aboutsummaryrefslogtreecommitdiffhomepage
path: root/seccomp/api.go
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-03-17 02:55:36 +0900
committerOphestra <cat@gensokyo.uk>2025-03-17 02:55:36 +0900
commit24618ab9a1524e8b8986a9bf67667288e642fcf1 (patch)
treeb3f2a71a2c9bedf937d0fec00092ad9133cb3ec9 /seccomp/api.go
parent9ce4706a0766880c072cccd2643d66f614a6a16b (diff)
sandbox: move out of internal
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'seccomp/api.go')
-rw-r--r--seccomp/api.go71
1 files changed, 0 insertions, 71 deletions
diff --git a/seccomp/api.go b/seccomp/api.go
deleted file mode 100644
index 697b09f3..00000000
--- a/seccomp/api.go
+++ /dev/null
@@ -1,71 +0,0 @@
-package seccomp
-
-import (
- "context"
- "errors"
- "syscall"
-
- "git.gensokyo.uk/security/fortify/helper/proc"
-)
-
-// New returns an inactive Encoder instance.
-func New(opts SyscallOpts) *Encoder { return &Encoder{newExporter(opts)} }
-
-// Load loads a filter into the kernel.
-func Load(opts SyscallOpts) error { return buildFilter(-1, opts) }
-
-/*
-An Encoder writes a BPF program to an output stream.
-
-Methods of Encoder are not safe for concurrent use.
-
-An Encoder must not be copied after first use.
-*/
-type Encoder struct {
- *exporter
-}
-
-func (e *Encoder) Read(p []byte) (n int, err error) {
- if err = e.prepare(); err != nil {
- return
- }
- return e.r.Read(p)
-}
-
-func (e *Encoder) Close() error {
- if e.r == nil {
- return syscall.EINVAL
- }
-
- // this hangs if the cgo thread fails to exit
- return errors.Join(e.closeWrite(), <-e.exportErr)
-}
-
-// NewFile returns an instance of exporter implementing [proc.File].
-func NewFile(opts SyscallOpts) proc.File { return &File{opts: opts} }
-
-// File implements [proc.File] and provides access to the read end of exporter pipe.
-type File struct {
- opts SyscallOpts
- proc.BaseFile
-}
-
-func (f *File) ErrCount() int { return 2 }
-func (f *File) Fulfill(ctx context.Context, dispatchErr func(error)) error {
- e := newExporter(f.opts)
- if err := e.prepare(); err != nil {
- return err
- }
- f.Set(e.r)
- go func() {
- select {
- case err := <-e.exportErr:
- dispatchErr(nil)
- dispatchErr(err)
- case <-ctx.Done():
- dispatchErr(e.closeWrite())
- dispatchErr(<-e.exportErr)
- }
- }()
- return nil
-}