diff options
Diffstat (limited to 'seccomp/proc.go')
| -rw-r--r-- | seccomp/proc.go | 78 |
1 files changed, 78 insertions, 0 deletions
diff --git a/seccomp/proc.go b/seccomp/proc.go new file mode 100644 index 00000000..e4ce1853 --- /dev/null +++ b/seccomp/proc.go @@ -0,0 +1,78 @@ +package seccomp + +import ( + "context" + "errors" + "syscall" + + "git.gensokyo.uk/security/hakurei/helper/proc" +) + +const ( + PresetStrict = PresetExt | PresetDenyNS | PresetDenyTTY | PresetDenyDevel +) + +// New returns an inactive Encoder instance. +func New(rules []NativeRule, flags ExportFlag) *Encoder { return &Encoder{newExporter(rules, flags)} } + +// Load loads a filter into the kernel. +func Load(rules []NativeRule, flags ExportFlag) error { return Export(-1, rules, flags) } + +/* +An Encoder writes a BPF program to an output stream. + +Methods of Encoder are not safe for concurrent use. + +An Encoder must not be copied after first use. +*/ +type Encoder struct { + *exporter +} + +func (e *Encoder) Read(p []byte) (n int, err error) { + if err = e.prepare(); err != nil { + return + } + return e.r.Read(p) +} + +func (e *Encoder) Close() error { + if e.r == nil { + return syscall.EINVAL + } + + // this hangs if the cgo thread fails to exit + return errors.Join(e.closeWrite(), <-e.exportErr) +} + +// NewFile returns an instance of exporter implementing [proc.File]. +func NewFile(rules []NativeRule, flags ExportFlag) proc.File { + return &File{rules: rules, flags: flags} +} + +// File implements [proc.File] and provides access to the read end of exporter pipe. +type File struct { + rules []NativeRule + flags ExportFlag + proc.BaseFile +} + +func (f *File) ErrCount() int { return 2 } +func (f *File) Fulfill(ctx context.Context, dispatchErr func(error)) error { + e := newExporter(f.rules, f.flags) + if err := e.prepare(); err != nil { + return err + } + f.Set(e.r) + go func() { + select { + case err := <-e.exportErr: + dispatchErr(nil) + dispatchErr(err) + case <-ctx.Done(): + dispatchErr(e.closeWrite()) + dispatchErr(<-e.exportErr) + } + }() + return nil +} |
