feat(container-engine): run the engine CLI privileged on request
CI / test (3.10) (push) Successful in 23s
CI / test (3.11) (push) Successful in 23s
CI / test (3.12) (push) Successful in 24s
CI / test (3.10) (pull_request) Successful in 23s
CI / test (3.11) (pull_request) Successful in 22s
CI / test (3.12) (pull_request) Successful in 23s

run_cli() and stream_cli() take privileged=, passed to the driver's
run_command()/open_stream(): an engine that refuses the login user can
be retried as root, the way the driver gains root for any command.
netOrk uses it to retry a refused container start/stop/restart with
sudo (NetOrk/netork#773).
This commit is contained in:
2026-10-07 22:08:37 +02:00
parent 3aed0b48d7
commit e50e497939
4 changed files with 49 additions and 8 deletions
+21 -6
View File
@@ -65,19 +65,34 @@ class ContainerEngineConnection:
return self._driver.open_stream(self._command(["system", "dial-stdio"]))
def run_cli(
self, args: Sequence[str], *, stdin: Optional[bytes] = None, timeout: float = _CLI_TIMEOUT
self,
args: Sequence[str],
*,
stdin: Optional[bytes] = None,
timeout: float = _CLI_TIMEOUT,
privileged: bool = False,
) -> CommandResult:
"""Run the engine's CLI with *args* and wait for it."""
return self._driver.run_command(self._command(args), timeout=timeout, stdin=stdin)
"""Run the engine's CLI with *args* and wait for it.
def stream_cli(self, args: Sequence[str], *, merge_stderr: bool = False) -> ByteStream:
*privileged* runs it as root, the way the driver gains root for any
command: for a call the engine refused to the login user.
"""
return self._driver.run_command(
self._command(args), privileged=privileged, timeout=timeout, stdin=stdin
)
def stream_cli(
self, args: Sequence[str], *, merge_stderr: bool = False, privileged: bool = False
) -> ByteStream:
"""Start the engine's CLI with *args* and stream its output.
*merge_stderr* folds stderr into the stream, for tools that report
progress there (``compose up``).
progress there (``compose up``); *privileged* as for :meth:`run_cli`.
"""
command = self._command(args)
return self._driver.open_stream(f"{command} 2>&1" if merge_stderr else command)
return self._driver.open_stream(
f"{command} 2>&1" if merge_stderr else command, privileged=privileged
)
class ContainerEngineMixin: