2 * lxc: linux Container library
4 * (C) Copyright Canonical, Inc. 2012
7 * Serge Hallyn <serge.hallyn@canonical.com>
9 * This library is free software; you can redistribute it and/or
10 * modify it under the terms of the GNU Lesser General Public
11 * License as published by the Free Software Foundation; either
12 * version 2.1 of the License, or (at your option) any later version.
14 * This library is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
17 * Lesser General Public License for more details.
19 * You should have received a copy of the GNU Lesser General Public
20 * License along with this library; if not, write to the Free Software
21 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
24 #ifndef __LXC_LXCSECCOMP_H
25 #define __LXC_LXCSECCOMP_H
32 #include <linux/seccomp.h>
35 #if HAVE_DECL_SECCOMP_NOTIFY_FD
36 #include <sys/socket.h>
42 #include "memory_utils.h"
45 struct lxc_epoll_descr
;
48 #ifndef SECCOMP_FILTER_FLAG_NEW_LISTENER
49 #define SECCOMP_FILTER_FLAG_NEW_LISTENER (1UL << 3)
55 #if HAVE_DECL_SECCOMP_NOTIFY_FD
57 #if !HAVE_STRUCT_SECCOMP_NOTIF_SIZES
58 struct seccomp_notif_sizes
{
60 __u16 seccomp_notif_resp
;
65 struct seccomp_notify_proxy_msg
{
69 struct seccomp_notif_sizes sizes
;
71 /* followed by: seccomp_notif, seccomp_notif_resp, cookie */
74 struct seccomp_notify
{
75 bool wants_supervision
;
78 struct sockaddr_un proxy_addr
;
79 struct seccomp_notif_sizes sizes
;
80 struct seccomp_notif
*req_buf
;
81 struct seccomp_notif_resp
*rsp_buf
;
85 #define HAVE_SECCOMP_NOTIFY 1
87 #endif /* HAVE_DECL_SECCOMP_NOTIFY_FD */
91 #if HAVE_SCMP_FILTER_CTX
92 unsigned int allow_nesting
;
93 scmp_filter_ctx seccomp_ctx
;
94 #endif /* HAVE_SCMP_FILTER_CTX */
96 #if HAVE_DECL_SECCOMP_NOTIFY_FD
97 struct seccomp_notify notifier
;
98 #endif /* HAVE_DECL_SECCOMP_NOTIFY_FD */
101 extern int lxc_seccomp_load(struct lxc_conf
*conf
);
102 extern int lxc_read_seccomp_config(struct lxc_conf
*conf
);
103 extern void lxc_seccomp_free(struct lxc_seccomp
*seccomp
);
104 extern int seccomp_notify_handler(int fd
, uint32_t events
, void *data
,
105 struct lxc_epoll_descr
*descr
);
106 extern void seccomp_conf_init(struct lxc_conf
*conf
);
107 extern int lxc_seccomp_setup_proxy(struct lxc_seccomp
*seccomp
,
108 struct lxc_epoll_descr
*descr
,
109 struct lxc_handler
*handler
);
110 extern int lxc_seccomp_send_notifier_fd(struct lxc_seccomp
*seccomp
,
112 extern int lxc_seccomp_recv_notifier_fd(struct lxc_seccomp
*seccomp
,
114 extern int lxc_seccomp_add_notifier(const char *name
, const char *lxcpath
,
115 struct lxc_seccomp
*seccomp
);
116 static inline int lxc_seccomp_get_notify_fd(struct lxc_seccomp
*seccomp
)
118 #if HAVE_DECL_SECCOMP_NOTIFY_FD
119 return seccomp
->notifier
.notify_fd
;
126 #else /* HAVE_SECCOMP */
132 static inline int lxc_seccomp_load(struct lxc_conf
*conf
)
137 static inline int lxc_read_seccomp_config(struct lxc_conf
*conf
)
142 static inline void lxc_seccomp_free(struct lxc_seccomp
*seccomp
)
144 free_disarm(seccomp
->seccomp
);
147 static inline int seccomp_notify_handler(int fd
, uint32_t events
, void *data
,
148 struct lxc_epoll_descr
*descr
)
153 static inline void seccomp_conf_init(struct lxc_conf
*conf
)
157 static inline int lxc_seccomp_setup_proxy(struct lxc_seccomp
*seccomp
,
158 struct lxc_epoll_descr
*descr
,
159 struct lxc_handler
*handler
)
164 static inline int lxc_seccomp_send_notifier_fd(struct lxc_seccomp
*seccomp
,
170 static inline int lxc_seccomp_recv_notifier_fd(struct lxc_seccomp
*seccomp
,
176 static inline int lxc_seccomp_add_notifier(const char *name
, const char *lxcpath
,
177 struct lxc_seccomp
*seccomp
)
182 static inline int lxc_seccomp_get_notify_fd(struct lxc_seccomp
*seccomp
)
187 #endif /* HAVE_SECCOMP */
188 #endif /* __LXC_LXCSECCOMP_H */