Skip to main content

Filter

Struct Filter 

Source
pub struct Filter { /* private fields */ }
Expand description

Seccomp-BPF program byte code.

Implementations§

Source§

impl Filter

Source

pub const fn new() -> Self

Creates a new, empty seccomp program. Note that empty BPF programs are not valid and will fail to load.

Source

pub fn push(&mut self, instruction: sock_filter)

Appends a single instruction to the seccomp-BPF program.

Source

pub fn len(&self) -> usize

Returns the number of instructions in the BPF program.

Source

pub fn is_empty(&self) -> bool

Returns true if the program is empty. Empty seccomp filters will result in an error when loaded.

Source

pub fn instructions(&self) -> &[sock_filter]

Returns the program’s instructions, in order, exactly as they would be loaded.

Source

pub fn load(&self) -> Result<(), Errno>

Loads the program via seccomp into the current process.

Once loaded, the seccomp filter can never be removed. Additional seccomp filters can be loaded, however, and they will chain together and be executed in reverse order.

NOTE: The maximum size of any single seccomp-bpf filter is 4096 instructions. The overall limit is 32768 instructions across all loaded filters.

See seccomp(2) for more details.

Source

pub fn load_and_listen(&self) -> Result<Fd, Errno>

This is the same as Filter::load except that it returns a file descriptor. This is meant to be used with seccomp_unotify(2).

Trait Implementations§

Source§

impl Clone for Filter

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Filter

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Filter

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl Eq for Filter

Source§

impl Extend<sock_filter> for Filter

Source§

fn extend<T: IntoIterator<Item = sock_filter>>(&mut self, iter: T)

Extends a collection with the contents of an iterator. Read more
Source§

fn extend_one(&mut self, item: T)

🔬This is a nightly-only experimental API. (extend_one)
Extends a collection with exactly one element.
Source§

fn extend_reserve(&mut self, additional: usize)

🔬This is a nightly-only experimental API. (extend_one)
Reserves capacity in a collection for the given number of additional elements. Read more
Source§

impl PartialEq for Filter

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for Filter

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.