#![recursion_limit = "512"]
#[cfg(not(target_os = "linux"))]
fn main() {}
#[cfg(target_os = "linux")]
fn main() {
use seacomb::*;
use std::os::unix::process::CommandExt;
let compat = match Arch::native().unwrap() {
Arch::X86_64 => Arch::X86,
Arch::Aarch64 => Arch::Arm,
_ => unimplemented!(),
};
let policy = policy! {
default errno(libc::EPERM as u16) on native, {compat};
allow accept();
allow accept4();
allow access();
allow adjtimex();
allow alarm();
allow bind();
allow brk();
allow cachestat();
allow capget();
allow capset();
allow chdir();
allow chmod();
allow chown();
allow chown32();
allow clock_adjtime();
allow clock_adjtime64();
allow clock_getres();
allow clock_getres_time64();
allow clock_gettime();
allow clock_gettime64();
allow clock_nanosleep();
allow clock_nanosleep_time64();
allow close();
allow close_range();
allow connect();
allow copy_file_range();
allow creat();
allow dup();
allow dup2();
allow dup3();
allow epoll_create();
allow epoll_create1();
allow epoll_ctl();
allow epoll_ctl_old();
allow epoll_pwait();
allow epoll_pwait2();
allow epoll_wait();
allow epoll_wait_old();
allow eventfd();
allow eventfd2();
allow execve();
allow execveat();
allow exit();
allow exit_group();
allow faccessat();
allow faccessat2();
allow fadvise64();
allow fadvise64_64();
allow fallocate();
allow fanotify_mark();
allow fchdir();
allow fchmod();
allow fchmodat();
allow fchmodat2();
allow fchown();
allow fchown32();
allow fchownat();
allow fcntl();
allow fcntl64();
allow fdatasync();
allow fgetxattr();
allow flistxattr();
allow flock();
allow fork();
allow fremovexattr();
allow fsetxattr();
allow fstat();
allow fstat64();
allow fstatat64();
allow fstatfs();
allow fstatfs64();
allow fsync();
allow ftruncate();
allow ftruncate64();
allow futex();
allow futex_requeue();
allow futex_time64();
allow futex_wait();
allow futex_waitv();
allow futex_wake();
allow futimesat();
allow getcpu();
allow getcwd();
allow getdents();
allow getdents64();
allow getegid();
allow getegid32();
allow geteuid();
allow geteuid32();
allow getgid();
allow getgid32();
allow getgroups();
allow getgroups32();
allow getitimer();
allow getpeername();
allow getpgid();
allow getpgrp();
allow getpid();
allow getppid();
allow getpriority();
allow getrandom();
allow getresgid();
allow getresgid32();
allow getresuid();
allow getresuid32();
allow getrlimit();
allow get_robust_list();
allow getrusage();
allow getsid();
allow getsockname();
allow getsockopt();
allow get_thread_area();
allow gettid();
allow gettimeofday();
allow getuid();
allow getuid32();
allow getxattr();
allow getxattrat();
allow inotify_add_watch();
allow inotify_init();
allow inotify_init1();
allow inotify_rm_watch();
allow io_cancel();
allow ioctl();
allow io_destroy();
allow io_getevents();
allow io_pgetevents();
allow io_pgetevents_time64();
allow ioprio_get();
allow ioprio_set();
allow io_setup();
allow io_submit();
allow ipc();
allow kill();
allow landlock_add_rule();
allow landlock_create_ruleset();
allow landlock_restrict_self();
allow lchown();
allow lchown32();
allow lgetxattr();
allow link();
allow linkat();
allow listen();
allow listmount();
allow listxattr();
allow listxattrat();
allow llistxattr();
allow _llseek();
allow lremovexattr();
allow lseek();
allow lsetxattr();
allow lstat();
allow lstat64();
allow madvise();
allow map_shadow_stack();
allow membarrier();
allow memfd_create();
allow memfd_secret();
allow mincore();
allow mkdir();
allow mkdirat();
allow mknod();
allow mknodat();
allow mlock();
allow mlock2();
allow mlockall();
allow mmap();
allow mmap2();
allow mprotect();
allow mq_getsetattr();
allow mq_notify();
allow mq_open();
allow mq_timedreceive();
allow mq_timedreceive_time64();
allow mq_timedsend();
allow mq_timedsend_time64();
allow mq_unlink();
allow mremap();
allow mseal();
allow msgctl();
allow msgget();
allow msgrcv();
allow msgsnd();
allow msync();
allow munlock();
allow munlockall();
allow munmap();
allow name_to_handle_at();
allow nanosleep();
allow newfstatat();
allow _newselect();
allow open();
allow openat();
allow openat2();
allow pause();
allow pidfd_open();
allow pidfd_send_signal();
allow pipe();
allow pipe2();
allow pkey_alloc();
allow pkey_free();
allow pkey_mprotect();
allow poll();
