diff --git a/packages/marmel/package.nix b/packages/marmel/package.nix index cb04726..45b6958 100644 --- a/packages/marmel/package.nix +++ b/packages/marmel/package.nix @@ -36,12 +36,30 @@ rustPlatform.buildRustPackage rec { # src/orchestrator/bus.rs, src/orchestrator/preemption.rs), so the # manager-loop tests fail nondeterministically when the harness runs them on # parallel threads: rebuilding one unchanged derivation yielded 3 failures, - # then 1 failure, then 0 with serial threads. All 325 tests still run — none - # are skipped or filtered. Drop this flag once upstream makes that state - # per-instance. + # then 1 failure, then 0 with serial threads. Drop this flag once upstream + # makes that state per-instance. + # + # The two sandbox-exec tests are skipped. They re-exec `sh` through + # `marmel --internal-sandbox-exec`, and apply_landlock_linux() allow-lists + # FHS paths only (/usr, /bin, /lib, /opt, /etc, /var) plus /tmp. Landlock + # matches inodes rather than symlinked views, and every binary on NixOS + # resolves into the store (`/bin/sh` is + # /nix/store/-bash-interactive-5.3p9/bin/bash), so the exec is denied: + # "Failed to exec shell in sandbox: Permission denied (os error 13)". Checked + # against this build on a NixOS host, where the same command succeeds once + # the workspace root is `/` and therefore covers /nix/store. Inside the build + # sandbox the tests are doubly impossible: /usr, /lib, /run and /var do not + # exist, so the `if let Ok(fd)` guards silently drop those rules, and + # /etc/resolv.conf is absent because the sandbox has no network. 342 of 344 + # tests still run. Upstream main still carries the FHS-only list; drop these + # skips if that ever gains /nix/store. cargoTestFlags = [ "--" "--test-threads=1" + "--skip" + "harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns" + "--skip" + "harness::sandbox::tests::test_internal_sandbox_cross_directory_rename" ]; # Role prompts are embedded with `include_str!`, so the binary needs no