aboutsummaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
-rw-r--r--container/autoroot.go2
-rw-r--r--container/autoroot_test.go26
2 files changed, 28 insertions, 0 deletions
diff --git a/container/autoroot.go b/container/autoroot.go
index 215a7bb3..6145ec6f 100644
--- a/container/autoroot.go
+++ b/container/autoroot.go
@@ -89,6 +89,8 @@ func IsAutoRootBindable(name string) bool {
case "mnt":
case "etc":
+ case "": // guard against accidentally binding /
+
default:
return true
}
diff --git a/container/autoroot_test.go b/container/autoroot_test.go
new file mode 100644
index 00000000..7e9d1477
--- /dev/null
+++ b/container/autoroot_test.go
@@ -0,0 +1,26 @@
+package container
+
+import "testing"
+
+func TestIsAutoRootBindable(t *testing.T) {
+ testCases := []struct {
+ name string
+ want bool
+ }{
+ {"proc", false},
+ {"dev", false},
+ {"tmp", false},
+ {"mnt", false},
+ {"etc", false},
+ {"", false},
+
+ {"var", true},
+ }
+ for _, tc := range testCases {
+ t.Run(tc.name, func(t *testing.T) {
+ if got := IsAutoRootBindable(tc.name); got != tc.want {
+ t.Errorf("IsAutoRootBindable: %v, want %v", got, tc.want)
+ }
+ })
+ }
+}