mirror of
https://github.com/systemd/systemd.git
synced 2026-08-08 17:10:55 +00:00
seccomp: split out inner loop code of seccomp_add_syscall_filter_set()
Let's add a new helper function seccomp_add_syscall_filter_item() that contains the inner loop code of seccomp_add_syscall_filter_set(). This helper function we can then export and make use of elsewhere.
This commit is contained in:
@@ -682,6 +682,40 @@ const SyscallFilterSet *syscall_filter_set_find(const char *name) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
static int seccomp_add_syscall_filter_set(scmp_filter_ctx seccomp, const SyscallFilterSet *set, uint32_t action);
|
||||
|
||||
int seccomp_add_syscall_filter_item(scmp_filter_ctx *seccomp, const char *name, uint32_t action) {
|
||||
int r;
|
||||
|
||||
assert(seccomp);
|
||||
assert(name);
|
||||
|
||||
if (name[0] == '@') {
|
||||
const SyscallFilterSet *other;
|
||||
|
||||
other = syscall_filter_set_find(name);
|
||||
if (!other)
|
||||
return -EINVAL;
|
||||
|
||||
r = seccomp_add_syscall_filter_set(seccomp, other, action);
|
||||
if (r < 0)
|
||||
return r;
|
||||
} else {
|
||||
int id;
|
||||
|
||||
id = seccomp_syscall_resolve_name(name);
|
||||
if (id == __NR_SCMP_ERROR)
|
||||
return -EINVAL; /* Not known at all? Then that's a real error */
|
||||
|
||||
r = seccomp_rule_add_exact(seccomp, action, id, 0);
|
||||
if (r < 0)
|
||||
/* If the system call is not known on this architecture, then that's fine, let's ignore it */
|
||||
log_debug_errno(r, "Failed to add rule for system call %s() / %d, ignoring: %m", name, id);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
static int seccomp_add_syscall_filter_set(
|
||||
scmp_filter_ctx seccomp,
|
||||
const SyscallFilterSet *set,
|
||||
@@ -694,28 +728,9 @@ static int seccomp_add_syscall_filter_set(
|
||||
assert(set);
|
||||
|
||||
NULSTR_FOREACH(sys, set->value) {
|
||||
int id;
|
||||
|
||||
if (sys[0] == '@') {
|
||||
const SyscallFilterSet *other;
|
||||
|
||||
other = syscall_filter_set_find(sys);
|
||||
if (!other)
|
||||
return -EINVAL;
|
||||
|
||||
r = seccomp_add_syscall_filter_set(seccomp, other, action);
|
||||
if (r < 0)
|
||||
return r;
|
||||
} else {
|
||||
id = seccomp_syscall_resolve_name(sys);
|
||||
if (id == __NR_SCMP_ERROR)
|
||||
return -EINVAL; /* Not known at all? Then that's a real error */
|
||||
|
||||
r = seccomp_rule_add_exact(seccomp, action, id, 0);
|
||||
if (r < 0)
|
||||
/* If the system call is not known on this architecture, then that's fine, let's ignore it */
|
||||
log_debug_errno(r, "Failed to add rule for system call %s() / %d, ignoring: %m", sys, id);
|
||||
}
|
||||
r = seccomp_add_syscall_filter_item(seccomp, sys, action);
|
||||
if (r < 0)
|
||||
return r;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
@@ -69,6 +69,8 @@ const SyscallFilterSet *syscall_filter_set_find(const char *name);
|
||||
|
||||
int seccomp_filter_set_add(Set *s, bool b, const SyscallFilterSet *set);
|
||||
|
||||
int seccomp_add_syscall_filter_item(scmp_filter_ctx *ctx, const char *name, uint32_t action);
|
||||
|
||||
int seccomp_load_syscall_filter_set(uint32_t default_action, const SyscallFilterSet *set, uint32_t action);
|
||||
int seccomp_load_syscall_filter_set_raw(uint32_t default_action, Set* set, uint32_t action);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user