Blame tools/bpf.h

Packit 56e23f
/**
Packit 56e23f
 * BPF Language Definitions
Packit 56e23f
 *
Packit 56e23f
 * Copyright (c) 2012 Red Hat <pmoore@redhat.com>
Packit 56e23f
 * Author: Paul Moore <paul@paul-moore.com>
Packit 56e23f
 */
Packit 56e23f
Packit 56e23f
/*
Packit 56e23f
 * This library is free software; you can redistribute it and/or modify it
Packit 56e23f
 * under the terms of version 2.1 of the GNU Lesser General Public License as
Packit 56e23f
 * published by the Free Software Foundation.
Packit 56e23f
 *
Packit 56e23f
 * This library is distributed in the hope that it will be useful, but WITHOUT
Packit 56e23f
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
Packit 56e23f
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Lesser General Public License
Packit 56e23f
 * for more details.
Packit 56e23f
 *
Packit 56e23f
 * You should have received a copy of the GNU Lesser General Public License
Packit 56e23f
 * along with this library; if not, see <http://www.gnu.org/licenses>.
Packit 56e23f
 */
Packit 56e23f
Packit 56e23f
#ifndef _BPF_H
Packit 56e23f
#define _BPF_H
Packit 56e23f
Packit 56e23f
#include <inttypes.h>
Packit 56e23f
#include <stddef.h>
Packit 56e23f
Packit 56e23f
/* most of these structures and values are designed to match the Linux Kernel's
Packit 56e23f
 * BPF interface (see /usr/include/linux/{filter,seccomp}.h), but we define our
Packit 56e23f
 * own here so that we can function independent of the host OS */
Packit 56e23f
Packit 56e23f
/* XXX - need to verify these values */
Packit 56e23f
#define BPF_SCRATCH_SIZE	6
Packit 56e23f
Packit 56e23f
/**
Packit 56e23f
 * Syscall record data format used by seccomp
Packit 56e23f
 */
Packit 56e23f
#define BPF_SYS_ARG_MAX		6
Packit 56e23f
struct seccomp_data {
Packit 56e23f
	int32_t nr;
Packit 56e23f
	uint32_t arch;
Packit 56e23f
	uint64_t instruction_pointer;
Packit 56e23f
	uint64_t args[BPF_SYS_ARG_MAX];
Packit 56e23f
};
Packit 56e23f
#define BPF_SYSCALL_MAX		(sizeof(struct seccomp_data))
Packit 56e23f
Packit 56e23f
/**
Packit 56e23f
 * BPF instruction format
Packit 56e23f
 */
Packit 56e23f
struct sock_filter {
Packit 56e23f
	uint16_t code;
Packit 56e23f
	uint8_t jt;
Packit 56e23f
	uint8_t jf;
Packit 56e23f
	uint32_t k;
Packit 56e23f
} __attribute__ ((packed));
Packit 56e23f
typedef struct sock_filter bpf_instr_raw;
Packit 56e23f
Packit 56e23f
/* seccomp return masks */
Packit 56e23f
#define SECCOMP_RET_ACTION_FULL 0xffff0000U
Packit 56e23f
#define SECCOMP_RET_ACTION	0x7fff0000U
Packit 56e23f
#define SECCOMP_RET_DATA	0x0000ffffU
Packit 56e23f
Packit 56e23f
/* seccomp action values */
Packit 56e23f
#define SECCOMP_RET_KILL_PROCESS 0x80000000U
Packit 56e23f
#define SECCOMP_RET_KILL_THREAD 0x00000000U
Packit 56e23f
#define SECCOMP_RET_KILL	SECCOMP_RET_KILL_THREAD
Packit 56e23f
#define SECCOMP_RET_TRAP	0x00030000U
Packit 56e23f
#define SECCOMP_RET_ERRNO	0x00050000U
Packit 56e23f
#define SECCOMP_RET_TRACE	0x7ff00000U
Packit 56e23f
#define SECCOMP_RET_LOG		0x7ffc0000U
Packit 56e23f
#define SECCOMP_RET_ALLOW	0x7fff0000U
Packit 56e23f
Packit 56e23f
/* bpf command classes */
Packit 56e23f
#define BPF_CLASS(code)		((code) & 0x07)
Packit 56e23f
#define BPF_LD			0x00
Packit 56e23f
#define BPF_LDX			0x01
Packit 56e23f
#define BPF_ST			0x02
Packit 56e23f
#define BPF_STX			0x03
Packit 56e23f
#define BPF_ALU			0x04
Packit 56e23f
#define BPF_JMP			0x05
Packit 56e23f
#define BPF_RET			0x06
Packit 56e23f
#define BPF_MISC		0x07
Packit 56e23f
Packit 56e23f
/* BPF_LD and BPF_LDX */
Packit 56e23f
#define BPF_SIZE(code)		((code) & 0x18)
Packit 56e23f
#define BPF_W			0x00
Packit 56e23f
#define BPF_H			0x08
Packit 56e23f
#define BPF_B			0x10
Packit 56e23f
#define BPF_MODE(code)		((code) & 0xe0)
Packit 56e23f
#define BPF_IMM			0x00
Packit 56e23f
#define BPF_ABS			0x20
Packit 56e23f
#define BPF_IND			0x40
Packit 56e23f
#define BPF_MEM			0x60
Packit 56e23f
#define BPF_LEN			0x80
Packit 56e23f
#define BPF_MSH			0xa0
Packit 56e23f
Packit 56e23f
#define BPF_OP(code)		((code) & 0xf0)
Packit 56e23f
/* BPF_ALU */
Packit 56e23f
#define BPF_ADD			0x00
Packit 56e23f
#define BPF_SUB			0x10
Packit 56e23f
#define BPF_MUL			0x20
Packit 56e23f
#define BPF_DIV			0x30
Packit 56e23f
#define BPF_OR			0x40
Packit 56e23f
#define BPF_AND			0x50
Packit 56e23f
#define BPF_LSH			0x60
Packit 56e23f
#define BPF_RSH			0x70
Packit 56e23f
#define BPF_NEG			0x80
Packit 56e23f
#define BPF_MOD			0x90
Packit 56e23f
#define BPF_XOR			0xa0
Packit 56e23f
Packit 56e23f
/* BPF_JMP */
Packit 56e23f
#define BPF_JA			0x00
Packit 56e23f
#define BPF_JEQ			0x10
Packit 56e23f
#define BPF_JGT			0x20
Packit 56e23f
#define BPF_JGE			0x30
Packit 56e23f
#define BPF_JSET		0x40
Packit 56e23f
Packit 56e23f
#define BPF_SRC(code)		((code) & 0x08)
Packit 56e23f
#define BPF_K			0x00
Packit 56e23f
#define BPF_X			0x08
Packit 56e23f
Packit 56e23f
/* BPF_RET (BPF_K and BPF_X also apply) */
Packit 56e23f
#define BPF_RVAL(code)		((code) & 0x18)
Packit 56e23f
#define BPF_A			0x10
Packit 56e23f
Packit 56e23f
/* BPF_MISC */
Packit 56e23f
#define BPF_MISCOP(code)	((code) & 0xf8)
Packit 56e23f
#define BPF_TAX			0x00
Packit 56e23f
#define BPF_TXA			0x80
Packit 56e23f
Packit 56e23f
#endif