Repository navigation
test(podman): run existing Podman behavioral e2e coverage in CI #3712
Description
Activity
Looking at this one
Plan and order of operations
This issue overlaps significantly with open PR #3637 ("test(e2e): run podman suite with tmachine", author elezar), which independently adds a tmachine-based
e2e-podmannextest archive (43 tests passing) covering most of the 39 eligiblee2e-podmantargets, removespodman_userns.rsas superseded by thedriver-podmantmachine suite (resolving that acceptance criterion directly), and depends on PR #3597 (migratessync.rscoverage into conformance scenarios). Both #3637 and #3597 are currently green in CI but showmergeable: CONFLICTINGand need a rebase before they can land.Order of operations for this work:
- Treat test(e2e): run podman suite with tmachine #3637 + test(conformance): migrate file transfer coverage #3597 as prerequisites. This plan does not duplicate their work and does not touch the files they modify (
tests/ansible/playbooks/drivers/podman/e2e.yaml,tests/artifacts.nix) until they're onmain. - Track A (starting now, independent of test(e2e): run podman suite with tmachine #3637):
- Wire
podman_preflightinto CI via the existingpodman-external-driver-e2ejob's already-exported driver binary artifact (it never runs anywhere today because that job's mise task disables the cargo-test step for other reasons). - Add an automated inventory/reachability check (new
tasks/scripts/check-podman-e2e-coverage.sh, modeled oncheck-cargo-lockfiles.sh) that fails CI if a newe2e-podman-eligible test target isn't accounted for in eitherPODMAN_CI_TESTSor a documented exclusion — this directly satisfies the acceptance criterion preventing silent future omissions like this one. - Document the current test-selection contract in
CI.md.
- Wire
- Track B (after test(e2e): run podman suite with tmachine #3637 + test(conformance): migrate file transfer coverage #3597 merge):
- Extend the coverage check to also read test(e2e): run podman suite with tmachine #3637's
podmanE2eFollowUpBinariesexclusion list; file tracked follow-up issues for the exclusions that need distinct scope work (sandbox_lifecycleconformance migration,podman_oci_identitySPIFFE fixture plumbing,provider_refresh_handles's own purpose-built suite), and linktransparent_tcp's exclusion to the existing test(e2e): restore musl DNS probe coverage for guest prebuilt artifacts #3009 rather than duplicating it. - Investigate the remaining plausible quick-fix targets (
provider_auto_create,proxy_egress_pipeline,websocket_conformance,workspace_lifecycle) against a live tmachine environment. - Add a rootful leg to the new tmachine
e2e-podmantestsuite (its current playbook hardcodes rootless-only values instead of using thetmachine_container_runtimerole the waydriver-podman's playbooks already do). - Wire
driver-podman/e2e-podmaninto Release Dev and Release Tag qualification, mirroring the existingprovider-refreshjob pattern. - Add visible selected-vs-eligible test-count reporting so a narrow run can't be mistaken for full coverage.
- Extend the coverage check to also read test(e2e): run podman suite with tmachine #3637's
PRs for Track A will follow this comment. Track B PRs will follow once #3637/#3597 land.
- Treat test(e2e): run podman suite with tmachine #3637 + test(conformance): migrate file transfer coverage #3597 as prerequisites. This plan does not duplicate their work and does not touch the files they modify (
Status update given everything that's landed since the plan above:
podman_preflightis resolved via test(podman): move podman_preflight into driver-podman integration tests #3783 (reopened and approved by @elezar,/ok-to-testapplied, pending merge) rather than the original test(podman): wire podman_preflight into CI and add a Podman e2e coverage check #3749 approach.podman_usernsis resolved via test(e2e): run podman suite with tmachine #3637 (superseded by thedriver-podmantmachine suite).podman_resource_limitsnow runs for real against a live gateway via test(e2e): run podman suite with tmachine #3637's tmachinee2e-podmanarchive.
@elezar — given #3460 (Nix/tmachine target-state doc) and the string of
test(conformance)/test(tmachine)PRs you've got in flight (#3766, #3768, #3792, #3795, #3839, etc.), it looks like most of the remaining shared-target and driver-specific coverage gaps here (the 6 of 12 shared targets still excluded,podman_oci_identity,provider_refresh_handles) will fall out of that migration rather than needing separate Podman-specific CI wiring. To avoid duplicating effort, I'm deliberately not touching that migration.What I'll pick up next instead, since it's orthogonal to the conformance/driver-specific split:
- Release Dev and Release Tag bundled Podman behavioral qualification (currently absent from both).
- Selected-vs-eligible test-count reporting in job names/summaries, so a narrow run can't be mistaken for full coverage.
- Documenting the rootless-only scope of the current
e2e-podmantmachine archive (onlyfedora-podman-rootlessruns it;podman_resource_limitsspecifically would benefit from a rootful leg since it reads real cgroup v2 state and rootless cgroup delegation is the harder/riskier case).
Flag anything above that's already in flight or planned elsewhere so we don't collide again.
