seacomb 0.3.2

A formally verified seccomp compiler.
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
//! Docker's default seccomp profile,
//! [`DefaultProfile`](https://github.com/moby/profiles/blob/seccomp/v0.2.3/seccomp/default_linux.go).

#![recursion_limit = "512"]

#[cfg(not(target_os = "linux"))]
fn main() {}

#[cfg(target_os = "linux")]
fn main() {
    use seacomb::*;
    use std::os::unix::process::CommandExt;

    let compat = match Arch::native().unwrap() {
        Arch::X86_64 => Arch::X86,
        Arch::Aarch64 => Arch::Arm,
        _ => unimplemented!(),
    };

    let policy = policy! {
        default errno(libc::EPERM as u16) on native, {compat};

        allow accept();
        allow accept4();
        allow access();
        allow adjtimex();
        allow alarm();
        allow bind();
        allow brk();
        allow cachestat();
        allow capget();
        allow capset();
        allow chdir();
        allow chmod();
        allow chown();
        allow chown32();
        allow clock_adjtime();
        allow clock_adjtime64();
        allow clock_getres();
        allow clock_getres_time64();
        allow clock_gettime();
        allow clock_gettime64();
        allow clock_nanosleep();
        allow clock_nanosleep_time64();
        allow close();
        allow close_range();
        allow connect();
        allow copy_file_range();
        allow creat();
        allow dup();
        allow dup2();
        allow dup3();
        allow epoll_create();
        allow epoll_create1();
        allow epoll_ctl();
        allow epoll_ctl_old();
        allow epoll_pwait();
        allow epoll_pwait2();
        allow epoll_wait();
        allow epoll_wait_old();
        allow eventfd();
        allow eventfd2();
        allow execve();
        allow execveat();
        allow exit();
        allow exit_group();
        allow faccessat();
        allow faccessat2();
        allow fadvise64();
        allow fadvise64_64();
        allow fallocate();
        allow fanotify_mark();
        allow fchdir();
        allow fchmod();
        allow fchmodat();
        allow fchmodat2();
        allow fchown();
        allow fchown32();
        allow fchownat();
        allow fcntl();
        allow fcntl64();
        allow fdatasync();
        allow fgetxattr();
        allow flistxattr();
        allow flock();
        allow fork();
        allow fremovexattr();
        allow fsetxattr();
        allow fstat();
        allow fstat64();
        allow fstatat64();
        allow fstatfs();
        allow fstatfs64();
        allow fsync();
        allow ftruncate();
        allow ftruncate64();
        allow futex();
        allow futex_requeue();
        allow futex_time64();
        allow futex_wait();
        allow futex_waitv();
        allow futex_wake();
        allow futimesat();
        allow getcpu();
        allow getcwd();
        allow getdents();
        allow getdents64();
        allow getegid();
        allow getegid32();
        allow geteuid();
        allow geteuid32();
        allow getgid();
        allow getgid32();
        allow getgroups();
        allow getgroups32();
        allow getitimer();
        allow getpeername();
        allow getpgid();
        allow getpgrp();
        allow getpid();
        allow getppid();
        allow getpriority();
        allow getrandom();
        allow getresgid();
        allow getresgid32();
        allow getresuid();
        allow getresuid32();
        allow getrlimit();
        allow get_robust_list();
        allow getrusage();
        allow getsid();
        allow getsockname();
        allow getsockopt();
        allow get_thread_area();
        allow gettid();
        allow gettimeofday();
        allow getuid();
        allow getuid32();
        allow getxattr();
        allow getxattrat();
        allow inotify_add_watch();
        allow inotify_init();
        allow inotify_init1();
        allow inotify_rm_watch();
        allow io_cancel();
        allow ioctl();
        allow io_destroy();
        allow io_getevents();
        allow io_pgetevents();
        allow io_pgetevents_time64();
        allow ioprio_get();
        allow ioprio_set();
        allow io_setup();
        allow io_submit();
        allow ipc();
        allow kill();
        allow landlock_add_rule();
        allow landlock_create_ruleset();
        allow landlock_restrict_self();
        allow lchown();
        allow lchown32();
        allow lgetxattr();
        allow link();
        allow linkat();
        allow listen();
        allow listmount();
        allow listxattr();
        allow listxattrat();
        allow llistxattr();
        allow _llseek();
        allow lremovexattr();
        allow lseek();
        allow lsetxattr();
        allow lstat();
        allow lstat64();
        allow madvise();
        allow map_shadow_stack();
        allow membarrier();
        allow memfd_create();
        allow memfd_secret();
        allow mincore();
        allow mkdir();
        allow mkdirat();
        allow mknod();
        allow mknodat();
        allow mlock();
        allow mlock2();
        allow mlockall();
        allow mmap();
        allow mmap2();
        allow mprotect();
        allow mq_getsetattr();
        allow mq_notify();
        allow mq_open();
        allow mq_timedreceive();
        allow mq_timedreceive_time64();
        allow mq_timedsend();
        allow mq_timedsend_time64();
        allow mq_unlink();
        allow mremap();
        allow mseal();
        allow msgctl();
        allow msgget();
        allow msgrcv();
        allow msgsnd();
        allow msync();
        allow munlock();
        allow munlockall();
        allow munmap();
        allow name_to_handle_at();
        allow nanosleep();
        allow newfstatat();
        allow _newselect();
        allow open();
        allow openat();
        allow openat2();
        allow pause();
        allow pidfd_open();
        allow pidfd_send_signal();
        allow pipe();
        allow pipe2();
        allow pkey_alloc();
        allow pkey_free();
        allow pkey_mprotect();
        allow poll();
        allow ppoll();
        allow ppoll_time64();
        allow prctl();
        allow pread64();
        allow preadv();
        allow preadv2();
        allow prlimit64();
        allow process_mrelease();
        allow pselect6();
        allow pselect6_time64();
        allow pwrite64();
        allow pwritev();
        allow pwritev2();
        allow read();
        allow readahead();
        allow readlink();
        allow readlinkat();
        allow readv();
        allow recv();
        allow recvfrom();
        allow recvmmsg();
        allow recvmmsg_time64();
        allow recvmsg();
        allow remap_file_pages();
        allow removexattr();
        allow removexattrat();
        allow rename();
        allow renameat();
        allow renameat2();
        allow restart_syscall();
        allow rmdir();
        allow rseq();
        allow rt_sigaction();
        allow rt_sigpending();
        allow rt_sigprocmask();
        allow rt_sigqueueinfo();
        allow rt_sigreturn();
        allow rt_sigsuspend();
        allow rt_sigtimedwait();
        allow rt_sigtimedwait_time64();
        allow rt_tgsigqueueinfo();
        allow sched_getaffinity();
        allow sched_getattr();
        allow sched_getparam();
        allow sched_get_priority_max();
        allow sched_get_priority_min();
        allow sched_getscheduler();
        allow sched_rr_get_interval();
        allow sched_rr_get_interval_time64();
        allow sched_setaffinity();
        allow sched_setattr();
        allow sched_setparam();
        allow sched_setscheduler();
        allow sched_yield();
        allow seccomp();
        allow select();
        allow semctl();
        allow semget();
        allow semop();
        allow semtimedop();
        allow semtimedop_time64();
        allow send();
        allow sendfile();
        allow sendfile64();
        allow sendmmsg();
        allow sendmsg();
        allow sendto();
        allow setfsgid();
        allow setfsgid32();
        allow setfsuid();
        allow setfsuid32();
        allow setgid();
        allow setgid32();
        allow setgroups();
        allow setgroups32();
        allow setitimer();
        allow setpgid();
        allow setpriority();
        allow setregid();
        allow setregid32();
        allow setresgid();
        allow setresgid32();
        allow setresuid();
        allow setresuid32();
        allow setreuid();
        allow setreuid32();
        allow setrlimit();
        allow set_robust_list();
        allow setsid();
        allow setsockopt();
        allow set_thread_area();
        allow set_tid_address();
        allow setuid();
        allow setuid32();
        allow setxattr();
        allow setxattrat();
        allow shmat();
        allow shmctl();
        allow shmdt();
        allow shmget();
        allow shutdown();
        allow sigaltstack();
        allow signalfd();
        allow signalfd4();
        allow sigprocmask();
        allow sigreturn();
        allow socketcall();
        allow socketpair();
        allow splice();
        allow stat();
        allow stat64();
        allow statfs();
        allow statfs64();
        allow statmount();
        allow statx();
        allow symlink();
        allow symlinkat();
        allow sync();
        allow sync_file_range();
        allow syncfs();
        allow sysinfo();
        allow tee();
        allow tgkill();
        allow time();
        allow timer_create();
        allow timer_delete();
        allow timer_getoverrun();
        allow timer_gettime();
        allow timer_gettime64();
        allow timer_settime();
        allow timer_settime64();
        allow timerfd_create();
        allow timerfd_gettime();
        allow timerfd_gettime64();
        allow timerfd_settime();
        allow timerfd_settime64();
        allow times();
        allow tkill();
        allow truncate();
        allow truncate64();
        allow ugetrlimit();
        allow umask();
        allow uname();
        allow unlink();
        allow unlinkat();
        allow uretprobe();
        allow utime();
        allow utimensat();
        allow utimensat_time64();
        allow utimes();
        allow vfork();
        allow vmsplice();
        allow wait4();
        allow waitid();
        allow waitpid();
        allow write();
        allow writev();

        allow process_vm_readv();
        allow process_vm_writev();
        allow ptrace();

        allow exact socket(domain) if domain != {libc::AF_ALG} && domain != {libc::AF_VSOCK};

        allow personality(persona) if persona == 0x0u32 || persona == 0x0008u32
            || persona == 0x20000u32 || persona == 0x20008u32 || persona == 0xffff_ffffu32;

        allow arm_fadvise64_64();
        allow arm_sync_file_range();
        allow breakpoint();
        allow cacheflush();
        allow set_tls();

        allow arch_prctl();

        allow modify_ldt();

        [native] allow clone(flags) if
            flags & {libc::CLONE_NEWNS | libc::CLONE_NEWUTS | libc::CLONE_NEWIPC |
                    libc::CLONE_NEWUSER | libc::CLONE_NEWPID | libc::CLONE_NEWNET |
                    libc::CLONE_NEWCGROUP} as usize == 0usize;
        [{compat}] allow clone(flags) if
            flags & {libc::CLONE_NEWNS | libc::CLONE_NEWUTS | libc::CLONE_NEWIPC |
                    libc::CLONE_NEWUSER | libc::CLONE_NEWPID | libc::CLONE_NEWNET |
                    libc::CLONE_NEWCGROUP} as usize == 0usize;

        errno(libc::ENOSYS as u16) clone3();

        allow chroot();
    }.unwrap();

    policy.install().unwrap();
    let mut args = std::env::args_os().skip(1);
    if let Some(program) = args.next() {
        panic!("{}", std::process::Command::new(program).args(args).exec());
    }
}