diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-11-15 16:53:10 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-11-15 17:06:43 +0900 |
| commit | 41b49137a8d11183c0d13ea32527f58f9c1a3dec (patch) | |
| tree | 4b632dd654770bc55c409f8da671c89658f84ceb /container/seccomp | |
| parent | c761e1de4dcf87b9106e4f70cb89217a81aa2f9f (diff) | |
.clang-format: do not limit line length
This hard limit destroys readability in some places.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container/seccomp')
| -rw-r--r-- | container/seccomp/libseccomp-helper.c | 28 | ||||
| -rw-r--r-- | container/seccomp/libseccomp-helper.h | 11 |
2 files changed, 17 insertions, 22 deletions
diff --git a/container/seccomp/libseccomp-helper.c b/container/seccomp/libseccomp-helper.c index e5980d7e..539ed685 100644 --- a/container/seccomp/libseccomp-helper.c +++ b/container/seccomp/libseccomp-helper.c @@ -9,10 +9,11 @@ #define LEN(arr) (sizeof(arr) / sizeof((arr)[0])) -int32_t hakurei_scmp_make_filter(int *ret_p, uintptr_t allocate_p, - uint32_t arch, uint32_t multiarch, - struct hakurei_syscall_rule *rules, - size_t rules_sz, hakurei_export_flag flags) { +int32_t hakurei_scmp_make_filter( + int *ret_p, uintptr_t allocate_p, + uint32_t arch, uint32_t multiarch, + struct hakurei_syscall_rule *rules, + size_t rules_sz, hakurei_export_flag flags) { int i; int last_allowed_family; int disallowed; @@ -72,11 +73,9 @@ int32_t hakurei_scmp_make_filter(int *ret_p, uintptr_t allocate_p, assert(rule->m_errno == EPERM || rule->m_errno == ENOSYS); if (rule->arg) - *ret_p = seccomp_rule_add(ctx, SCMP_ACT_ERRNO(rule->m_errno), - rule->syscall, 1, *rule->arg); + *ret_p = seccomp_rule_add(ctx, SCMP_ACT_ERRNO(rule->m_errno), rule->syscall, 1, *rule->arg); else - *ret_p = seccomp_rule_add(ctx, SCMP_ACT_ERRNO(rule->m_errno), - rule->syscall, 0); + *ret_p = seccomp_rule_add(ctx, SCMP_ACT_ERRNO(rule->m_errno), rule->syscall, 0); if (*ret_p == -EFAULT) { res = 4; @@ -93,22 +92,17 @@ int32_t hakurei_scmp_make_filter(int *ret_p, uintptr_t allocate_p, last_allowed_family = -1; for (i = 0; i < LEN(socket_family_allowlist); i++) { if (socket_family_allowlist[i].flags_mask != 0 && - (socket_family_allowlist[i].flags_mask & flags) != - socket_family_allowlist[i].flags_mask) + (socket_family_allowlist[i].flags_mask & flags) != socket_family_allowlist[i].flags_mask) continue; - for (disallowed = last_allowed_family + 1; - disallowed < socket_family_allowlist[i].family; disallowed++) { + for (disallowed = last_allowed_family + 1; disallowed < socket_family_allowlist[i].family; disallowed++) { /* Blocklist the in-between valid families */ - seccomp_rule_add_exact(ctx, SCMP_ACT_ERRNO(EAFNOSUPPORT), - SCMP_SYS(socket), 1, - SCMP_A0(SCMP_CMP_EQ, disallowed)); + seccomp_rule_add_exact(ctx, SCMP_ACT_ERRNO(EAFNOSUPPORT), SCMP_SYS(socket), 1, SCMP_A0(SCMP_CMP_EQ, disallowed)); } last_allowed_family = socket_family_allowlist[i].family; } /* Blocklist the rest */ - seccomp_rule_add_exact(ctx, SCMP_ACT_ERRNO(EAFNOSUPPORT), SCMP_SYS(socket), 1, - SCMP_A0(SCMP_CMP_GE, last_allowed_family + 1)); + seccomp_rule_add_exact(ctx, SCMP_ACT_ERRNO(EAFNOSUPPORT), SCMP_SYS(socket), 1, SCMP_A0(SCMP_CMP_GE, last_allowed_family + 1)); if (allocate_p == 0) { *ret_p = seccomp_load(ctx); diff --git a/container/seccomp/libseccomp-helper.h b/container/seccomp/libseccomp-helper.h index 0fad2d4a..72e29771 100644 --- a/container/seccomp/libseccomp-helper.h +++ b/container/seccomp/libseccomp-helper.h @@ -1,7 +1,7 @@ #include <seccomp.h> #include <stdint.h> -#if (SCMP_VER_MAJOR < 2) || (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 5) || \ +#if (SCMP_VER_MAJOR < 2) || (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 5) || \ (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR == 5 && SCMP_VER_MICRO < 1) #error This package requires libseccomp >= v2.5.1 #endif @@ -19,7 +19,8 @@ struct hakurei_syscall_rule { }; extern void *hakurei_scmp_allocate(uintptr_t f, size_t len); -int32_t hakurei_scmp_make_filter(int *ret_p, uintptr_t allocate_p, - uint32_t arch, uint32_t multiarch, - struct hakurei_syscall_rule *rules, - size_t rules_sz, hakurei_export_flag flags);
\ No newline at end of file +int32_t hakurei_scmp_make_filter( + int *ret_p, uintptr_t allocate_p, + uint32_t arch, uint32_t multiarch, + struct hakurei_syscall_rule *rules, + size_t rules_sz, hakurei_export_flag flags); |
