Add arm64 support to pkg/seccomp

Signed-off-by: Bin Lu <bin.lu@arm.com>
PiperOrigin-RevId: 246622505
Change-Id: I803639a0c5b0f75959c64fee5385314214834d10
This commit is contained in:
Bin Lu
2019-05-03 22:03:59 -07:00
committed by Shentubot
parent bf0ac565d2
commit ebe2f78d9b
5 changed files with 56 additions and 7 deletions
+2
View File
@@ -22,6 +22,8 @@ go_library(
name = "seccomp",
srcs = [
"seccomp.go",
"seccomp_amd64.go",
"seccomp_arm64.go",
"seccomp_rules.go",
"seccomp_unsafe.go",
],
+2 -2
View File
@@ -123,11 +123,11 @@ func BuildProgram(rules []RuleSet, defaultAction linux.BPFAction) ([]linux.BPFIn
// Be paranoid and check that syscall is done in the expected architecture.
//
// A = seccomp_data.arch
// if (A != AUDIT_ARCH_X86_64) goto defaultAction.
// if (A != AUDIT_ARCH) goto defaultAction.
program.AddStmt(bpf.Ld|bpf.Abs|bpf.W, seccompDataOffsetArch)
// defaultLabel is at the bottom of the program. The size of program
// may exceeds 255 lines, which is the limit of a condition jump.
program.AddJump(bpf.Jmp|bpf.Jeq|bpf.K, linux.AUDIT_ARCH_X86_64, skipOneInst, 0)
program.AddJump(bpf.Jmp|bpf.Jeq|bpf.K, LINUX_AUDIT_ARCH, skipOneInst, 0)
program.AddDirectJumpLabel(defaultLabel)
if err := buildIndex(rules, program); err != nil {
return nil, err
+26
View File
@@ -0,0 +1,26 @@
// Copyright 2018 The gVisor Authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
// +build amd64
package seccomp
import (
"gvisor.googlesource.com/gvisor/pkg/abi/linux"
)
const (
LINUX_AUDIT_ARCH = linux.AUDIT_ARCH_X86_64
SYS_SECCOMP = 317
)
+26
View File
@@ -0,0 +1,26 @@
// Copyright 2018 The gVisor Authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
// +build arm64
package seccomp
import (
"gvisor.googlesource.com/gvisor/pkg/abi/linux"
)
const (
LINUX_AUDIT_ARCH = linux.AUDIT_ARCH_AARCH64
SYS_SECCOMP = 277
)
-5
View File
@@ -12,8 +12,6 @@
// See the License for the specific language governing permissions and
// limitations under the License.
// +build amd64
package seccomp
import (
@@ -65,9 +63,6 @@ func isKillProcessAvailable() (bool, error) {
//
//go:nosplit
func seccomp(op, flags uint32, ptr unsafe.Pointer) syscall.Errno {
// SYS_SECCOMP is not available in syscall package.
const SYS_SECCOMP = 317
if _, _, errno := syscall.RawSyscall(SYS_SECCOMP, uintptr(op), uintptr(flags), uintptr(ptr)); errno != 0 {
return errno
}