Skip to main content

seccomp_profile

Function seccomp_profile 

Source
pub fn seccomp_profile(target: &Target) -> String
Expand description

An OCI/Docker/Podman seccomp profile that allows only the syscalls target provides, answers ENOSYS for every other syscall, and answers EINVAL for madvise advice values target does not know.

The profile is an allowlist on purpose. Container runtimes resolve names with their own libseccomp and silently drop names it does not know, so a blocklist fails open for exactly the newest syscalls. With an allowlist an unknown name stays blocked (and syscall-probe reports it), and syscalls newer than this crate’s data are blocked too.

madvise gets one rule per advice value from 0 to the highest known value, plus one for anything above it, so no two rules overlap and the result never depends on how a runtime orders conflicting rules. Values are compared on the low 32 bits because the kernel reads an int.