Thanks @politerealism. I am busy constructing a plan to migrate the
e2e/rusttests that are covered by thee2e-podmanfeature so that we can tackle that in parallel.Reacted by Polite_realism and Matthew Grossman- added a commit that references this issue
on Oct 3, 2026 Update 2026-10-06: Following up on the 2026-09-29 note above where I deferred the
e2e/rust→conformance migration to @elezar to avoid duplicating his in-flight work.Coordinated directly with Evan today on the 11 general-conformance candidates I'd flagged in a research pass on #3460. He confirmed his own plan (verify under Podman, relax gates on
provider_refresh_handles.rs/websocket_conformance.rs,sandbox_labels.rsneeds nothing) and suggested migrating applicable ones straight intotests/suites/conformance/rather than gate-relaxing in place — and invited a partial migration on my end rather than a hard handoff.Migrated so far (branch not yet opened as a PR, pending final review on my end):
workspace_lifecycle.rs→workspace-lifecycle/workspace-terminatingscenariosupload_create.rs→file-transfer/create-uploadscenario (grouped with the existing file-transfer family)provider_auto_create.rs→provider-auto-createscenariosandbox_templates.rs→ 4 scenarios (lifecycle, get-after-delete, duplicate-name, missing-template)settings_management.rs→settings-managementscenario
All verified against an ephemeral Podman gateway. Will reference #3954 (not this issue) when the PR opens, since that's the umbrella tracking issue for the RFC-0016 testing-strategy work this falls under.
Two things surfaced along the way worth noting here:
port_forward.rsdoesn't fit the conformance harness's CLI request/response model (needs a long-lived background SSH-tunnel process + raw socket I/O) — holding that one for Evan's input on whether that pattern belongs onOpenShellRunneror as a scenario-local bypass.- Found two of Evan's already-landed
file_transfer.rsconformance scenarios (round-trip,git-filtering) currently failing against main — pre-existing, unrelated to this migration, flagged to him separately.
User Story
As an OpenShell maintainer, I want the existing Podman behavioral end-to-end tests to run in required CI and release qualification, so that Podman-specific networking, lifecycle, policy, identity, resource, and provider regressions cannot merge while applicable tests remain unscheduled.
Problem Statement
OpenShell currently has a required bundled-Podman branch job, but it runs a hard-coded
PODMAN_CI_TESTSallowlist rather than the full set of targets eligible under thee2e-podmanfeature.There are currently 39 eligible Rust test targets. The curated CI set selects 20 and omits 19. Two omissions are intentionally ignored performance benchmarks, leaving 17 executable targets outside Podman behavioral CI.
Twelve of those 17 are shared, driver-independent test targets that run from the same source files in Docker and Kubernetes CI but are explicitly omitted from Podman CI:
port_forwardprovider_auto_createproxy_egress_pipelinesandbox_labelssandbox_lifecyclesandbox_templatessettings_managementsynctransparent_tcpupload_createwebsocket_conformanceworkspace_lifecycleFive are Podman-specific targets whose behavior cannot be covered by another driver:
podman_oci_identitypodman_preflightpodman_resource_limitspodman_usernsprovider_refresh_handlespodman_preflightmay need a separate lightweight invocation because it expects the standaloneopenshell-driver-podmanbinary. The olderpodman_usernsRust target should either run or be removed as superseded by the newer rootful/rootless tmachine user-namespace suite.The bundled Podman behavioral job is also present only in the branch workflow. Release Dev and Release Tag do not run the bundled Podman behavioral suite.
This is a follow-up to #3663. PR #3690 added the resource-limit and daemon-failure targets and broadened rootful user-namespace testing, but the new Rust targets were not added to
PODMAN_CI_TESTS. PR #3606 restored a bundled Podman branch lane after thehost.openshell.internalregression, but intentionally limited it to targets known to pass at that time.Impact / Why This Matters
This scheduling gap has already allowed a Podman host-networking regression to merge even though relevant e2e coverage existed. It creates the same exposure for transparent networking, proxy enforcement, port forwarding, lifecycle cleanup, resource enforcement, OCI identity, workspace operations, and credential refresh.
The current workaround is for contributors to know that
mise run e2e:podmanis broader than required CI and run it manually on a compatible Linux Podman host. That is insufficient because:Acceptance Criteria
podman_oci_identity,podman_resource_limits, andprovider_refresh_handlesrun against a real Podman-backed OpenShell gateway in CI.podman_preflightruns in CI with the standalone Podman driver artifact and verifies the bounded, actionable daemon-unavailable failure path.podman_usernsis either enabled or removed with its assertions demonstrably covered by the rootful/rootlessdriver-podmantmachine suite.e2e-podmantarget is not selected by a workflow, unless it appears in a checked-in exclusion list with a rationale and tracking issue.Reproduction Steps
[[test]]declarations and auto-discovered files undere2e/rust/tests/that are eligible with thee2e-podmanfeature againstPODMAN_CI_TESTSine2e/rust/e2e-podman.sh.OPENSHELL_E2E_PODMAN_TEST_SET=ci..github/workflows/branch-e2e.ymland observe that required branch CI invokesmise run e2e:podman:ci, not the fullmise run e2e:podmansuite..github/workflows/release-dev.ymland.github/workflows/release-tag.ymland observe that neither has a bundled Podman behavioral job.Environment
mainat924486805e2e/rust/e2e-podman.sh,e2e/rust/Cargo.toml,.github/workflows/branch-e2e.yml,.github/workflows/e2e-podman-test.ymlRelated Work
host.openshell.internalregression