Skip to main content

Crate kernel_abi_tools

Crate kernel_abi_tools 

Source
Expand description

Linux kernel ABI data for x86_64 and seccomp profiles that make a modern kernel answer like a selected older kernel: ENOSYS for every syscall it lacks, and EINVAL for madvise advice values it does not know.

Two runners apply the simulation (see Runner): local installs a BPF filter built by filter and runs the program on the host, and container runs it in an image under the equivalent OCI profile.

The profiles are a testing aid, not a security boundary: everything the simulated kernel has is allowed. Other newer flags on old syscalls and behavior changes are not modelled yet; see the roadmap.

Modules§

container
Runs a program in a container whose seccomp profile simulates a kernel.
filter
Classic-BPF seccomp filters built directly from the data, for the local runner: no container, no libseccomp, and no root.
local
Runs a program on the host under a seccomp filter that simulates a kernel.

Structs§

Distro
A distribution preset: a kernel floor, a glibc floor, and a test image.
MadviseAdvice
One madvise advice value and the first mainline release defining it.
Syscall
One x86_64 syscall and the first mainline release whose table lists it.
Target
What a profile simulates.

Enums§

Runner
How a program runs under a simulated kernel.

Constants§

EINVAL
EINVAL on Linux (all architectures).
ENOSYS
ENOSYS on Linux (all architectures).
GENERIC_KERNELS
Kernel releases shipped as generic profiles. Chosen to cover the kernels of the linux-targets distribution presets plus common LTS lines.
PROVIDER_FORMAT
Version of the profile format this crate emits (named in each profile).

Functions§

distro
The preset with this id.
distros
All distribution presets from data/distros.tsv.
madvise_accepts
Whether kernel accepts madvise advice value. Unknown values are rejected with EINVAL by every kernel.
madvise_advice
All madvise advice values known to the data, ordered by value.
missing_syscalls
Syscalls missing from kernel, minus any names in allow (backports).
present_syscalls
Syscalls target provides: those in its mainline release plus backports.
seccomp_profile
An OCI/Docker/Podman seccomp profile that allows only the syscalls target provides, answers ENOSYS for every other syscall, and answers EINVAL for madvise advice values target does not know.
syscalls
All x86_64 (64-bit ABI) syscalls, ordered by number.
table_ceiling
The newest release scanned for the data (from its # Tags scanned: header), which can be newer than the last release that added a syscall.
table_floor
The oldest release in the data. Syscalls reported at this release may be older; kernels below it cannot be distinguished from it.

Type Aliases§

KernelVersion
A mainline Linux kernel release.