aboutsummaryrefslogtreecommitdiffhomepage
path: root/container
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-11-15 16:53:10 +0900
committerOphestra <cat@gensokyo.uk>2025-11-15 17:06:43 +0900
commit41b49137a8d11183c0d13ea32527f58f9c1a3dec (patch)
tree4b632dd654770bc55c409f8da671c89658f84ceb /container
parentc761e1de4dcf87b9106e4f70cb89217a81aa2f9f (diff)
.clang-format: do not limit line length
This hard limit destroys readability in some places. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container')
-rw-r--r--container/seccomp/libseccomp-helper.c28
-rw-r--r--container/seccomp/libseccomp-helper.h11
2 files changed, 17 insertions, 22 deletions
diff --git a/container/seccomp/libseccomp-helper.c b/container/seccomp/libseccomp-helper.c
index e5980d7e..539ed685 100644
--- a/container/seccomp/libseccomp-helper.c
+++ b/container/seccomp/libseccomp-helper.c
@@ -9,10 +9,11 @@
#define LEN(arr) (sizeof(arr) / sizeof((arr)[0]))
-int32_t hakurei_scmp_make_filter(int *ret_p, uintptr_t allocate_p,
- uint32_t arch, uint32_t multiarch,
- struct hakurei_syscall_rule *rules,
- size_t rules_sz, hakurei_export_flag flags) {
+int32_t hakurei_scmp_make_filter(
+ int *ret_p, uintptr_t allocate_p,
+ uint32_t arch, uint32_t multiarch,
+ struct hakurei_syscall_rule *rules,
+ size_t rules_sz, hakurei_export_flag flags) {
int i;
int last_allowed_family;
int disallowed;
@@ -72,11 +73,9 @@ int32_t hakurei_scmp_make_filter(int *ret_p, uintptr_t allocate_p,
assert(rule->m_errno == EPERM || rule->m_errno == ENOSYS);
if (rule->arg)
- *ret_p = seccomp_rule_add(ctx, SCMP_ACT_ERRNO(rule->m_errno),
- rule->syscall, 1, *rule->arg);
+ *ret_p = seccomp_rule_add(ctx, SCMP_ACT_ERRNO(rule->m_errno), rule->syscall, 1, *rule->arg);
else
- *ret_p = seccomp_rule_add(ctx, SCMP_ACT_ERRNO(rule->m_errno),
- rule->syscall, 0);
+ *ret_p = seccomp_rule_add(ctx, SCMP_ACT_ERRNO(rule->m_errno), rule->syscall, 0);
if (*ret_p == -EFAULT) {
res = 4;
@@ -93,22 +92,17 @@ int32_t hakurei_scmp_make_filter(int *ret_p, uintptr_t allocate_p,
last_allowed_family = -1;
for (i = 0; i < LEN(socket_family_allowlist); i++) {
if (socket_family_allowlist[i].flags_mask != 0 &&
- (socket_family_allowlist[i].flags_mask & flags) !=
- socket_family_allowlist[i].flags_mask)
+ (socket_family_allowlist[i].flags_mask & flags) != socket_family_allowlist[i].flags_mask)
continue;
- for (disallowed = last_allowed_family + 1;
- disallowed < socket_family_allowlist[i].family; disallowed++) {
+ for (disallowed = last_allowed_family + 1; disallowed < socket_family_allowlist[i].family; disallowed++) {
/* Blocklist the in-between valid families */
- seccomp_rule_add_exact(ctx, SCMP_ACT_ERRNO(EAFNOSUPPORT),
- SCMP_SYS(socket), 1,
- SCMP_A0(SCMP_CMP_EQ, disallowed));
+ seccomp_rule_add_exact(ctx, SCMP_ACT_ERRNO(EAFNOSUPPORT), SCMP_SYS(socket), 1, SCMP_A0(SCMP_CMP_EQ, disallowed));
}
last_allowed_family = socket_family_allowlist[i].family;
}
/* Blocklist the rest */
- seccomp_rule_add_exact(ctx, SCMP_ACT_ERRNO(EAFNOSUPPORT), SCMP_SYS(socket), 1,
- SCMP_A0(SCMP_CMP_GE, last_allowed_family + 1));
+ seccomp_rule_add_exact(ctx, SCMP_ACT_ERRNO(EAFNOSUPPORT), SCMP_SYS(socket), 1, SCMP_A0(SCMP_CMP_GE, last_allowed_family + 1));
if (allocate_p == 0) {
*ret_p = seccomp_load(ctx);
diff --git a/container/seccomp/libseccomp-helper.h b/container/seccomp/libseccomp-helper.h
index 0fad2d4a..72e29771 100644
--- a/container/seccomp/libseccomp-helper.h
+++ b/container/seccomp/libseccomp-helper.h
@@ -1,7 +1,7 @@
#include <seccomp.h>
#include <stdint.h>
-#if (SCMP_VER_MAJOR < 2) || (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 5) || \
+#if (SCMP_VER_MAJOR < 2) || (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 5) || \
(SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR == 5 && SCMP_VER_MICRO < 1)
#error This package requires libseccomp >= v2.5.1
#endif
@@ -19,7 +19,8 @@ struct hakurei_syscall_rule {
};
extern void *hakurei_scmp_allocate(uintptr_t f, size_t len);
-int32_t hakurei_scmp_make_filter(int *ret_p, uintptr_t allocate_p,
- uint32_t arch, uint32_t multiarch,
- struct hakurei_syscall_rule *rules,
- size_t rules_sz, hakurei_export_flag flags); \ No newline at end of file
+int32_t hakurei_scmp_make_filter(
+ int *ret_p, uintptr_t allocate_p,
+ uint32_t arch, uint32_t multiarch,
+ struct hakurei_syscall_rule *rules,
+ size_t rules_sz, hakurei_export_flag flags);