pub struct Filter { /* private fields */ }Expand description
Seccomp-BPF program byte code.
Implementations§
Source§impl Filter
impl Filter
Sourcepub const fn new() -> Self
pub const fn new() -> Self
Creates a new, empty seccomp program. Note that empty BPF programs are not valid and will fail to load.
Sourcepub fn push(&mut self, instruction: sock_filter)
pub fn push(&mut self, instruction: sock_filter)
Appends a single instruction to the seccomp-BPF program.
Sourcepub fn is_empty(&self) -> bool
pub fn is_empty(&self) -> bool
Returns true if the program is empty. Empty seccomp filters will result in an error when loaded.
Sourcepub fn instructions(&self) -> &[sock_filter]
pub fn instructions(&self) -> &[sock_filter]
Returns the program’s instructions, in order, exactly as they would be loaded.
Sourcepub fn load(&self) -> Result<(), Errno>
pub fn load(&self) -> Result<(), Errno>
Loads the program via seccomp into the current process.
Once loaded, the seccomp filter can never be removed. Additional seccomp filters can be loaded, however, and they will chain together and be executed in reverse order.
NOTE: The maximum size of any single seccomp-bpf filter is 4096 instructions. The overall limit is 32768 instructions across all loaded filters.
See seccomp(2)
for more details.
Sourcepub fn load_and_listen(&self) -> Result<Fd, Errno>
pub fn load_and_listen(&self) -> Result<Fd, Errno>
This is the same as Filter::load except that it returns a file
descriptor. This is meant to be used with
seccomp_unotify(2).
Trait Implementations§
impl Eq for Filter
Source§impl Extend<sock_filter> for Filter
impl Extend<sock_filter> for Filter
Source§fn extend<T: IntoIterator<Item = sock_filter>>(&mut self, iter: T)
fn extend<T: IntoIterator<Item = sock_filter>>(&mut self, iter: T)
Source§fn extend_one(&mut self, item: T)
fn extend_one(&mut self, item: T)
extend_one)Source§fn extend_reserve(&mut self, additional: usize)
fn extend_reserve(&mut self, additional: usize)
extend_one)