1 /* SPDX-License-Identifier: LGPL-2.1+ */
3 #ifndef __LXC_LXCSECCOMP_H
4 #define __LXC_LXCSECCOMP_H
11 #include <linux/seccomp.h>
15 #if HAVE_DECL_SECCOMP_NOTIFY_FD
16 #include <sys/socket.h>
22 #include "memory_utils.h"
25 struct lxc_async_descr
;
28 #ifndef SECCOMP_FILTER_FLAG_NEW_LISTENER
29 #define SECCOMP_FILTER_FLAG_NEW_LISTENER (1UL << 3)
35 #if HAVE_DECL_SECCOMP_NOTIFY_FD
37 #if !HAVE_STRUCT_SECCOMP_NOTIF_SIZES
38 struct seccomp_notif_sizes
{
40 __u16 seccomp_notif_resp
;
45 struct seccomp_notify_proxy_msg
{
49 struct seccomp_notif_sizes sizes
;
51 /* followed by: seccomp_notif, seccomp_notif_resp, cookie */
54 struct seccomp_notify
{
55 bool wants_supervision
;
58 struct sockaddr_un proxy_addr
;
59 struct seccomp_notif_sizes sizes
;
60 struct seccomp_notif
*req_buf
;
61 struct seccomp_notif_resp
*rsp_buf
;
65 #endif /* HAVE_DECL_SECCOMP_NOTIFY_FD */
69 #if HAVE_SCMP_FILTER_CTX
70 unsigned int allow_nesting
;
71 scmp_filter_ctx seccomp_ctx
;
72 #endif /* HAVE_SCMP_FILTER_CTX */
74 #if HAVE_DECL_SECCOMP_NOTIFY_FD
75 struct seccomp_notify notifier
;
76 #endif /* HAVE_DECL_SECCOMP_NOTIFY_FD */
79 __hidden
extern int lxc_seccomp_load(struct lxc_conf
*conf
);
80 __hidden
extern int lxc_read_seccomp_config(struct lxc_conf
*conf
);
81 __hidden
extern void lxc_seccomp_free(struct lxc_seccomp
*seccomp
);
82 __hidden
extern int seccomp_notify_cleanup_handler(int fd
, void *data
);
83 __hidden
extern int seccomp_notify_handler(int fd
, uint32_t events
, void *data
,
84 struct lxc_async_descr
*descr
);
85 __hidden
extern void seccomp_conf_init(struct lxc_conf
*conf
);
86 __hidden
extern int lxc_seccomp_setup_proxy(struct lxc_seccomp
*seccomp
,
87 struct lxc_async_descr
*descr
,
88 struct lxc_handler
*handler
);
89 __hidden
extern int lxc_seccomp_send_notifier_fd(struct lxc_seccomp
*seccomp
, int socket_fd
);
90 __hidden
extern int lxc_seccomp_recv_notifier_fd(struct lxc_seccomp
*seccomp
, int socket_fd
);
91 __hidden
extern int lxc_seccomp_add_notifier(const char *name
, const char *lxcpath
,
92 struct lxc_seccomp
*seccomp
);
93 static inline void lxc_seccomp_close_notifier_fd(struct lxc_seccomp
*seccomp
)
95 #if HAVE_DECL_SECCOMP_NOTIFY_FD
96 if (seccomp
->notifier
.wants_supervision
)
97 close_prot_errno_disarm(seccomp
->notifier
.notify_fd
);
101 static inline int lxc_seccomp_get_notify_fd(struct lxc_seccomp
*seccomp
)
103 #if HAVE_DECL_SECCOMP_NOTIFY_FD
104 return seccomp
->notifier
.notify_fd
;
111 #else /* HAVE_SECCOMP */
117 static inline int lxc_seccomp_load(struct lxc_conf
*conf
)
122 static inline int lxc_read_seccomp_config(struct lxc_conf
*conf
)
127 static inline void lxc_seccomp_free(struct lxc_seccomp
*seccomp
)
129 free_disarm(seccomp
->seccomp
);
132 static inline int seccomp_notify_handler(int fd
, uint32_t events
, void *data
,
133 struct lxc_async_descr
*descr
)
135 return ret_errno(ENOSYS
);
138 static inline int seccomp_notify_cleanup_handler(void *data
)
140 return ret_errno(ENOSYS
);
143 static inline void seccomp_conf_init(struct lxc_conf
*conf
)
147 static inline int lxc_seccomp_setup_proxy(struct lxc_seccomp
*seccomp
,
148 struct lxc_async_descr
*descr
,
149 struct lxc_handler
*handler
)
154 static inline int lxc_seccomp_send_notifier_fd(struct lxc_seccomp
*seccomp
,
160 static inline int lxc_seccomp_recv_notifier_fd(struct lxc_seccomp
*seccomp
,
166 static inline int lxc_seccomp_add_notifier(const char *name
, const char *lxcpath
,
167 struct lxc_seccomp
*seccomp
)
172 static inline int lxc_seccomp_get_notify_fd(struct lxc_seccomp
*seccomp
)
177 static inline void lxc_seccomp_close_notifier_fd(struct lxc_seccomp
*seccomp
)
181 #endif /* HAVE_SECCOMP */
182 #endif /* __LXC_LXCSECCOMP_H */