Arvados-DCO-1.1-Signed-off-by: Tom Clegg <tom@curii.com>
}
}
+ // Allow users in the "sudo" group to use
+ // --network=bridge without --fakeroot. (Currently
+ // tests use --fakeroot anyway.)
err = inst.runBash(`
install /usr/bin/nsenter /var/lib/arvados/bin/nsenter
setcap "cap_sys_admin+pei cap_sys_chroot+pei" /var/lib/arvados/bin/nsenter
-singularity config global --set 'allow net networks' bridge
-singularity config global --set 'allow net groups' sudo
+/var/lib/arvados/bin/singularity config global --set 'allow net networks' bridge
+/var/lib/arvados/bin/singularity config global --set 'allow net groups' sudo
`, stdout, stderr)
if err != nil {
return 1