diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-01-22 01:51:10 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-01-22 01:52:57 +0900 |
| commit | 9a239fa1a5ad2ff248ca7a9d39342f66926c9fef (patch) | |
| tree | 09efadb2ddf4eaeaf153d7e4b7d73e1b20d2fc1a /helper/bwrap/seccomp-export.h | |
| parent | 82029948e6d8d047edc02ccff354e16c419e5742 (diff) | |
helper/bwrap: integrate seccomp into helper interface
This makes API usage much cleaner, and encapsulates all bwrap arguments in argsWt.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'helper/bwrap/seccomp-export.h')
| -rw-r--r-- | helper/bwrap/seccomp-export.h | 22 |
1 files changed, 22 insertions, 0 deletions
diff --git a/helper/bwrap/seccomp-export.h b/helper/bwrap/seccomp-export.h new file mode 100644 index 00000000..5df0dc65 --- /dev/null +++ b/helper/bwrap/seccomp-export.h @@ -0,0 +1,22 @@ +#include <stdint.h> +#include <seccomp.h> + +#if (SCMP_VER_MAJOR < 2) || \ + (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 5) || \ + (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR == 5 && SCMP_VER_MICRO < 1) +#error This package requires libseccomp >= v2.5.1 +#endif + +typedef enum { + F_DENY_NS = 1 << 0, + F_DENY_TTY = 1 << 1, + F_DENY_DEVEL = 1 << 2, + F_MULTIARCH = 1 << 3, + F_LINUX32 = 1 << 4, + F_CAN = 1 << 5, + F_BLUETOOTH = 1 << 6, +} f_syscall_opts; + +extern void F_println(char *v); +int f_tmpfile_fd(); +int32_t f_export_bpf(int fd, uint32_t arch, uint32_t multiarch, f_syscall_opts opts);
\ No newline at end of file |
