Expand description
Linux kernel ABI data for x86_64 and seccomp profiles that make a modern
kernel answer like a selected older kernel: ENOSYS for every syscall it
lacks, and EINVAL for madvise advice values it does not know.
Two runners apply the simulation (see Runner): local installs a
BPF filter built by filter and runs the program on the host, and
container runs it in an image under the equivalent OCI profile.
The profiles are a testing aid, not a security boundary: everything the simulated kernel has is allowed. Other newer flags on old syscalls and behavior changes are not modelled yet; see the roadmap.
Modules§
- container
- Runs a program in a container whose seccomp profile simulates a kernel.
- filter
- Classic-BPF seccomp filters built directly from the data, for the local runner: no container, no libseccomp, and no root.
- local
- Runs a program on the host under a seccomp filter that simulates a kernel.
Structs§
- Distro
- A distribution preset: a kernel floor, a glibc floor, and a test image.
- Madvise
Advice - One
madviseadvice value and the first mainline release defining it. - Syscall
- One x86_64 syscall and the first mainline release whose table lists it.
- Target
- What a profile simulates.
Enums§
- Runner
- How a program runs under a simulated kernel.
Constants§
- EINVAL
EINVALon Linux (all architectures).- ENOSYS
ENOSYSon Linux (all architectures).- GENERIC_
KERNELS - Kernel releases shipped as generic profiles. Chosen to cover the kernels
of the
linux-targetsdistribution presets plus common LTS lines. - PROVIDER_
FORMAT - Version of the profile format this crate emits (named in each profile).
Functions§
- distro
- The preset with this id.
- distros
- All distribution presets from
data/distros.tsv. - madvise_
accepts - Whether
kernelacceptsmadviseadvicevalue. Unknown values are rejected withEINVALby every kernel. - madvise_
advice - All
madviseadvice values known to the data, ordered by value. - missing_
syscalls - Syscalls missing from
kernel, minus any names inallow(backports). - present_
syscalls - Syscalls
targetprovides: those in its mainline release plus backports. - seccomp_
profile - An OCI/Docker/Podman seccomp profile that allows only the syscalls
targetprovides, answersENOSYSfor every other syscall, and answersEINVALformadviseadvice valuestargetdoes not know. - syscalls
- All x86_64 (64-bit ABI) syscalls, ordered by number.
- table_
ceiling - The newest release scanned for the data (from its
# Tags scanned:header), which can be newer than the last release that added a syscall. - table_
floor - The oldest release in the data. Syscalls reported at this release may be older; kernels below it cannot be distinguished from it.
Type Aliases§
- Kernel
Version - A mainline Linux kernel release.