tor/src/common/sandbox.h

94 lines
1.5 KiB
C
Raw Normal View History

/* Copyright (c) 2001 Matej Pfajfar.
* Copyright (c) 2001-2004, Roger Dingledine.
* Copyright (c) 2004-2006, Roger Dingledine, Nick Mathewson.
* Copyright (c) 2007-2013, The Tor Project, Inc. */
/* See LICENSE for licensing information */
/**
* \file sandbox.h
* \brief Header file for sandbox.c.
**/
#ifndef SANDBOX_H_
#define SANDBOX_H_
#ifndef SYS_SECCOMP
/**
* Used by SIGSYS signal handler to check if the signal was issued due to a
* seccomp2 filter violation.
*/
#define SYS_SECCOMP 1
#endif
2013-07-23 09:14:25 +02:00
#include "torint.h"
/**
* Linux definitions
*/
#ifdef __linux__
2013-07-29 15:30:39 +02:00
#ifndef __USE_GNU
#define __USE_GNU
2013-07-29 15:30:39 +02:00
#endif
#include <sys/ucontext.h>
#define MAX_PARAM_LEN 64
#define PARAM_PTR 0
#define PARAM_NUM 1
typedef struct {
int syscall;
char ptype;
2013-07-23 13:22:31 +02:00
char pindex;
intptr_t param;
char prot;
} sandbox_static_cfg_t;
struct pfd_elem {
int syscall;
char ptype;
char pindex;
intptr_t param;
char prot;
struct pfd_elem *next;
};
typedef struct pfd_elem sandbox_cfg_t;
/**
* Linux 32 bit definitions
*/
#if defined(__i386__)
#define REG_SYSCALL REG_EAX
/**
* Linux 64 bit definitions
*/
#elif defined(__x86_64__)
#define REG_SYSCALL REG_RAX
#endif
#endif // __linux__
void sandbox_set_debugging_fd(int fd);
int tor_global_sandbox(void);
2013-07-29 15:30:39 +02:00
const char* sandbox_intern_string(const char *param);
2013-07-25 13:08:02 +02:00
sandbox_cfg_t * sandbox_cfg_new();
int sandbox_cfg_allow_open_filename(sandbox_cfg_t **cfg, char *file);
int sandbox_cfg_allow_openat_filename(sandbox_cfg_t **cfg, char *file);
2013-07-25 13:08:02 +02:00
int sandbox_init(sandbox_cfg_t* cfg);
#endif /* SANDBOX_H_ */