<feed xmlns='http://www.w3.org/2005/Atom'>
<title>hakurei/helper/seccomp/api.go, branch develop</title>
<subtitle>low-level userspace tooling for Rosa OS</subtitle>
<id>http://src.rosa.moe/hakurei/atom/helper/seccomp/api.go?h=develop</id>
<link rel='self' href='http://src.rosa.moe/hakurei/atom/helper/seccomp/api.go?h=develop'/>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/'/>
<updated>2025-03-14T13:42:40Z</updated>
<entry>
<title>seccomp: move out of helper</title>
<updated>2025-03-14T13:42:40Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-03-14T13:42:40Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=2647a71be1f287e50011a65653b9e9c806627899'/>
<id>urn:sha1:2647a71be1f287e50011a65653b9e9c806627899</id>
<content type='text'>
Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>helper/seccomp: seccomp_load on negative fd</title>
<updated>2025-03-12T06:18:52Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-03-12T06:18:52Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=be16970e770554b3c2191da41eb9bd4472b323e4'/>
<id>urn:sha1:be16970e770554b3c2191da41eb9bd4472b323e4</id>
<content type='text'>
Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>helper: use generic extra files interface</title>
<updated>2025-02-13T14:34:15Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-02-13T14:15:34Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=fe7d208cf76fa6f24bb9d12ba29b5ed61d837ce3'/>
<id>urn:sha1:fe7d208cf76fa6f24bb9d12ba29b5ed61d837ce3</id>
<content type='text'>
This replaces the pipes object and integrates context into helper process lifecycle.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>helper/seccomp: implement reader interface via pipe</title>
<updated>2025-02-03T10:43:03Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-02-03T09:10:29Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=5b7b3fa9a4d8ca4ad08d6648752e28ee66f0ffae'/>
<id>urn:sha1:5b7b3fa9a4d8ca4ad08d6648752e28ee66f0ffae</id>
<content type='text'>
This also does not require the libc tmpfile call.

BPF programs emitted by libseccomp seems to be deterministic. The tests would catch regressions as it verifies the program against known good output backed by manual testing.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
</feed>
