From e03d702d088ad78645d1cce448713ef71b12e803 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Tue, 1 Jul 2025 00:35:27 +0900 Subject: sandbox/seccomp: implement syscall lookup This uses the Go map and is verified against libseccomp. Signed-off-by: Ophestra --- sandbox/seccomp/syscall.go | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) create mode 100644 sandbox/seccomp/syscall.go (limited to 'sandbox/seccomp/syscall.go') diff --git a/sandbox/seccomp/syscall.go b/sandbox/seccomp/syscall.go new file mode 100644 index 00000000..36a988aa --- /dev/null +++ b/sandbox/seccomp/syscall.go @@ -0,0 +1,28 @@ +package seccomp + +import "iter" + +// Syscalls returns an iterator over all wired syscalls. +func Syscalls() iter.Seq2[string, int] { + return func(yield func(string, int) bool) { + for name, num := range syscallNum { + if !yield(name, num) { + return + } + } + for name, num := range syscallNumExtra { + if !yield(name, num) { + return + } + } + } +} + +// SyscallResolveName resolves a syscall number from its string representation. +func SyscallResolveName(name string) (num int, ok bool) { + if num, ok = syscallNum[name]; ok { + return + } + num, ok = syscallNumExtra[name] + return +} -- cgit v1.3.1