Skip to content

apparmor: validate generated profiles with apparmor_parser - #45

Merged
thaJeztah merged 1 commit into
moby:mainfrom
thaJeztah:test_parse
Sep 25, 2026
Merged

thaJeztah merged 1 commit into
moby:mainfrom
thaJeztah:test_parse

Conversation

@thaJeztah

Copy link
Copy Markdown
Member

Add a helper that parses generated profiles with apparmor_parser without loading them into the kernel, and use it for golden profile tests where the referenced includes are available.

This gives the tests an additional syntax/validation check beyond comparing the generated output with golden files.

Add a helper that parses generated profiles with apparmor_parser without
loading them into the kernel, and use it for golden profile tests where the
referenced includes are available.

This gives the tests an additional syntax/validation check beyond comparing
the generated output with golden files.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
@thaJeztah

Copy link
Copy Markdown
Member Author

This fails when adding this test-case;

		{
			name: "with-special-characters",
			data: profileData{
				Name: `foo"bar`,
			},
		},
=== RUN   TestGenerateDefault/with-special-characters/validate
    apparmor_linux_test.go:312: parsing generated profile: exit status 1
        Cache read/write disabled: interface file missing. (Kernel needs AppArmor 2.4 compatibility patch.)
        AppArmor parser error at line 6: Lexer found unexpected character: '"' (0x22) in state: INITIAL

@thaJeztah
thaJeztah marked this pull request as ready for review September 25, 2026 08:43
@thaJeztah

Copy link
Copy Markdown
Member Author

cc @vvoland ptal

@thaJeztah
thaJeztah merged commit ae27944 into moby:main Sep 25, 2026
10 checks passed
@thaJeztah
thaJeztah deleted the test_parse branch September 25, 2026 11:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants