|
Packit |
56e23f |
/**
|
|
Packit |
56e23f |
* BPF Language Definitions
|
|
Packit |
56e23f |
*
|
|
Packit |
56e23f |
* Copyright (c) 2012 Red Hat <pmoore@redhat.com>
|
|
Packit |
56e23f |
* Author: Paul Moore <paul@paul-moore.com>
|
|
Packit |
56e23f |
*/
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/*
|
|
Packit |
56e23f |
* This library is free software; you can redistribute it and/or modify it
|
|
Packit |
56e23f |
* under the terms of version 2.1 of the GNU Lesser General Public License as
|
|
Packit |
56e23f |
* published by the Free Software Foundation.
|
|
Packit |
56e23f |
*
|
|
Packit |
56e23f |
* This library is distributed in the hope that it will be useful, but WITHOUT
|
|
Packit |
56e23f |
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
|
Packit |
56e23f |
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public License
|
|
Packit |
56e23f |
* for more details.
|
|
Packit |
56e23f |
*
|
|
Packit |
56e23f |
* You should have received a copy of the GNU Lesser General Public License
|
|
Packit |
56e23f |
* along with this library; if not, see <http://www.gnu.org/licenses>.
|
|
Packit |
56e23f |
*/
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
#ifndef _BPF_H
|
|
Packit |
56e23f |
#define _BPF_H
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
#include <inttypes.h>
|
|
Packit |
56e23f |
#include <stddef.h>
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/* most of these structures and values are designed to match the Linux Kernel's
|
|
Packit |
56e23f |
* BPF interface (see /usr/include/linux/{filter,seccomp}.h), but we define our
|
|
Packit |
56e23f |
* own here so that we can function independent of the host OS */
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/* XXX - need to verify these values */
|
|
Packit |
56e23f |
#define BPF_SCRATCH_SIZE 6
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/**
|
|
Packit |
56e23f |
* Syscall record data format used by seccomp
|
|
Packit |
56e23f |
*/
|
|
Packit |
56e23f |
#define BPF_SYS_ARG_MAX 6
|
|
Packit |
56e23f |
struct seccomp_data {
|
|
Packit |
56e23f |
int32_t nr;
|
|
Packit |
56e23f |
uint32_t arch;
|
|
Packit |
56e23f |
uint64_t instruction_pointer;
|
|
Packit |
56e23f |
uint64_t args[BPF_SYS_ARG_MAX];
|
|
Packit |
56e23f |
};
|
|
Packit |
56e23f |
#define BPF_SYSCALL_MAX (sizeof(struct seccomp_data))
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/**
|
|
Packit |
56e23f |
* BPF instruction format
|
|
Packit |
56e23f |
*/
|
|
Packit |
56e23f |
struct sock_filter {
|
|
Packit |
56e23f |
uint16_t code;
|
|
Packit |
56e23f |
uint8_t jt;
|
|
Packit |
56e23f |
uint8_t jf;
|
|
Packit |
56e23f |
uint32_t k;
|
|
Packit |
56e23f |
} __attribute__ ((packed));
|
|
Packit |
56e23f |
typedef struct sock_filter bpf_instr_raw;
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/* seccomp return masks */
|
|
Packit |
56e23f |
#define SECCOMP_RET_ACTION_FULL 0xffff0000U
|
|
Packit |
56e23f |
#define SECCOMP_RET_ACTION 0x7fff0000U
|
|
Packit |
56e23f |
#define SECCOMP_RET_DATA 0x0000ffffU
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/* seccomp action values */
