test: fix nginx to run as non-root user#179
Conversation
|
With this fix, there is still issues with |
d3c867d to
23a6f0d
Compare
|
It's not clear to me what fails at your end. I can run the tests successfully as an unprivileged user with Debian trixie. The nginx errors are somewhat expected for unprivileged users, but should not be fatal: rauc-hawkbit-updater/test/conftest.py Lines 237 to 238 in b201399 Can you provide logs of a pytest run with |
|
Here is a run on |
23a6f0d to
e4d3004
Compare
|
Okay, since it's officially documented, we should apply the config directives. Rebased on top of #188 and marked as draft for now. Once the depending PRs are merged, we can mark this as "ready for review". |
f84e82e to
b18ac03
Compare
ea506c5 to
1e28022
Compare
Under some unknown circumstances, the current nginx config run as
non-root still leads to fatal errors:
$ ./test/wait-for-hawkbit-online && dbus-run-session -- pytest -v -o log_cli=true test/test_download.py
[...]
test/test_download.py::test_download_too_slow
-------------------------------------------------------- live log call --------------------------------------------------------
INFO nginx running: nginx -c /tmp/pytest-of-thibaud/pytest-8/nginx0/nginx.conf -p .
INFO nginx nginx: [alert] could not open error log file: open() "/var/log/nginx/error.log" failed (13: Permission denied)
INFO nginx 2024/06/28 15:41:56 [emerg] 1450257#1450257: mkdir() "/var/lib/nginx/tmp/client_body" failed (13: Permission denied)
SKIPPED (nginx failed, use -s to see logs) [ 42%]
test/test_download.py::test_download_partials_without_resume
------------------------------------------------------- live log setup --------------------------------------------------------
INFO nginx running: nginx -c /tmp/pytest-of-thibaud/pytest-8/nginx1/nginx.conf -p .
INFO nginx nginx: [alert] could not open error log file: open() "/var/log/nginx/error.log" failed (13: Permission denied)
INFO nginx 2024/06/28 15:41:56 [emerg] 1450258#1450258: mkdir() "/var/lib/nginx/tmp/client_body" failed (13: Permission denied)
SKIPPED (nginx failed, use -s to see logs) [ 57%]
test/test_download.py::test_download_partials_with_resume SKIPPED (nginx failed, use -s to see logs) [ 71%]
test/test_download.py::test_download_slow_with_resume
-------------------------------------------------------- live log call --------------------------------------------------------
INFO nginx running: nginx -c /tmp/pytest-of-thibaud/pytest-8/nginx2/nginx.conf -p .
INFO nginx nginx: [alert] could not open error log file: open() "/var/log/nginx/error.log" failed (13: Permission denied)
INFO nginx 2024/06/28 15:41:56 [emerg] 1450259#1450259: mkdir() "/var/lib/nginx/tmp/client_body" failed (13: Permission denied)
SKIPPED (nginx failed, use -s to see logs)
The section "Running nginx as a non-root user" of the official nginx
docker image [1] gives a hint what options must be set to not run into
errors. Apply the config directives appropriate for our use case.
[1] https://hub.docker.com/_/nginx
Signed-off-by: Thibaud Dufour <thibaudd@rtone.fr>
[bst: dropped unused options fastcgi_temp_path, uwsgi_temp_path, scgi_temp_path, rebased]
Signed-off-by: Bastian Krause <bst@pengutronix.de>
1e28022 to
e5c84a8
Compare
Logs
Run on Fedora 40 with following rpm packages installed: