jail: only output BPF instr. table header if debugging
authorDaniel Golle <daniel@makrotopia.org>
Mon, 4 Jan 2021 21:52:33 +0000 (21:52 +0000)
committerDaniel Golle <daniel@makrotopia.org>
Tue, 2 Feb 2021 12:54:00 +0000 (12:54 +0000)
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
jail/seccomp-oci.c

index e85191e9c03e906bc09c8887de7e11aa4d6d4aca..f089ac6cc75eb54bdb902106a82046b71173b213 100644 (file)
@@ -407,14 +407,15 @@ struct sock_fprog *parseOCIlinuxseccomp(struct blob_attr *msg)
        prog->filter = filter;
 
        DEBUG("generated seccomp-bpf program:\n");
-       fprintf(stderr, " [idx]\tcode\t jt\t jf\tk\n");
-       if (debug)
+       if (debug) {
+               fprintf(stderr, " [idx]\tcode\t jt\t jf\tk\n");
                for (idx=0; idx<sz; idx++)
                        fprintf(stderr, " [%03d]\t%04hx\t%3hhu\t%3hhu\t%08x\n", idx,
                                filter[idx].code,
                                filter[idx].jt,
                                filter[idx].jf,
                                filter[idx].k);
+       }
 
        return prog;