diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-04-08 01:59:45 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-04-08 01:59:45 +0900 |
| commit | 584405f7ccd4c8c0e63762e113f4650f2abd469e (patch) | |
| tree | f72d79d1a90e9bffe8f5c975e564ad40c602f2f7 /sandbox/seccomp/export_test.go | |
| parent | 50127ed5f9bc89f38c7d5d1aa06b4d99229b9c64 (diff) | |
sandbox/seccomp: rename flag type and constants
The names are ambiguous. Rename them to make more sense.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'sandbox/seccomp/export_test.go')
| -rw-r--r-- | sandbox/seccomp/export_test.go | 27 |
1 files changed, 13 insertions, 14 deletions
diff --git a/sandbox/seccomp/export_test.go b/sandbox/seccomp/export_test.go index 66db3e40..dbe4d74f 100644 --- a/sandbox/seccomp/export_test.go +++ b/sandbox/seccomp/export_test.go @@ -14,7 +14,7 @@ import ( func TestExport(t *testing.T) { testCases := []struct { name string - opts seccomp.SyscallOpts + opts seccomp.FilterOpts want []byte wantErr bool }{ @@ -28,7 +28,7 @@ func TestExport(t *testing.T) { 0xa7, 0x9b, 0x07, 0x0e, 0x04, 0xc0, 0xee, 0x9a, 0xcd, 0xf5, 0x8f, 0x55, 0xcf, 0xa8, 0x15, 0xa5, }, false}, - {"base", seccomp.FlagExt, []byte{ + {"base", seccomp.FilterExt, []byte{ 0xdc, 0x7f, 0x2e, 0x1c, 0x5e, 0x82, 0x9b, 0x79, 0xeb, 0xb7, 0xef, 0xc7, 0x59, 0x15, 0x0f, 0x54, 0xa8, 0x3a, 0x75, 0xc8, 0xdf, 0x6f, 0xee, 0x4d, @@ -38,10 +38,10 @@ func TestExport(t *testing.T) { 0x1d, 0xb0, 0x5d, 0x90, 0x99, 0x7c, 0x86, 0x59, 0xb9, 0x58, 0x91, 0x20, 0x6a, 0xc9, 0x95, 0x2d, }, false}, - {"everything", seccomp.FlagExt | - seccomp.FlagDenyNS | seccomp.FlagDenyTTY | seccomp.FlagDenyDevel | - seccomp.FlagMultiarch | seccomp.FlagLinux32 | seccomp.FlagCan | - seccomp.FlagBluetooth, []byte{ + {"everything", seccomp.FilterExt | + seccomp.FilterDenyNS | seccomp.FilterDenyTTY | seccomp.FilterDenyDevel | + seccomp.FilterMultiarch | seccomp.FilterLinux32 | seccomp.FilterCan | + seccomp.FilterBluetooth, []byte{ 0xe9, 0x9d, 0xd3, 0x45, 0xe1, 0x95, 0x41, 0x34, 0x73, 0xd3, 0xcb, 0xee, 0x07, 0xb4, 0xed, 0x57, 0xb9, 0x08, 0xbf, 0xa8, 0x9e, 0xa2, 0x07, 0x2f, @@ -51,8 +51,7 @@ func TestExport(t *testing.T) { 0x4c, 0x02, 0x4e, 0xd4, 0x88, 0x50, 0xbe, 0x69, 0xb6, 0x8a, 0x9a, 0x4c, 0x5f, 0x53, 0xa9, 0xdb, }, false}, - {"strict", seccomp.FlagExt | - seccomp.FlagDenyNS | seccomp.FlagDenyTTY | seccomp.FlagDenyDevel, []byte{ + {"strict", seccomp.PresetStrict, []byte{ 0xe8, 0x80, 0x29, 0x8d, 0xf2, 0xbd, 0x67, 0x51, 0xd0, 0x04, 0x0f, 0xc2, 0x1b, 0xc0, 0xed, 0x4c, 0x00, 0xf9, 0x5d, 0xc0, 0xd7, 0xba, 0x50, 0x6c, @@ -63,7 +62,7 @@ func TestExport(t *testing.T) { 0x14, 0x89, 0x60, 0xfb, 0xd3, 0x5c, 0xd7, 0x35, }, false}, {"strict compat", 0 | - seccomp.FlagDenyNS | seccomp.FlagDenyTTY | seccomp.FlagDenyDevel, []byte{ + seccomp.FilterDenyNS | seccomp.FilterDenyTTY | seccomp.FilterDenyDevel, []byte{ 0x39, 0x87, 0x1b, 0x93, 0xff, 0xaf, 0xc8, 0xb9, 0x79, 0xfc, 0xed, 0xc0, 0xb0, 0xc3, 0x7b, 0x9e, 0x03, 0x92, 0x2f, 0x5b, 0x02, 0x74, 0x8d, 0xc5, @@ -73,7 +72,7 @@ func TestExport(t *testing.T) { 0x80, 0x8b, 0x1a, 0x6f, 0x84, 0xf3, 0x2b, 0xbd, 0xe1, 0xaa, 0x02, 0xae, 0x30, 0xee, 0xdc, 0xfa, }, false}, - {"fortify default", seccomp.FlagExt | seccomp.FlagDenyDevel, []byte{ + {"fortify default", seccomp.FilterExt | seccomp.FilterDenyDevel, []byte{ 0xc6, 0x98, 0xb0, 0x81, 0xff, 0x95, 0x7a, 0xfe, 0x17, 0xa6, 0xd9, 0x43, 0x74, 0x53, 0x7d, 0x37, 0xf2, 0xa6, 0x3f, 0x6f, 0x9d, 0xd7, 0x5d, 0xa7, @@ -138,10 +137,10 @@ func TestExport(t *testing.T) { func BenchmarkExport(b *testing.B) { buf := make([]byte, 8) for i := 0; i < b.N; i++ { - e := seccomp.New(seccomp.FlagExt | - seccomp.FlagDenyNS | seccomp.FlagDenyTTY | seccomp.FlagDenyDevel | - seccomp.FlagMultiarch | seccomp.FlagLinux32 | seccomp.FlagCan | - seccomp.FlagBluetooth) + e := seccomp.New(seccomp.FilterExt | + seccomp.FilterDenyNS | seccomp.FilterDenyTTY | seccomp.FilterDenyDevel | + seccomp.FilterMultiarch | seccomp.FilterLinux32 | seccomp.FilterCan | + seccomp.FilterBluetooth) if _, err := io.CopyBuffer(io.Discard, e, buf); err != nil { b.Fatalf("cannot export: %v", err) } |
