CI smoke test does not exercise AWX's real invocation (ansible-runner worker as uid 1000) #3
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
The CI smoke test and
tests/smoke-test.shdo not exercise the code path AWX actually uses, so failures like the world-writable warning (#1) or a broken non-root worker slip through CI.What CI does today
.gitea/workflows/build.yml:63-72:and
tests/smoke-test.sh:25:What AWX actually does
awx/main/utils/execution_environments.pybuilds the job pod with:and the pod runs as the image's
USER 1000/ gid 0, with no volumes. So the real invocation isansible-runner worker, as uid 1000, against an in-image/runner(not a bind mount).Why it matters
ansible-runner runas root cannot catch permission/ownership problems that only show up for uid 1000.workersubcommand is the one that sets up/runner/projectand triggers the world-writable warning;rundoes not.-v ...:Z) masks the image's own/runnerpermissions.Suggested fix
Add a second check to CI/smoke test that mirrors AWX:
Plus an assertion that
/runnerand/runner/projectare not world-writable, and a check that the worker starts as uid 1000 without errors.Impact
Test gap only, but it hides the exact class of bug that motivated this file (a Debian EE that works locally but not in AWX).
Moved to beads:
work-po8