]>
Commit | Line | Data |
---|---|---|
8befd5cc MG |
1 | #!/usr/bin/env python |
2 | ||
3 | # | |
4 | # Seccomp Library test program | |
5 | # | |
6 | # Copyright (c) 2012 Red Hat <pmoore@redhat.com> | |
7 | # Author: Paul Moore <paul@paul-moore.com> | |
8 | # | |
9 | ||
10 | # | |
11 | # This library is free software; you can redistribute it and/or modify it | |
12 | # under the terms of version 2.1 of the GNU Lesser General Public License as | |
13 | # published by the Free Software Foundation. | |
14 | # | |
15 | # This library is distributed in the hope that it will be useful, but WITHOUT | |
16 | # ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or | |
17 | # FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public License | |
18 | # for more details. | |
19 | # | |
20 | # You should have received a copy of the GNU Lesser General Public License | |
21 | # along with this library; if not, see <http://www.gnu.org/licenses>. | |
22 | # | |
23 | ||
24 | import argparse | |
25 | import sys | |
26 | ||
27 | import util | |
28 | ||
29 | from seccomp import * | |
30 | ||
31 | def test(args): | |
32 | f = SyscallFilter(KILL) | |
33 | # the syscall and argument numbers are all fake to make the test simpler | |
34 | f.add_rule_exactly(ALLOW, 1000, | |
35 | Arg(0, EQ, 0), | |
36 | Arg(1, EQ, 1)) | |
37 | f.add_rule_exactly(ALLOW, 1000, | |
38 | Arg(1, EQ, 1)) | |
39 | ||
40 | f.add_rule_exactly(ALLOW, 1001, | |
41 | Arg(1, EQ, 1)) | |
42 | f.add_rule_exactly(ALLOW, 1001, | |
43 | Arg(0, EQ, 0), | |
44 | Arg(1, EQ, 1)) | |
45 | ||
46 | f.add_rule_exactly(ALLOW, 1002, | |
47 | Arg(0, EQ, 0), | |
48 | Arg(1, EQ, 1), | |
49 | Arg(2, EQ, 2), | |
50 | Arg(3, EQ, 3)) | |
51 | f.add_rule_exactly(ALLOW, 1002, | |
52 | Arg(1, EQ, 1), | |
53 | Arg(2, EQ, 2)) | |
54 | ||
55 | f.add_rule_exactly(ALLOW, 1003, | |
56 | Arg(1, EQ, 1), | |
57 | Arg(2, EQ, 2)) | |
58 | f.add_rule_exactly(ALLOW, 1003, | |
59 | Arg(0, EQ, 0), | |
60 | Arg(1, EQ, 1), | |
61 | Arg(2, EQ, 2), | |
62 | Arg(3, EQ, 3)) | |
63 | ||
64 | f.add_rule_exactly(ALLOW, 1004, | |
65 | Arg(0, EQ, 0), | |
66 | Arg(1, EQ, 1), | |
67 | Arg(2, EQ, 2), | |
68 | Arg(3, EQ, 3)) | |
69 | f.add_rule_exactly(ALLOW, 1004, | |
70 | Arg(0, EQ, 0), | |
71 | Arg(1, EQ, 11)) | |
72 | f.add_rule_exactly(ALLOW, 1004, | |
73 | Arg(0, EQ, 0), | |
74 | Arg(1, EQ, 1), | |
75 | Arg(2, EQ, 2), | |
76 | Arg(3, EQ, 33)) | |
77 | f.add_rule_exactly(ALLOW, 1004, | |
78 | Arg(1, EQ, 1), | |
79 | Arg(2, EQ, 2)) | |
80 | ||
81 | f.add_rule_exactly(ALLOW, 1005, | |
82 | Arg(1, EQ, 1), | |
83 | Arg(2, EQ, 2)) | |
84 | f.add_rule_exactly(ALLOW, 1005, | |
85 | Arg(0, EQ, 0), | |
86 | Arg(1, EQ, 1), | |
87 | Arg(2, EQ, 2), | |
88 | Arg(3, EQ, 3)) | |
89 | f.add_rule_exactly(ALLOW, 1005, | |
90 | Arg(0, EQ, 0), | |
91 | Arg(1, EQ, 11)) | |
92 | f.add_rule_exactly(ALLOW, 1005, | |
93 | Arg(0, EQ, 0), | |
94 | Arg(1, EQ, 1), | |
95 | Arg(2, EQ, 2), | |
96 | Arg(3, EQ, 33)) | |
97 | ||
98 | f.add_rule_exactly(ALLOW, 1006, | |
99 | Arg(1, NE, 1), | |
100 | Arg(2, EQ, 0)) | |
101 | f.add_rule_exactly(ALLOW, 1006, | |
102 | Arg(1, EQ, 1), | |
103 | Arg(2, EQ, 2)) | |
104 | f.add_rule_exactly(ALLOW, 1006, | |
105 | Arg(1, NE, 1)) | |
106 | ||
107 | f.add_rule_exactly(TRAP, 1007, | |
108 | Arg(2, EQ, 1), | |
109 | Arg(3, EQ, 3)) | |
110 | f.add_rule_exactly(ALLOW, 1007, | |
111 | Arg(2, EQ, 1), | |
112 | Arg(3, NE, 3)) | |
113 | f.add_rule_exactly(ALLOW, 1007, | |
114 | Arg(3, NE, 3)) | |
115 | return f | |
116 | ||
117 | args = util.get_opt() | |
118 | ctx = test(args) | |
119 | util.filter_output(args, ctx) | |
120 | ||
121 | # kate: syntax python; | |
122 | # kate: indent-mode python; space-indent on; indent-width 4; mixedindent off; |