonical-identity); printf 'exec=%s canonical=%s owner=%s \\ n' \" $actual \" \" $canonical \" \" $owner \" ; test \" $canonical \" = \" $actual \" ; test \" $owner \" = \" $actual\" ; printf 'identity=%s\\ n' \" $actual\" " ,
9092 ] ) . await . expect ( "canonical and exec identities and file ownership agree" ) ;
9193 let clean = strip_ansi ( & output) ;
9294 let pair = clean
You can’t perform that action at this time.
0 commit comments