aboutsummaryrefslogtreecommitdiffhomepage
path: root/seccomp
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-03-17 01:09:12 +0900
committerOphestra <cat@gensokyo.uk>2025-03-17 01:10:27 +0900
commitee108603572101ad3c285830e04ee248916b6c5d (patch)
treee3d2274301cf7f1ed39df9c510672745fbe0b08a /seccomp
parent44277dc0f1fd1806f5ceea34246a4c805a06b61b (diff)
seccomp: install output atomically
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'seccomp')
-rw-r--r--seccomp/export_test.go6
-rw-r--r--seccomp/output.go30
-rw-r--r--seccomp/seccomp.go11
3 files changed, 34 insertions, 13 deletions
diff --git a/seccomp/export_test.go b/seccomp/export_test.go
index 991517f4..34bb306b 100644
--- a/seccomp/export_test.go
+++ b/seccomp/export_test.go
@@ -4,7 +4,6 @@ import (
"crypto/sha512"
"errors"
"io"
- "log"
"slices"
"syscall"
"testing"
@@ -79,8 +78,9 @@ func TestExport(t *testing.T) {
buf := make([]byte, 8)
for _, tc := range testCases {
t.Run(tc.name, func(t *testing.T) {
- seccomp.CPrintln = log.Println
- t.Cleanup(func() { seccomp.CPrintln = nil })
+ oldF := seccomp.GetOutput()
+ seccomp.SetOutput(t.Log)
+ t.Cleanup(func() { seccomp.SetOutput(oldF) })
e := seccomp.New(tc.opts)
digest := sha512.New()
diff --git a/seccomp/output.go b/seccomp/output.go
new file mode 100644
index 00000000..d583c9ee
--- /dev/null
+++ b/seccomp/output.go
@@ -0,0 +1,30 @@
+package seccomp
+
+import "C"
+import "sync/atomic"
+
+var printlnP atomic.Pointer[func(v ...any)]
+
+func SetOutput(f func(v ...any)) {
+ if f == nil {
+ // avoid storing nil function
+ printlnP.Store(nil)
+ } else {
+ printlnP.Store(&f)
+ }
+}
+
+func GetOutput() func(v ...any) {
+ if fp := printlnP.Load(); fp == nil {
+ return nil
+ } else {
+ return *fp
+ }
+}
+
+//export F_println
+func F_println(v *C.char) {
+ if fp := printlnP.Load(); fp != nil {
+ (*fp)(C.GoString(v))
+ }
+}
diff --git a/seccomp/seccomp.go b/seccomp/seccomp.go
index 05c314c9..2e730479 100644
--- a/seccomp/seccomp.go
+++ b/seccomp/seccomp.go
@@ -13,8 +13,6 @@ import (
"syscall"
)
-var CPrintln func(v ...any)
-
// LibraryError represents a libseccomp error.
type LibraryError struct {
Prefix string
@@ -99,7 +97,7 @@ func buildFilter(fd int, opts SyscallOpts) error {
// this removes repeated transitions between C and Go execution
// when producing log output via F_println and CPrintln is nil
- if CPrintln != nil {
+ if fp := printlnP.Load(); fp != nil {
opts |= flagVerbose
}
@@ -114,10 +112,3 @@ func buildFilter(fd int, opts SyscallOpts) error {
}
return err
}
-
-//export F_println
-func F_println(v *C.char) {
- if CPrintln != nil {
- CPrintln(C.GoString(v))
- }
-}