From 29f14a14c649ad10d78219643ce155a41f8d7236 Mon Sep 17 00:00:00 2001 From: ZhuchkaTriplesix Date: Fri, 9 Oct 2026 11:41:41 +0300 Subject: [PATCH] ci: let bwrap create user namespaces on the runner so the sandbox test runs bwrap failed with "setting up uid map: Permission denied": Ubuntu 24.04 runners block unprivileged user namespaces through AppArmor. The sandbox test skipped for that reason, so its check never ran. The setting is relaxed on the CI VM only, in the test job, and the temporary diagnostics step is removed. --- .github/workflows/ci.yml | 15 +++------------ 1 file changed, 3 insertions(+), 12 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6fc3dba4..43167095 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -51,18 +51,9 @@ jobs: sudo apt-get $APT update # bubblewrap runs the extension sandbox tests; without it they skip. sudo apt-get $APT install -y libsecret-1-dev bubblewrap - - # TEMPORARY diagnostics: why the sandbox probe in the extension tests - # cannot run on this runner. Remove once the sandbox test runs. - - name: Diagnose bubblewrap - if: runner.environment == 'github-hosted' - continue-on-error: true - run: | - sudo apt-get install -y bubblewrap >/dev/null 2>&1 || true - bwrap --ro-bind / / /bin/true; echo "bwrap exit=$?" - bwrap --unshare-user --ro-bind / / /bin/true; echo "bwrap userns exit=$?" - sysctl kernel.apparmor_restrict_unprivileged_userns kernel.unprivileged_userns_clone 2>&1 || true - ls /etc/apparmor.d | grep -i bwrap || echo "no bwrap apparmor profile" + # Ubuntu 24.04 blocks unprivileged user namespaces for bwrap ("setting + # up uid map: Permission denied"). This relaxes it on the CI VM only. + sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 - name: Get dependencies run: flutter pub get