From 1a8840bebc673672235b6e10b1b9386f24751757 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Tue, 1 Jul 2025 20:23:33 +0900 Subject: sandbox/seccomp: resolve rules natively This enables loading syscall filter policies from external cross-platform config files. This also removes a significant amount of C code. Signed-off-by: Ophestra --- sandbox/container_test.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'sandbox/container_test.go') diff --git a/sandbox/container_test.go b/sandbox/container_test.go index 7f64e128..85e40bf0 100644 --- a/sandbox/container_test.go +++ b/sandbox/container_test.go @@ -164,8 +164,8 @@ func e(root, target, vfsOptstr, fsType, source, fsOptstr string) *vfs.MountInfoE func TestContainerString(t *testing.T) { container := sandbox.New(t.Context(), "ldd", "/usr/bin/env") container.Flags |= sandbox.FAllowDevel - container.Seccomp |= seccomp.FilterMultiarch - want := `argv: ["ldd" "/usr/bin/env"], flags: 0x2, seccomp: 0x2e` + container.SeccompFlags |= seccomp.AllowMultiarch + want := `argv: ["ldd" "/usr/bin/env"], flags: 0x2, seccomp: 0x1, presets: 0x7` if got := container.String(); got != want { t.Errorf("String: %s, want %s", got, want) } -- cgit v1.3.1