aboutsummaryrefslogtreecommitdiffstats
path: root/src/firejail/firejail.h
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2015-10-27 08:51:41 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2015-10-27 08:51:41 -0400
commita1ea3e726196e5fa54950ebd0f88d25b6e9fe98c (patch)
treeddee416d477a40373ad81d7e07a9228965a53e1c /src/firejail/firejail.h
parentsyscall testing (diff)
downloadfirejail-a1ea3e726196e5fa54950ebd0f88d25b6e9fe98c.tar.gz
firejail-a1ea3e726196e5fa54950ebd0f88d25b6e9fe98c.tar.zst
firejail-a1ea3e726196e5fa54950ebd0f88d25b6e9fe98c.zip
seccomp refactoring
Diffstat (limited to 'src/firejail/firejail.h')
-rw-r--r--src/firejail/firejail.h10
1 files changed, 6 insertions, 4 deletions
diff --git a/src/firejail/firejail.h b/src/firejail/firejail.h
index ab2fedbd8..91bb420b6 100644
--- a/src/firejail/firejail.h
+++ b/src/firejail/firejail.h
@@ -107,6 +107,12 @@ typedef struct config_t {
107 uint32_t dns2; 107 uint32_t dns2;
108 uint32_t dns3; 108 uint32_t dns3;
109 109
110 // seccomp
111 char *seccomp_list;// optional seccomp list on top of default filter
112 char *seccomp_list_drop; // seccomp drop list
113 char *seccomp_list_keep; // seccomp keep list
114 char **seccomp_list_errno; // seccomp errno[nr] lists
115
110 // rlimits 116 // rlimits
111 unsigned rlimit_nofile; 117 unsigned rlimit_nofile;
112 unsigned rlimit_nproc; 118 unsigned rlimit_nproc;
@@ -152,10 +158,6 @@ extern int arg_zsh; // use zsh as default shell
152extern int arg_csh; // use csh as default shell 158extern int arg_csh; // use csh as default shell
153 159
154extern int arg_seccomp; // enable default seccomp filter 160extern int arg_seccomp; // enable default seccomp filter
155extern char *arg_seccomp_list;// optional seccomp list on top of default filter
156extern char *arg_seccomp_list_drop; // seccomp drop list
157extern char *arg_seccomp_list_keep; // seccomp keep list
158extern char **arg_seccomp_list_errno; // seccomp errno[nr] lists
159 161
160extern int arg_caps_default_filter; // enable default capabilities filter 162extern int arg_caps_default_filter; // enable default capabilities filter
161extern int arg_caps_drop; // drop list 163extern int arg_caps_drop; // drop list