From e03d702d088ad78645d1cce448713ef71b12e803 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Tue, 1 Jul 2025 00:35:27 +0900 Subject: sandbox/seccomp: implement syscall lookup This uses the Go map and is verified against libseccomp. Signed-off-by: Ophestra --- sandbox/seccomp/syscall.go | 28 ++++++++++++++++++++++++++++ sandbox/seccomp/syscall_test.go | 6 +++++- 2 files changed, 33 insertions(+), 1 deletion(-) create mode 100644 sandbox/seccomp/syscall.go (limited to 'sandbox') diff --git a/sandbox/seccomp/syscall.go b/sandbox/seccomp/syscall.go new file mode 100644 index 00000000..36a988aa --- /dev/null +++ b/sandbox/seccomp/syscall.go @@ -0,0 +1,28 @@ +package seccomp + +import "iter" + +// Syscalls returns an iterator over all wired syscalls. +func Syscalls() iter.Seq2[string, int] { + return func(yield func(string, int) bool) { + for name, num := range syscallNum { + if !yield(name, num) { + return + } + } + for name, num := range syscallNumExtra { + if !yield(name, num) { + return + } + } + } +} + +// SyscallResolveName resolves a syscall number from its string representation. +func SyscallResolveName(name string) (num int, ok bool) { + if num, ok = syscallNum[name]; ok { + return + } + num, ok = syscallNumExtra[name] + return +} diff --git a/sandbox/seccomp/syscall_test.go b/sandbox/seccomp/syscall_test.go index 81f470aa..933f060b 100644 --- a/sandbox/seccomp/syscall_test.go +++ b/sandbox/seccomp/syscall_test.go @@ -5,12 +5,16 @@ import ( ) func TestSyscallResolveName(t *testing.T) { - for name, want := range syscallNum { + for name, want := range Syscalls() { t.Run(name, func(t *testing.T) { if got := syscallResolveName(name); got != want { t.Errorf("syscallResolveName(%q) = %d, want %d", name, got, want) } + if got, ok := SyscallResolveName(name); !ok || got != want { + t.Errorf("SyscallResolveName(%q) = %d, want %d", + name, got, want) + } }) } } -- cgit v1.3.1