aboutsummaryrefslogtreecommitdiffhomepage
path: root/helper/bwrap/seccomp-export.h
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-01-22 01:51:10 +0900
committerOphestra <cat@gensokyo.uk>2025-01-22 01:52:57 +0900
commit9a239fa1a5ad2ff248ca7a9d39342f66926c9fef (patch)
tree09efadb2ddf4eaeaf153d7e4b7d73e1b20d2fc1a /helper/bwrap/seccomp-export.h
parent82029948e6d8d047edc02ccff354e16c419e5742 (diff)
helper/bwrap: integrate seccomp into helper interface
This makes API usage much cleaner, and encapsulates all bwrap arguments in argsWt. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'helper/bwrap/seccomp-export.h')
-rw-r--r--helper/bwrap/seccomp-export.h22
1 files changed, 22 insertions, 0 deletions
diff --git a/helper/bwrap/seccomp-export.h b/helper/bwrap/seccomp-export.h
new file mode 100644
index 00000000..5df0dc65
--- /dev/null
+++ b/helper/bwrap/seccomp-export.h
@@ -0,0 +1,22 @@
+#include <stdint.h>
+#include <seccomp.h>
+
+#if (SCMP_VER_MAJOR < 2) || \
+ (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 5) || \
+ (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR == 5 && SCMP_VER_MICRO < 1)
+#error This package requires libseccomp >= v2.5.1
+#endif
+
+typedef enum {
+ F_DENY_NS = 1 << 0,
+ F_DENY_TTY = 1 << 1,
+ F_DENY_DEVEL = 1 << 2,
+ F_MULTIARCH = 1 << 3,
+ F_LINUX32 = 1 << 4,
+ F_CAN = 1 << 5,
+ F_BLUETOOTH = 1 << 6,
+} f_syscall_opts;
+
+extern void F_println(char *v);
+int f_tmpfile_fd();
+int32_t f_export_bpf(int fd, uint32_t arch, uint32_t multiarch, f_syscall_opts opts); \ No newline at end of file