The Pedigree Project 0.1
sandbox-state.h
1/* Copyright (c) 2026, Pedigree Developers. */
2#ifndef POSIX_SANDBOX_STATE_H
3#define POSIX_SANDBOX_STATE_H
4
5#include "pedigree/kernel/compiler.h"
6#include "pedigree/kernel/process/Thread.h"
7#include "pedigree/kernel/processor/state_forward.h"
8#include "pedigree/kernel/utilities/SharedPointer.h"
9
10class LandlockDomain;
11class IpcNamespace;
14class Thread;
15
16EXPORTED_PUBLIC bool posix_no_new_privs();
17EXPORTED_PUBLIC int posix_set_no_new_privs();
18EXPORTED_PUBLIC int posix_seccomp_mode();
19EXPORTED_PUBLIC int posix_seccomp(unsigned int operation, unsigned int flags, const void* args);
20EXPORTED_PUBLIC void posix_sandbox_inherit(Thread& child, Thread& parent);
21EXPORTED_PUBLIC bool posix_sandbox_prepare_namespaces(
22 Thread& source, const SharedPointer<PosixTaskCredentials>& credentials,
24 Thread::SecurityStateRef& prepared);
25EXPORTED_PUBLIC SharedPointer<PosixTaskCredentials> posix_sandbox_credentials(Thread& thread);
26EXPORTED_PUBLIC bool posix_sandbox_set_credentials(
27 Thread& thread, const SharedPointer<PosixTaskCredentials>& credentials);
28EXPORTED_PUBLIC SharedPointer<LandlockDomain> posix_sandbox_domain();
29EXPORTED_PUBLIC bool posix_sandbox_restrict(const SharedPointer<LandlockDomain>& domain);
30
31#endif