allow ppoll();
allow ppoll_time64();
allow prctl();
allow pread64();
allow preadv();
allow preadv2();
allow prlimit64();
allow process_mrelease();
allow pselect6();
allow pselect6_time64();
allow pwrite64();
allow pwritev();
allow pwritev2();
allow read();
allow readahead();
allow readlink();
allow readlinkat();
allow readv();
allow recv();
allow recvfrom();
allow recvmmsg();
allow recvmmsg_time64();
allow recvmsg();
allow remap_file_pages();
allow removexattr();
allow removexattrat();
allow rename();
allow renameat();
allow renameat2();
allow restart_syscall();
allow rmdir();
allow rseq();
allow rt_sigaction();
allow rt_sigpending();
allow rt_sigprocmask();
allow rt_sigqueueinfo();
allow rt_sigreturn();
allow rt_sigsuspend();
allow rt_sigtimedwait();
allow rt_sigtimedwait_time64();
allow rt_tgsigqueueinfo();
allow sched_getaffinity();
allow sched_getattr();
allow sched_getparam();
allow sched_get_priority_max();
allow sched_get_priority_min();
allow sched_getscheduler();
allow sched_rr_get_interval();
allow sched_rr_get_interval_time64();
allow sched_setaffinity();
allow sched_setattr();
allow sched_setparam();
allow sched_setscheduler();
allow sched_yield();
allow seccomp();
allow select();
allow semctl();
allow semget();
allow semop();
allow semtimedop();
allow semtimedop_time64();
allow send();
allow sendfile();
allow sendfile64();
allow sendmmsg();
allow sendmsg();
allow sendto();
allow setfsgid();
allow setfsgid32();
allow setfsuid();
allow setfsuid32();
allow setgid();
allow setgid32();
allow setgroups();
allow setgroups32();
allow setitimer();
allow setpgid();
allow setpriority();
allow setregid();
allow setregid32();
allow setresgid();
allow setresgid32();
allow setresuid();
allow setresuid32();
allow setreuid();
allow setreuid32();
allow setrlimit();
allow set_robust_list();
allow setsid();
allow setsockopt();
allow set_thread_area();
allow set_tid_address();
allow setuid();
allow setuid32();
allow setxattr();
allow setxattrat();
allow shmat();
allow shmctl();
allow shmdt();
allow shmget();
allow shutdown();
allow sigaltstack();
allow signalfd();
allow signalfd4();
allow sigprocmask();
allow sigreturn();
allow socketcall();
allow socketpair();
allow splice();
allow stat();
allow stat64();
allow statfs();
allow statfs64();
allow statmount();
allow statx();
allow symlink();
allow symlinkat();
allow sync();
allow sync_file_range();
allow syncfs();
allow sysinfo();
allow tee();
allow tgkill();
allow time();
allow timer_create();
allow timer_delete();
allow timer_getoverrun();
allow timer_gettime();
allow timer_gettime64();
allow timer_settime();
allow timer_settime64();
allow timerfd_create();
allow timerfd_gettime();
allow timerfd_gettime64();
allow timerfd_settime();
allow timerfd_settime64();
allow times();
allow tkill();
allow truncate();
allow truncate64();
allow ugetrlimit();
allow umask();
allow uname();
allow unlink();
allow unlinkat();
allow uretprobe();
allow utime();
allow utimensat();
allow utimensat_time64();
allow utimes();
allow vfork();
allow vmsplice();
allow wait4();
allow waitid();
allow waitpid();
allow write();
allow writev();
allow process_vm_readv();
allow process_vm_writev();
allow ptrace();
allow exact socket(domain) if domain != {libc::AF_ALG} && domain != {libc::AF_VSOCK};
allow personality(persona) if persona == 0x0u32 || persona == 0x0008u32
|| persona == 0x20000u32 || persona == 0x20008u32 || persona == 0xffff_ffffu32;
allow arm_fadvise64_64();
allow arm_sync_file_range();
allow breakpoint();
allow cacheflush();
allow set_tls();
allow arch_prctl();
allow modify_ldt();
[native] allow clone(flags) if
flags & {libc::CLONE_NEWNS | libc::CLONE_NEWUTS | libc::CLONE_NEWIPC |
libc::CLONE_NEWUSER | libc::CLONE_NEWPID | libc::CLONE_NEWNET |
libc::CLONE_NEWCGROUP} as usize == 0usize;
[{compat}] allow clone(flags) if
flags & {libc::CLONE_NEWNS | libc::CLONE_NEWUTS | libc::CLONE_NEWIPC |
libc::CLONE_NEWUSER | libc::CLONE_NEWPID | libc::CLONE_NEWNET |
libc::CLONE_NEWCGROUP} as usize == 0usize;
errno(libc::ENOSYS as u16) clone3();
allow chroot();
}.unwrap();
policy.install().unwrap();
let mut args = std::env::args_os().skip(1);
if let Some(program) = args.next() {
panic!("{}", std::process::Command::new(program).args(args).exec());
}
}