diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-10-13 18:49:58 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-10-13 18:51:35 +0900 |
| commit | 123d7fbfd5a2955dc5042c0a85211e376d5a8e65 (patch) | |
| tree | 7e03e35309083b81873f3cf1939d2f4d27d41659 /container/seccomp/libseccomp-helper.c | |
| parent | 7638a44fa613f23434318bdf136723aa010e8638 (diff) | |
container/seccomp: remove export pipe
This was only useful when wrapping bwrap.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container/seccomp/libseccomp-helper.c')
| -rw-r--r-- | container/seccomp/libseccomp-helper.c | 26 |
1 files changed, 20 insertions, 6 deletions
diff --git a/container/seccomp/libseccomp-helper.c b/container/seccomp/libseccomp-helper.c index b09c3eb2..e5980d7e 100644 --- a/container/seccomp/libseccomp-helper.c +++ b/container/seccomp/libseccomp-helper.c @@ -9,14 +9,16 @@ #define LEN(arr) (sizeof(arr) / sizeof((arr)[0])) -int32_t hakurei_export_filter(int *ret_p, int fd, uint32_t arch, - uint32_t multiarch, - struct hakurei_syscall_rule *rules, - size_t rules_sz, hakurei_export_flag flags) { +int32_t hakurei_scmp_make_filter(int *ret_p, uintptr_t allocate_p, + uint32_t arch, uint32_t multiarch, + struct hakurei_syscall_rule *rules, + size_t rules_sz, hakurei_export_flag flags) { int i; int last_allowed_family; int disallowed; struct hakurei_syscall_rule *rule; + void *buf; + size_t len = 0; int32_t res = 0; /* refer to resPrefix for message */ @@ -108,14 +110,26 @@ int32_t hakurei_export_filter(int *ret_p, int fd, uint32_t arch, seccomp_rule_add_exact(ctx, SCMP_ACT_ERRNO(EAFNOSUPPORT), SCMP_SYS(socket), 1, SCMP_A0(SCMP_CMP_GE, last_allowed_family + 1)); - if (fd < 0) { + if (allocate_p == 0) { *ret_p = seccomp_load(ctx); if (*ret_p != 0) { res = 7; goto out; } } else { - *ret_p = seccomp_export_bpf(ctx, fd); + *ret_p = seccomp_export_bpf_mem(ctx, NULL, &len); + if (*ret_p != 0) { + res = 6; + goto out; + } + + buf = hakurei_scmp_allocate(allocate_p, len); + if (buf == NULL) { + res = 4; + goto out; + } + + *ret_p = seccomp_export_bpf_mem(ctx, buf, &len); if (*ret_p != 0) { res = 6; goto out; |