|
|
Packit |
56e23f |
#define SECCOMP_RET_KILL_PROCESS 0x80000000U
|
|
Packit |
56e23f |
#define SECCOMP_RET_KILL_THREAD 0x00000000U
|
|
Packit |
56e23f |
#define SECCOMP_RET_KILL SECCOMP_RET_KILL_THREAD
|
|
Packit |
56e23f |
#define SECCOMP_RET_TRAP 0x00030000U
|
|
Packit |
56e23f |
#define SECCOMP_RET_ERRNO 0x00050000U
|
|
Packit |
56e23f |
#define SECCOMP_RET_TRACE 0x7ff00000U
|
|
Packit |
56e23f |
#define SECCOMP_RET_LOG 0x7ffc0000U
|
|
Packit |
56e23f |
#define SECCOMP_RET_ALLOW 0x7fff0000U
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/* bpf command classes */
|
|
Packit |
56e23f |
#define BPF_CLASS(code) ((code) & 0x07)
|
|
Packit |
56e23f |
#define BPF_LD 0x00
|
|
Packit |
56e23f |
#define BPF_LDX 0x01
|
|
Packit |
56e23f |
#define BPF_ST 0x02
|
|
Packit |
56e23f |
#define BPF_STX 0x03
|
|
Packit |
56e23f |
#define BPF_ALU 0x04
|
|
Packit |
56e23f |
#define BPF_JMP 0x05
|
|
Packit |
56e23f |
#define BPF_RET 0x06
|
|
Packit |
56e23f |
#define BPF_MISC 0x07
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/* BPF_LD and BPF_LDX */
|
|
Packit |
56e23f |
#define BPF_SIZE(code) ((code) & 0x18)
|
|
Packit |
56e23f |
#define BPF_W 0x00
|
|
Packit |
56e23f |
#define BPF_H 0x08
|
|
Packit |
56e23f |
#define BPF_B 0x10
|
|
Packit |
56e23f |
#define BPF_MODE(code) ((code) & 0xe0)
|
|
Packit |
56e23f |
#define BPF_IMM 0x00
|
|
Packit |
56e23f |
#define BPF_ABS 0x20
|
|
Packit |
56e23f |
#define BPF_IND 0x40
|
|
Packit |
56e23f |
#define BPF_MEM 0x60
|
|
Packit |
56e23f |
#define BPF_LEN 0x80
|
|
Packit |
56e23f |
#define BPF_MSH 0xa0
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
#define BPF_OP(code) ((code) & 0xf0)
|
|
Packit |
56e23f |
/* BPF_ALU */
|
|
Packit |
56e23f |
#define BPF_ADD 0x00
|
|
Packit |
56e23f |
#define BPF_SUB 0x10
|
|
Packit |
56e23f |
#define BPF_MUL 0x20
|
|
Packit |
56e23f |
#define BPF_DIV 0x30
|
|
Packit |
56e23f |
#define BPF_OR 0x40
|
|
Packit |
56e23f |
#define BPF_AND 0x50
|
|
Packit |
56e23f |
#define BPF_LSH 0x60
|
|
Packit |
56e23f |
#define BPF_RSH 0x70
|
|
Packit |
56e23f |
#define BPF_NEG 0x80
|
|
Packit |
56e23f |
#define BPF_MOD 0x90
|
|
Packit |
56e23f |
#define BPF_XOR 0xa0
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/* BPF_JMP */
|
|
Packit |
56e23f |
#define BPF_JA 0x00
|
|
Packit |
56e23f |
#define BPF_JEQ 0x10
|
|
Packit |
56e23f |
#define BPF_JGT 0x20
|
|
Packit |
56e23f |
#define BPF_JGE 0x30
|
|
Packit |
56e23f |
#define BPF_JSET 0x40
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
#define BPF_SRC(code) ((code) & 0x08)
|
|
Packit |
56e23f |
#define BPF_K 0x00
|
|
Packit |
56e23f |
#define BPF_X 0x08
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/* BPF_RET (BPF_K and BPF_X also apply) */
|
|
Packit |
56e23f |
#define BPF_RVAL(code) ((code) & 0x18)
|
|
Packit |
56e23f |
#define BPF_A 0x10
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
/* BPF_MISC */
|
|
Packit |
56e23f |
#define BPF_MISCOP(code) ((code) & 0xf8)
|
|
Packit |
56e23f |
#define BPF_TAX 0x00
|
|
Packit |
56e23f |
#define BPF_TXA 0x80
|
|
Packit |
56e23f |
|
|
Packit |
56e23f |
#endif
|