aboutsummaryrefslogtreecommitdiffhomepage
path: root/internal/proc/priv/shim/export.h
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-01-20 23:39:47 +0900
committerOphestra <cat@gensokyo.uk>2025-01-20 23:39:47 +0900
commit3df344828feaba958345050cfa56787e133d06db (patch)
tree7008d65284b8339165cfe731a02a892a790ba16a /internal/proc/priv/shim/export.h
parent27f5922d5c4d4432246d6de6eb0d81d574cdc8c7 (diff)
proc/priv/shim: seccomp bpf filter via libseccomp
Rulesets adapted from Flatpak for compatibility. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal/proc/priv/shim/export.h')
-rw-r--r--internal/proc/priv/shim/export.h22
1 files changed, 22 insertions, 0 deletions
diff --git a/internal/proc/priv/shim/export.h b/internal/proc/priv/shim/export.h
new file mode 100644
index 00000000..5df0dc65
--- /dev/null
+++ b/internal/proc/priv/shim/export.h
@@ -0,0 +1,22 @@
+#include <stdint.h>
+#include <seccomp.h>
+
+#if (SCMP_VER_MAJOR < 2) || \
+ (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 5) || \
+ (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR == 5 && SCMP_VER_MICRO < 1)
+#error This package requires libseccomp >= v2.5.1
+#endif
+
+typedef enum {
+ F_DENY_NS = 1 << 0,
+ F_DENY_TTY = 1 << 1,
+ F_DENY_DEVEL = 1 << 2,
+ F_MULTIARCH = 1 << 3,
+ F_LINUX32 = 1 << 4,
+ F_CAN = 1 << 5,
+ F_BLUETOOTH = 1 << 6,
+} f_syscall_opts;
+
+extern void F_println(char *v);
+int f_tmpfile_fd();
+int32_t f_export_bpf(int fd, uint32_t arch, uint32_t multiarch, f_syscall_opts opts); \ No newline at end of file