From 632b18addd56227682ab4e29d97dcaf5d9642454 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Fri, 21 Mar 2025 12:29:15 +0900 Subject: [PATCH] test/sandbox: rename misleading bind destination Signed-off-by: Ophestra --- test/configuration.nix | 2 +- test/sandbox/fs.nix | 2 +- test/sandbox/mount.nix | 4 ++-- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/test/configuration.nix b/test/configuration.nix index 6c72299..f6c3d14 100644 --- a/test/configuration.nix +++ b/test/configuration.nix @@ -113,7 +113,7 @@ extraPaths = [ { src = "/proc/mounts"; - dst = "/.fortify/host-mounts"; + dst = "/.fortify/mounts"; } ]; } diff --git a/test/sandbox/fs.nix b/test/sandbox/fs.nix index 8f2ea50..9714a82 100644 --- a/test/sandbox/fs.nix +++ b/test/sandbox/fs.nix @@ -23,7 +23,7 @@ let fortify = fs "16d" null null; init0 = fs "80001ff" null null; } null; - host-mounts = fs "124" null null; + mounts = fs "124" null null; } null; bin = fs "800001ed" { sh = fs "80001ff" null null; } null; dev = fs "800001ed" { diff --git a/test/sandbox/mount.nix b/test/sandbox/mount.nix index b3a310b..0c1bda1 100644 --- a/test/sandbox/mount.nix +++ b/test/sandbox/mount.nix @@ -42,7 +42,7 @@ let (ent "sysfs" "/sys/devices" "sysfs" "ro,nosuid,nodev,noexec,relatime" 0 0) (ent "overlay" "/run/opengl-driver" "overlay" "ro,nosuid,nodev,relatime,lowerdir=/mnt-root/nix/.ro-store,upperdir=/mnt-root/nix/.rw-store/upper,workdir=/mnt-root/nix/.rw-store/work,uuid=on" 0 0) (ent "devtmpfs" "/dev/dri" "devtmpfs" "host_passthrough" 0 0) - (ent "proc" "/.fortify/host-mounts" "proc" "ro,nosuid,nodev,noexec,relatime" 0 0) + (ent "proc" "/.fortify/mounts" "proc" "ro,nosuid,nodev,noexec,relatime" 0 0) (ent "/dev/disk/by-label/nixos" "/.fortify/etc" "ext4" "ro,nosuid,nodev,relatime" 0 0) (ent "tmpfs" "/run/user" "tmpfs" "rw,nosuid,nodev,relatime,size=1024k,mode=755,uid=1000001,gid=1000001" 0 0) (ent "tmpfs" "/run/user/65534" "tmpfs" "rw,nosuid,nodev,relatime,size=8192k,mode=755,uid=1000001,gid=1000001" 0 0) @@ -62,7 +62,7 @@ let import "git.gensokyo.uk/security/fortify/test/sandbox" - func main() { sandbox.MustAssertMounts("", "/.fortify/host-mounts", "${writeText "want-mounts.json" (builtins.toJSON wantMounts)}") } + func main() { sandbox.MustAssertMounts("", "/.fortify/mounts", "${writeText "want-mounts.json" (builtins.toJSON wantMounts)}") } ''; in buildGoModule {