diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-04-08 01:59:45 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-04-08 01:59:45 +0900 |
| commit | 584405f7ccd4c8c0e63762e113f4650f2abd469e (patch) | |
| tree | f72d79d1a90e9bffe8f5c975e564ad40c602f2f7 /sandbox/seccomp/api.go | |
| parent | 50127ed5f9bc89f38c7d5d1aa06b4d99229b9c64 (diff) | |
sandbox/seccomp: rename flag type and constants
The names are ambiguous. Rename them to make more sense.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'sandbox/seccomp/api.go')
| -rw-r--r-- | sandbox/seccomp/api.go | 13 |
1 files changed, 9 insertions, 4 deletions
diff --git a/sandbox/seccomp/api.go b/sandbox/seccomp/api.go index 697b09f3..f084a14f 100644 --- a/sandbox/seccomp/api.go +++ b/sandbox/seccomp/api.go @@ -8,11 +8,16 @@ import ( "git.gensokyo.uk/security/fortify/helper/proc" ) +const ( + PresetStrict = FilterExt | FilterDenyNS | FilterDenyTTY | FilterDenyDevel + PresetCommon = PresetStrict | FilterMultiarch +) + // New returns an inactive Encoder instance. -func New(opts SyscallOpts) *Encoder { return &Encoder{newExporter(opts)} } +func New(opts FilterOpts) *Encoder { return &Encoder{newExporter(opts)} } // Load loads a filter into the kernel. -func Load(opts SyscallOpts) error { return buildFilter(-1, opts) } +func Load(opts FilterOpts) error { return buildFilter(-1, opts) } /* An Encoder writes a BPF program to an output stream. @@ -42,11 +47,11 @@ func (e *Encoder) Close() error { } // NewFile returns an instance of exporter implementing [proc.File]. -func NewFile(opts SyscallOpts) proc.File { return &File{opts: opts} } +func NewFile(opts FilterOpts) proc.File { return &File{opts: opts} } // File implements [proc.File] and provides access to the read end of exporter pipe. type File struct { - opts SyscallOpts + opts FilterOpts proc.BaseFile } |
