aboutsummaryrefslogtreecommitdiffhomepage
path: root/seccomp/api.go
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-03-14 22:42:40 +0900
committerOphestra <cat@gensokyo.uk>2025-03-14 22:42:40 +0900
commit2647a71be1f287e50011a65653b9e9c806627899 (patch)
tree252dd8865632df348b7573ca6f31c04e4cb6c9e5 /seccomp/api.go
parent7c60a4d8e8baa77b42789c041838fa82dd7d36f9 (diff)
seccomp: move out of helper
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'seccomp/api.go')
-rw-r--r--seccomp/api.go71
1 files changed, 71 insertions, 0 deletions
diff --git a/seccomp/api.go b/seccomp/api.go
new file mode 100644
index 00000000..697b09f3
--- /dev/null
+++ b/seccomp/api.go
@@ -0,0 +1,71 @@
+package seccomp
+
+import (
+ "context"
+ "errors"
+ "syscall"
+
+ "git.gensokyo.uk/security/fortify/helper/proc"
+)
+
+// New returns an inactive Encoder instance.
+func New(opts SyscallOpts) *Encoder { return &Encoder{newExporter(opts)} }
+
+// Load loads a filter into the kernel.
+func Load(opts SyscallOpts) error { return buildFilter(-1, opts) }
+
+/*
+An Encoder writes a BPF program to an output stream.
+
+Methods of Encoder are not safe for concurrent use.
+
+An Encoder must not be copied after first use.
+*/
+type Encoder struct {
+ *exporter
+}
+
+func (e *Encoder) Read(p []byte) (n int, err error) {
+ if err = e.prepare(); err != nil {
+ return
+ }
+ return e.r.Read(p)
+}
+
+func (e *Encoder) Close() error {
+ if e.r == nil {
+ return syscall.EINVAL
+ }
+
+ // this hangs if the cgo thread fails to exit
+ return errors.Join(e.closeWrite(), <-e.exportErr)
+}
+
+// NewFile returns an instance of exporter implementing [proc.File].
+func NewFile(opts SyscallOpts) proc.File { return &File{opts: opts} }
+
+// File implements [proc.File] and provides access to the read end of exporter pipe.
+type File struct {
+ opts SyscallOpts
+ proc.BaseFile
+}
+
+func (f *File) ErrCount() int { return 2 }
+func (f *File) Fulfill(ctx context.Context, dispatchErr func(error)) error {
+ e := newExporter(f.opts)
+ if err := e.prepare(); err != nil {
+ return err
+ }
+ f.Set(e.r)
+ go func() {
+ select {
+ case err := <-e.exportErr:
+ dispatchErr(nil)
+ dispatchErr(err)
+ case <-ctx.Done():
+ dispatchErr(e.closeWrite())
+ dispatchErr(<-e.exportErr)
+ }
+ }()
+ return nil
+}