From 3d188ef884d6147d579e59eb8f51332bb8959ad5 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Fri, 7 Nov 2025 04:02:40 +0900 Subject: std: separate seccomp constants This avoids inadvertently using PNRs as syscall numbers. Signed-off-by: Ophestra --- container/seccomp/libseccomp.go | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) (limited to 'container/seccomp/libseccomp.go') diff --git a/container/seccomp/libseccomp.go b/container/seccomp/libseccomp.go index 962d6844..4684be26 100644 --- a/container/seccomp/libseccomp.go +++ b/container/seccomp/libseccomp.go @@ -215,10 +215,10 @@ const ( // syscallResolveName resolves a syscall number by name via seccomp_syscall_resolve_name. // This function is only for testing the lookup tables and included here for convenience. -func syscallResolveName(s string) (trap int, ok bool) { +func syscallResolveName(s string) (num std.ScmpSyscall, ok bool) { v := C.CString(s) - trap = int(C.seccomp_syscall_resolve_name(v)) + num = std.ScmpSyscall(C.seccomp_syscall_resolve_name(v)) C.free(unsafe.Pointer(v)) - ok = trap != C.__NR_SCMP_ERROR + ok = num != C.__NR_SCMP_ERROR return } -- cgit v1.3.1