aboutsummaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-08-20 02:45:00 +0900
committerOphestra <cat@gensokyo.uk>2025-08-20 02:45:00 +0900
commit022cc26b2eb2260cbec1187c45e8bab1afe87116 (patch)
tree0d78718e9d0ce13af4135eb8f78d9543a4d83ce0
parentb4c018da8f5280bf3e2716c8ccfea82f4459e80a (diff)
container/capability: check CAP_TO_INDEX and CAP_TO_MASK
Signed-off-by: Ophestra <cat@gensokyo.uk>
-rw-r--r--container/capability_test.go41
1 files changed, 41 insertions, 0 deletions
diff --git a/container/capability_test.go b/container/capability_test.go
new file mode 100644
index 00000000..21043fb0
--- /dev/null
+++ b/container/capability_test.go
@@ -0,0 +1,41 @@
+package container
+
+import "testing"
+
+func TestCapToIndex(t *testing.T) {
+ testCases := []struct {
+ name string
+ cap uintptr
+ want uintptr
+ }{
+ {"CAP_SYS_ADMIN", CAP_SYS_ADMIN, 0},
+ {"CAP_SETPCAP", CAP_SETPCAP, 0},
+ {"CAP_DAC_OVERRIDE", CAP_DAC_OVERRIDE, 0},
+ }
+ for _, tc := range testCases {
+ t.Run(tc.name, func(t *testing.T) {
+ if got := capToIndex(tc.cap); got != tc.want {
+ t.Errorf("capToIndex: %#x, want %#x", got, tc.want)
+ }
+ })
+ }
+}
+
+func TestCapToMask(t *testing.T) {
+ testCases := []struct {
+ name string
+ cap uintptr
+ want uint32
+ }{
+ {"CAP_SYS_ADMIN", CAP_SYS_ADMIN, 0x200000},
+ {"CAP_SETPCAP", CAP_SETPCAP, 0x100},
+ {"CAP_DAC_OVERRIDE", CAP_DAC_OVERRIDE, 0x2},
+ }
+ for _, tc := range testCases {
+ t.Run(tc.name, func(t *testing.T) {
+ if got := capToMask(tc.cap); got != tc.want {
+ t.Errorf("capToMask: %#x, want %#x", got, tc.want)
+ }
+ })
+ }
+}