1 /* SPDX-License-Identifier: LGPL-2.1+ */
3 #ifndef __LXC_LXCSECCOMP_H
4 #define __LXC_LXCSECCOMP_H
11 #include <linux/seccomp.h>
14 #if HAVE_DECL_SECCOMP_NOTIFY_FD
15 #include <sys/socket.h>
21 #include "memory_utils.h"
24 struct lxc_epoll_descr
;
27 #ifndef SECCOMP_FILTER_FLAG_NEW_LISTENER
28 #define SECCOMP_FILTER_FLAG_NEW_LISTENER (1UL << 3)
34 #if HAVE_DECL_SECCOMP_NOTIFY_FD
36 #if !HAVE_STRUCT_SECCOMP_NOTIF_SIZES
37 struct seccomp_notif_sizes
{
39 __u16 seccomp_notif_resp
;
44 struct seccomp_notify_proxy_msg
{
48 struct seccomp_notif_sizes sizes
;
50 /* followed by: seccomp_notif, seccomp_notif_resp, cookie */
53 struct seccomp_notify
{
54 bool wants_supervision
;
57 struct sockaddr_un proxy_addr
;
58 struct seccomp_notif_sizes sizes
;
59 struct seccomp_notif
*req_buf
;
60 struct seccomp_notif_resp
*rsp_buf
;
64 #define HAVE_SECCOMP_NOTIFY 1
66 #endif /* HAVE_DECL_SECCOMP_NOTIFY_FD */
70 #if HAVE_SCMP_FILTER_CTX
71 unsigned int allow_nesting
;
72 scmp_filter_ctx seccomp_ctx
;
73 #endif /* HAVE_SCMP_FILTER_CTX */
75 #if HAVE_DECL_SECCOMP_NOTIFY_FD
76 struct seccomp_notify notifier
;
77 #endif /* HAVE_DECL_SECCOMP_NOTIFY_FD */
80 extern int lxc_seccomp_load(struct lxc_conf
*conf
);
81 extern int lxc_read_seccomp_config(struct lxc_conf
*conf
);
82 extern void lxc_seccomp_free(struct lxc_seccomp
*seccomp
);
83 extern int seccomp_notify_handler(int fd
, uint32_t events
, void *data
,
84 struct lxc_epoll_descr
*descr
);
85 extern void seccomp_conf_init(struct lxc_conf
*conf
);
86 extern int lxc_seccomp_setup_proxy(struct lxc_seccomp
*seccomp
,
87 struct lxc_epoll_descr
*descr
,
88 struct lxc_handler
*handler
);
89 extern int lxc_seccomp_send_notifier_fd(struct lxc_seccomp
*seccomp
,
91 extern int lxc_seccomp_recv_notifier_fd(struct lxc_seccomp
*seccomp
,
93 extern int lxc_seccomp_add_notifier(const char *name
, const char *lxcpath
,
94 struct lxc_seccomp
*seccomp
);
95 static inline int lxc_seccomp_get_notify_fd(struct lxc_seccomp
*seccomp
)
97 #if HAVE_DECL_SECCOMP_NOTIFY_FD
98 return seccomp
->notifier
.notify_fd
;
105 #else /* HAVE_SECCOMP */
111 static inline int lxc_seccomp_load(struct lxc_conf
*conf
)
116 static inline int lxc_read_seccomp_config(struct lxc_conf
*conf
)
121 static inline void lxc_seccomp_free(struct lxc_seccomp
*seccomp
)
123 free_disarm(seccomp
->seccomp
);
126 static inline int seccomp_notify_handler(int fd
, uint32_t events
, void *data
,
127 struct lxc_epoll_descr
*descr
)
132 static inline void seccomp_conf_init(struct lxc_conf
*conf
)
136 static inline int lxc_seccomp_setup_proxy(struct lxc_seccomp
*seccomp
,
137 struct lxc_epoll_descr
*descr
,
138 struct lxc_handler
*handler
)
143 static inline int lxc_seccomp_send_notifier_fd(struct lxc_seccomp
*seccomp
,
149 static inline int lxc_seccomp_recv_notifier_fd(struct lxc_seccomp
*seccomp
,
155 static inline int lxc_seccomp_add_notifier(const char *name
, const char *lxcpath
,
156 struct lxc_seccomp
*seccomp
)
161 static inline int lxc_seccomp_get_notify_fd(struct lxc_seccomp
*seccomp
)
166 #endif /* HAVE_SECCOMP */
167 #endif /* __LXC_LXCSECCOMP_H */