The Pedigree Project 0.1
seccomp-filter.h
1/* Copyright (c) 2026, Pedigree Developers. */
2#ifndef POSIX_SECCOMP_FILTER_H
3#define POSIX_SECCOMP_FILTER_H
4
5#include <stddef.h>
6#include <stdint.h>
7
8namespace PosixSeccomp {
9constexpr size_t MaximumInstructions = 4096;
10constexpr uint32_t KillProcess = 0x80000000;
11
13 uint16_t code;
14 uint8_t jt;
15 uint8_t jf;
16 uint32_t k;
17};
18
19struct Data {
20 int32_t nr;
21 uint32_t arch;
22 uint64_t instructionPointer;
23 uint64_t args[6];
24};
25
26static_assert(sizeof(Instruction) == 8 && offsetof(Instruction, k) == 4, "Linux sock_filter ABI");
27static_assert(sizeof(Data) == 64 && offsetof(Data, instructionPointer) == 8 &&
28 offsetof(Data, args) == 16,
29 "Linux seccomp_data ABI");
30
31namespace Bpf {
32enum : uint16_t {
33 LD = 0x00,
34 LDX = 0x01,
35 ST = 0x02,
36 STX = 0x03,
37 ALU = 0x04,
38 JMP = 0x05,
39 RET = 0x06,
40 MISC = 0x07,
41 W = 0x00,
42 IMM = 0x00,
43 ABS = 0x20,
44 MEM = 0x60,
45 LEN = 0x80,
46 K = 0x00,
47 X = 0x08,
48 A = 0x10,
49 ADD = 0x00,
50 SUB = 0x10,
51 MUL = 0x20,
52 DIV = 0x30,
53 OR = 0x40,
54 AND = 0x50,
55 LSH = 0x60,
56 RSH = 0x70,
57 NEG = 0x80,
58 XOR = 0xa0,
59 JA = 0x00,
60 JEQ = 0x10,
61 JGT = 0x20,
62 JGE = 0x30,
63 JSET = 0x40,
64 TAX = 0x00,
65 TXA = 0x80
66};
67} // namespace Bpf
68
69// The caller owns an immutable kernel copy of the instructions. Validate it
70// before publication; evaluation allocates nothing and retains action/data bits.
71bool validate(const Instruction* instructions, size_t count);
72uint32_t evaluate(const Instruction* instructions, size_t count, const Data& data);
73} // namespace PosixSeccomp
74
75#endif