aa3f96c9c4
Enabling seccomp across all processes, rather than just zygote, is useful for auditing the syscall usage of AOSP. Create a global seccomp policy that can optionally be enabled by init. Bug: 37960259 Test: confirm global seccomp by removing finit_module from policy and observing modprobe fail, confirm regular seccomp unchanged by comparing length of installed bpf Change-Id: Iac53a42fa26a80b05126f262dd9525f4f66df558
97 lines
6.5 KiB
C++
97 lines
6.5 KiB
C++
// Autogenerated file - edit at your peril!!
|
|
|
|
#include <linux/filter.h>
|
|
#include <errno.h>
|
|
|
|
#include "seccomp_bpfs.h"
|
|
const sock_filter mips64_global_filter[] = {
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5000, 0, 86),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5168, 43, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5077, 21, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5034, 11, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5008, 5, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5005, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5003, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5002, 79, 78), //read|write
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5004, 78, 77), //close
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5006, 77, 76), //fstat
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5031, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5023, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5020, 74, 73), //lseek|mmap|mprotect|munmap|brk|rt_sigaction|rt_sigprocmask|ioctl|pread64|pwrite64|readv|writev
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5028, 73, 72), //sched_yield|mremap|msync|mincore|madvise
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5032, 72, 71), //dup
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5057, 5, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5043, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5038, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5037, 68, 67), //nanosleep|getitimer|setitimer
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5042, 67, 66), //getpid|sendfile|socket|connect
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5056, 66, 65), //sendto|recvfrom|sendmsg|recvmsg|shutdown|bind|listen|getsockname|getpeername|socketpair|setsockopt|getsockopt|clone
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5070, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5062, 64, 63), //execve|exit|wait4|kill|uname
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5076, 63, 62), //fcntl|flock|fsync|fdatasync|truncate|ftruncate
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5134, 11, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5093, 5, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5091, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5089, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5080, 58, 57), //getcwd|chdir|fchdir
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5090, 57, 56), //fchmod
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5092, 56, 55), //fchown
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5132, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5110, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5109, 53, 52), //umask|gettimeofday|getrlimit|getrusage|sysinfo|times|ptrace|getuid|syslog|getgid|setuid|setgid|geteuid|getegid|setpgid|getppid
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5130, 52, 51), //setsid|setreuid|setregid|getgroups|setgroups|setresuid|getresuid|setresgid|getresgid|getpgid|setfsuid|setfsgid|getsid|capget|capset|rt_sigpending|rt_sigtimedwait|rt_sigqueueinfo|rt_sigsuspend|sigaltstack
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5133, 51, 50), //personality
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5153, 5, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5151, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5137, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5136, 47, 46), //statfs|fstatfs
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5150, 46, 45), //getpriority|setpriority|sched_setparam|sched_getparam|sched_setscheduler|sched_getscheduler|sched_get_priority_max|sched_get_priority_min|sched_rr_get_interval|mlock|munlock|mlockall|munlockall
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5152, 45, 44), //pivot_root
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5164, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5163, 43, 42), //prctl|adjtimex|setrlimit|chroot|sync|acct|settimeofday|mount|umount2|swapon
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5167, 42, 41), //reboot|sethostname|setdomainname
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5244, 21, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5211, 11, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5194, 5, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5178, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5172, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5170, 36, 35), //init_module|delete_module
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5173, 35, 34), //quotactl
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5193, 34, 33), //gettid|readahead|setxattr|lsetxattr|fsetxattr|getxattr|lgetxattr|fgetxattr|listxattr|llistxattr|flistxattr|removexattr|lremovexattr|fremovexattr|tkill
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5208, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5205, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5198, 31, 30), //futex|sched_setaffinity|sched_getaffinity|cacheflush
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5206, 30, 29), //exit_group
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5209, 29, 28), //epoll_ctl
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5239, 5, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5237, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5215, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5214, 25, 24), //rt_sigreturn|set_tid_address|restart_syscall
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5226, 24, 23), //fadvise64|timer_create|timer_settime|timer_gettime|timer_getoverrun|timer_delete|clock_settime|clock_gettime|clock_getres|clock_nanosleep|tgkill
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5238, 23, 22), //waitid
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5241, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5240, 21, 20), //add_key
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5243, 20, 19), //keyctl|set_thread_area
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5297, 9, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5271, 5, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5252, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5247, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5246, 15, 14), //inotify_add_watch|inotify_rm_watch
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5251, 14, 13), //openat|mkdirat|mknodat|fchownat
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5267, 13, 12), //newfstatat|unlinkat|renameat|linkat|symlinkat|readlinkat|fchmodat|faccessat|pselect6|ppoll|unshare|splice|sync_file_range|tee|vmsplice
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5279, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5276, 11, 10), //getcpu|epoll_pwait|ioprio_set|ioprio_get|utimensat
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5295, 10, 9), //fallocate|timerfd_create|timerfd_gettime|timerfd_settime|signalfd4|eventfd2|epoll_create1|dup3|pipe2|inotify_init1|preadv|pwritev|rt_tgsigqueueinfo|perf_event_open|accept4|recvmmsg
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5316, 5, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5307, 3, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5300, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5298, 6, 5), //prlimit64
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5306, 5, 4), //clock_adjtime|syncfs|sendmmsg|setns|process_vm_readv|process_vm_writev
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5315, 4, 3), //finit_module|getdents64|sched_setattr|sched_getattr|renameat2|seccomp|getrandom|memfd_create
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5319, 1, 0),
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5317, 2, 1), //execveat
|
|
BPF_JUMP(BPF_JMP|BPF_JGE|BPF_K, 5323, 1, 0), //mlock2|copy_file_range|preadv2|pwritev2
|
|
BPF_STMT(BPF_RET|BPF_K, SECCOMP_RET_ALLOW),
|
|
};
|
|
|
|
const size_t mips64_global_filter_size = sizeof(mips64_global_filter) / sizeof(struct sock_filter);
|