Skip to content

apparmor: allow compiling and testing on non-Linux - #49

Merged
vvoland merged 1 commit into
moby:mainfrom
thaJeztah:testable_nonlinux
Sep 30, 2026
Merged

vvoland merged 1 commit into
moby:mainfrom
thaJeztah:testable_nonlinux

Conversation

@thaJeztah

Copy link
Copy Markdown
Member

While AppArmor only applies to Linux platforms, the code in this module is largely platform-agnostic (with the exception of the apparmor utilities not being present).

Remove the Linux build-tags to allow running the unit-tests on other platforms.

With this patch:

go -C ./apparmor/ test -v
=== RUN   TestInstallDefault
    apparmor_test.go:148: requires root
--- SKIP: TestInstallDefault (0.00s)
=== RUN   TestIsLoaded
=== RUN   TestIsLoaded/loaded
=== RUN   TestIsLoaded/loaded_with_spaces
=== RUN   TestIsLoaded/not_loaded
=== RUN   TestIsLoaded/error
--- PASS: TestIsLoaded (0.00s)
    --- PASS: TestIsLoaded/loaded (0.00s)
    --- PASS: TestIsLoaded/loaded_with_spaces (0.00s)
    --- PASS: TestIsLoaded/not_loaded (0.00s)
    --- PASS: TestIsLoaded/error (0.00s)
=== RUN   TestGenerateDefault
=== RUN   TestGenerateDefault/default
=== RUN   TestGenerateDefault/default/validate
    apparmor_test.go:311: apparmor_parser not available
=== RUN   TestGenerateDefault/with-api3
=== RUN   TestGenerateDefault/with-api3/validate
    apparmor_test.go:311: apparmor_parser not available
=== RUN   TestGenerateDefault/with-tunables
=== RUN   TestGenerateDefault/with-tunables/validate
    apparmor_test.go:311: apparmor_parser not available
=== RUN   TestGenerateDefault/with-abstractions-base
=== RUN   TestGenerateDefault/with-abstractions-base/validate
    apparmor_test.go:311: apparmor_parser not available
=== RUN   TestGenerateDefault/with-daemon-profile
=== RUN   TestGenerateDefault/with-daemon-profile/validate
    apparmor_test.go:311: apparmor_parser not available
=== RUN   TestGenerateDefault/with-spaces
=== RUN   TestGenerateDefault/with-spaces/validate
    apparmor_test.go:311: apparmor_parser not available
=== RUN   TestGenerateDefault/with-custom-imports
=== RUN   TestGenerateDefault/with-custom-inner-imports
=== RUN   TestGenerateDefault/with-special-characters
=== RUN   TestGenerateDefault/with-special-characters/validate
    apparmor_test.go:311: apparmor_parser not available
--- PASS: TestGenerateDefault (0.00s)
    --- PASS: TestGenerateDefault/default (0.00s)
        --- SKIP: TestGenerateDefault/default/validate (0.00s)
    --- PASS: TestGenerateDefault/with-api3 (0.00s)
        --- SKIP: TestGenerateDefault/with-api3/validate (0.00s)
    --- PASS: TestGenerateDefault/with-tunables (0.00s)
        --- SKIP: TestGenerateDefault/with-tunables/validate (0.00s)
    --- PASS: TestGenerateDefault/with-abstractions-base (0.00s)
        --- SKIP: TestGenerateDefault/with-abstractions-base/validate (0.00s)
    --- PASS: TestGenerateDefault/with-daemon-profile (0.00s)
        --- SKIP: TestGenerateDefault/with-daemon-profile/validate (0.00s)
    --- PASS: TestGenerateDefault/with-spaces (0.00s)
        --- SKIP: TestGenerateDefault/with-spaces/validate (0.00s)
    --- PASS: TestGenerateDefault/with-custom-imports (0.00s)
    --- PASS: TestGenerateDefault/with-custom-inner-imports (0.00s)
    --- PASS: TestGenerateDefault/with-special-characters (0.00s)
        --- SKIP: TestGenerateDefault/with-special-characters/validate (0.00s)
=== RUN   TestGenerateProfileName
    apparmor_test.go:321: apparmor_parser not available: exec: "apparmor_parser": executable file not found in $PATH
--- SKIP: TestGenerateProfileName (0.00s)
