• source navigation  • diff markup  • identifier search  • freetext search  • 

Sources/procd/jail/seccomp-oci.h

  1 /*
  2  * Copyright (C) 2020 Daniel Golle <daniel@makrotopia.org>
  3  *
  4  * This program is free software; you can redistribute it and/or modify
  5  * it under the terms of the GNU Lesser General Public License version 2.1
  6  * as published by the Free Software Foundation
  7  *
  8  * This program is distributed in the hope that it will be useful,
  9  * but WITHOUT ANY WARRANTY; without even the implied warranty of
 10  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 11  * GNU General Public License for more details.
 12  */
 13 #ifndef _JAIL_SECCOMP_OCI_H_
 14 #define _JAIL_SECCOMP_OCI_H_
 15 
 16 #include <stdbool.h>
 17 #include <stdint.h>
 18 #include <linux/filter.h>
 19 
 20 #ifdef SECCOMP_SUPPORT
 21 extern const char * const seccomp_linker_base[];
 22 extern const char * const seccomp_init_base[];
 23 extern const char * const seccomp_loader_files[];
 24 #else
 25 static const char * const seccomp_linker_base[] = { NULL };
 26 static const char * const seccomp_init_base[] = { NULL };
 27 static const char * const seccomp_loader_files[] = { NULL };
 28 #endif
 29 
 30 struct sock_fprog *parseOCIlinuxseccomp(struct blob_attr *msg,
 31                                         const char * const *extra_allow);
 32 struct sock_fprog *seccomp_oci_audit_filter(const struct sock_fprog *prog);
 33 struct sock_fprog *seccomp_deny_delta(const char * const *names,
 34                                       const struct sock_fprog *app);
 35 int applyOCIlinuxseccomp(struct sock_fprog *prog, const char *container_id,
 36                          const char *bundle_path);
 37 bool seccomp_oci_needs_inproc(void);
 38 bool seccomp_profile_covers(const struct sock_fprog *prog, const char * const *names);
 39 
 40 #ifndef SECCOMP_SUPPORT
 41 struct sock_fprog *parseOCIlinuxseccomp(struct blob_attr *msg,
 42                                         const char * const *extra_allow) {
 43         return NULL;
 44 }
 45 
 46 struct sock_fprog *seccomp_oci_audit_filter(const struct sock_fprog *prog) {
 47         return NULL;
 48 }
 49 
 50 int applyOCIlinuxseccomp(struct sock_fprog *prog, const char *container_id,
 51                          const char *bundle_path) {
 52         return ENOTSUP;
 53 }
 54 
 55 bool seccomp_oci_needs_inproc(void) {
 56         return false;
 57 }
 58 #endif
 59 
 60 #endif
 61 

This page was automatically generated by LXR 0.3.1.  •  OpenWrt