2 * BPF Language Definitions
4 * Copyright (c) 2012 Red Hat <pmoore@redhat.com>
5 * Author: Paul Moore <paul@paul-moore.com>
9 * This library is free software; you can redistribute it and/or modify it
10 * under the terms of version 2.1 of the GNU Lesser General Public License as
11 * published by the Free Software Foundation.
13 * This library is distributed in the hope that it will be useful, but WITHOUT
14 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
15 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public License
18 * You should have received a copy of the GNU Lesser General Public License
19 * along with this library; if not, see <http://www.gnu.org/licenses>.
28 /* most of these structures and values are designed to match the Linux Kernel's
29 * BPF interface (see /usr/include/linux/{filter,seccomp}.h), but we define our
30 * own here so that we can function independent of the host OS */
32 /* XXX - need to verify these values */
33 #define BPF_SCRATCH_SIZE 6
36 * Syscall record data format used by seccomp
38 #define BPF_SYS_ARG_MAX 6
42 uint64_t instruction_pointer
;
43 uint64_t args
[BPF_SYS_ARG_MAX
];
45 #define BPF_SYSCALL_MAX (sizeof(struct seccomp_data))
48 * BPF instruction format
55 } __attribute__ ((packed
));
56 typedef struct sock_filter bpf_instr_raw
;
58 /* seccomp return masks */
59 #define SECCOMP_RET_ACTION 0x7fff0000U
60 #define SECCOMP_RET_DATA 0x0000ffffU
62 /* seccomp action values */
63 #define SECCOMP_RET_KILL 0x00000000U
64 #define SECCOMP_RET_TRAP 0x00030000U
65 #define SECCOMP_RET_ERRNO 0x00050000U
66 #define SECCOMP_RET_TRACE 0x7ff00000U
67 #define SECCOMP_RET_ALLOW 0x7fff0000U
69 /* bpf command classes */
70 #define BPF_CLASS(code) ((code) & 0x07)
80 /* BPF_LD and BPF_LDX */
81 #define BPF_SIZE(code) ((code) & 0x18)
85 #define BPF_MODE(code) ((code) & 0xe0)
93 #define BPF_OP(code) ((code) & 0xf0)
109 #define BPF_JSET 0x40
111 #define BPF_SRC(code) ((code) & 0x08)
115 /* BPF_RET (BPF_K and BPF_X also apply) */
116 #define BPF_RVAL(code) ((code) & 0x18)
120 #define BPF_MISCOP(code) ((code) & 0xf8)