jail: improve seccomp BPF generator
authorDaniel Golle <daniel@makrotopia.org>
Sun, 29 Nov 2020 19:12:17 +0000 (19:12 +0000)
committerDaniel Golle <daniel@makrotopia.org>
Mon, 30 Nov 2020 00:25:43 +0000 (00:25 +0000)
commitf3c35632a105607007c7e46da7ce51fcffe7fbe9
tree37f387da893236a53a3166c8392d3e4559a65b13
parent31e0a46ded22a517c03cb899f890207f0db75fb8
jail: improve seccomp BPF generator

Restructure and add code to process rules based on syscall arguments as
defined in OCI run-tine spec. Generated BPF code became more efficient
as now only one BPF instruction for each syscall is required.

Signed-off-by: Daniel Golle <daniel@makrotopia.org>
jail/seccomp-bpf.h
jail/seccomp-oci.c