Do not count the machine's own plumbing mounted into a container as found data (hq ADR 0103)

This commit is contained in:
2026-09-22 18:33:29 +02:00
parent a4e4632077
commit bd3fd17ad8
2 changed files with 38 additions and 1 deletions
+17
View File
@@ -754,3 +754,20 @@ func TestAUserFoundOnTheMachineKeepsItsShellAndGroups(t *testing.T) {
}
}
}
func TestMountingTheMachinesOwnPlumbingIsNotFoundData(t *testing.T) {
// The runtime's socket, the kernel's filesystems and the clock are on every machine; a
// container mounting them shares nothing a predecessor kept (novox/hq ADR 0103).
dir := t.TempDir()
m := &machine{containers: map[string]*fakeContainer{}}
report, state := applyAdopted(t, adopted(t, untaken("hello-web.server"),
`{"id":"hello-web.server","type":"container","name":"hello-web","image":"`+pinned+`",
"volumes":["/var/run/docker.sock:/var/run/docker.sock","/etc/localtime:/etc/localtime:ro",
"/proc/cpuinfo:/host/cpuinfo:ro","/dev/null:/data/null"]}`), store.State{}, m, dir)
if o := outcomeOf(report, "hello-web.server"); o.Action != "created" {
t.Errorf("a container mounting only system paths was not created: %+v", o)
}
if len(state.Held) != 0 {
t.Errorf("held: %+v", state.Held)
}
}