=== RUN   TestCleanProfileName
=== RUN   TestCleanProfileName/empty
=== RUN   TestCleanProfileName/unconfined
=== RUN   TestCleanProfileName/unconfined_newline
=== RUN   TestCleanProfileName/unconfined_enforce
=== RUN   TestCleanProfileName/unconfined_enforce_newline
=== RUN   TestCleanProfileName/simple
=== RUN   TestCleanProfileName/simple_enforce
=== RUN   TestCleanProfileName/spaces
=== RUN   TestCleanProfileName/parentheses_in_name
=== RUN   TestCleanProfileName/unknown_mode
--- PASS: TestCleanProfileName (0.00s)
    --- PASS: TestCleanProfileName/empty (0.00s)
    --- PASS: TestCleanProfileName/unconfined (0.00s)
    --- PASS: TestCleanProfileName/unconfined_newline (0.00s)
    --- PASS: TestCleanProfileName/unconfined_enforce (0.00s)
    --- PASS: TestCleanProfileName/unconfined_enforce_newline (0.00s)
    --- PASS: TestCleanProfileName/simple (0.00s)
    --- PASS: TestCleanProfileName/simple_enforce (0.00s)
    --- PASS: TestCleanProfileName/spaces (0.00s)
    --- PASS: TestCleanProfileName/parentheses_in_name (0.00s)
    --- PASS: TestCleanProfileName/unknown_mode (0.00s)
=== RUN   TestQuotePeerName
=== RUN   TestQuotePeerName/empty
=== RUN   TestQuotePeerName/simple
=== RUN   TestQuotePeerName/spaces
=== RUN   TestQuotePeerName/double_quote
=== RUN   TestQuotePeerName/backslash
=== RUN   TestQuotePeerName/escape_sequence
=== RUN   TestQuotePeerName/AARE_wildcard
=== RUN   TestQuotePeerName/AARE_character_class
=== RUN   TestQuotePeerName/AARE_alternation
=== RUN   TestQuotePeerName/AARE_anchor
=== RUN   TestQuotePeerName/invalid_UTF-8_with_special_character
--- PASS: TestQuotePeerName (0.00s)
    --- PASS: TestQuotePeerName/empty (0.00s)
    --- PASS: TestQuotePeerName/simple (0.00s)
    --- PASS: TestQuotePeerName/spaces (0.00s)
    --- PASS: TestQuotePeerName/double_quote (0.00s)
    --- PASS: TestQuotePeerName/backslash (0.00s)
    --- PASS: TestQuotePeerName/escape_sequence (0.00s)
    --- PASS: TestQuotePeerName/AARE_wildcard (0.00s)
    --- PASS: TestQuotePeerName/AARE_character_class (0.00s)
    --- PASS: TestQuotePeerName/AARE_alternation (0.00s)
    --- PASS: TestQuotePeerName/AARE_anchor (0.00s)
    --- PASS: TestQuotePeerName/invalid_UTF-8_with_special_character (0.00s)
PASS
ok  	github.com/moby/profiles/apparmor	0.238s

While AppArmor only applies to Linux platforms, the code in this module
is largely platform-agnostic (with the exception of the apparmor utilities
not being present).

Remove the Linux build-tags to allow running the unit-tests on other platforms.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The platform-specific operations are appropriately guarded while portable functionality remains testable.

Review effort: Balanced
Findings: None

What changed in this PR

Enables the AppArmor package and its platform-agnostic tests to compile and run on non-Linux systems.

Changes:

  • Removes the Linux build constraint from the AppArmor implementation.
  • Adds portable unit tests while conditionally skipping Linux-specific integration checks.
File Description
apparmor/​apparmor.go Makes the implementation available across platforms.
apparmor/​apparmor_test.go Adds unit, integration, golden, and benchmark coverage.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@thaJeztah
thaJeztah requested a review from vvoland September 30, 2026 18:00
@vvoland
vvoland merged commit 2ceae35 into moby:main Sep 30, 2026
10 checks passed
@thaJeztah
thaJeztah deleted the testable_nonlinux branch September 30, 2026 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants