From be16970e770554b3c2191da41eb9bd4472b323e4 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Wed, 12 Mar 2025 15:18:52 +0900 Subject: helper/seccomp: seccomp_load on negative fd Signed-off-by: Ophestra --- helper/seccomp/seccomp-build.h | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 helper/seccomp/seccomp-build.h (limited to 'helper/seccomp/seccomp-build.h') diff --git a/helper/seccomp/seccomp-build.h b/helper/seccomp/seccomp-build.h new file mode 100644 index 00000000..0ae201d2 --- /dev/null +++ b/helper/seccomp/seccomp-build.h @@ -0,0 +1,23 @@ +#include +#include + +#if (SCMP_VER_MAJOR < 2) || \ + (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 5) || \ + (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR == 5 && SCMP_VER_MICRO < 1) +#error This package requires libseccomp >= v2.5.1 +#endif + +typedef enum { + F_VERBOSE = 1 << 0, + F_EXT = 1 << 1, + F_DENY_NS = 1 << 2, + F_DENY_TTY = 1 << 3, + F_DENY_DEVEL = 1 << 4, + F_MULTIARCH = 1 << 5, + F_LINUX32 = 1 << 6, + F_CAN = 1 << 7, + F_BLUETOOTH = 1 << 8, +} f_syscall_opts; + +extern void F_println(char *v); +int32_t f_build_filter(int fd, uint32_t arch, uint32_t multiarch, f_syscall_opts opts); \ No newline at end of file -- cgit v1.3.1