The Pedigree Project
0.1
src
modules
subsys
posix
sandbox-state.h
1
/* Copyright (c) 2026, Pedigree Developers. */
2
#ifndef POSIX_SANDBOX_STATE_H
3
#define POSIX_SANDBOX_STATE_H
4
5
#include "pedigree/kernel/compiler.h"
6
#include "pedigree/kernel/process/Thread.h"
7
#include "pedigree/kernel/processor/state_forward.h"
8
#include "pedigree/kernel/utilities/SharedPointer.h"
9
10
class
LandlockDomain
;
11
class
IpcNamespace
;
12
class
PosixNetworkNamespace
;
13
class
PosixTaskCredentials
;
14
class
Thread
;
15
16
EXPORTED_PUBLIC
bool
posix_no_new_privs();
17
EXPORTED_PUBLIC
int
posix_set_no_new_privs();
18
EXPORTED_PUBLIC
int
posix_seccomp_mode();
19
EXPORTED_PUBLIC
int
posix_seccomp(
unsigned
int
operation,
unsigned
int
flags,
const
void
* args);
20
EXPORTED_PUBLIC
void
posix_sandbox_inherit(
Thread
& child,
Thread
& parent);
21
EXPORTED_PUBLIC
bool
posix_sandbox_prepare_namespaces(
22
Thread
& source,
const
SharedPointer<PosixTaskCredentials>
& credentials,
23
const
SharedPointer<IpcNamespace>
& ipc,
const
SharedPointer<PosixNetworkNamespace>
& network,
24
Thread::SecurityStateRef
& prepared);
25
EXPORTED_PUBLIC
SharedPointer<PosixTaskCredentials>
posix_sandbox_credentials(
Thread
& thread);
26
EXPORTED_PUBLIC
bool
posix_sandbox_set_credentials(
27
Thread
& thread,
const
SharedPointer<PosixTaskCredentials>
& credentials);
28
EXPORTED_PUBLIC
SharedPointer<LandlockDomain>
posix_sandbox_domain();
29
EXPORTED_PUBLIC
bool
posix_sandbox_restrict(
const
SharedPointer<LandlockDomain>
& domain);
30
31
#endif
IpcNamespace
Definition
ipc-namespace.h:9
LandlockDomain
Definition
landlock.h:17
PosixNetworkNamespace
Definition
network-namespace.h:17
PosixTaskCredentials
Definition
user-namespace.h:43
SharedPointer
Definition
SharedPointer.h:31
Thread
Definition
Thread.h:77
Generated on Sat Oct 3 2026 06:38:05 for The Pedigree Project by
1.9.8