Elly Jones | cd7a904 | 2011-07-22 13:56:51 -0400 | [diff] [blame] | 1 | /* libminijail-private.h |
| 2 | * Copyright (c) 2011 The Chromium OS Authors. All rights reserved. |
| 3 | * Use of this source code is governed by a BSD-style license that can be |
| 4 | * found in the LICENSE file. |
| 5 | * |
| 6 | * Values shared between libminijailpreload and libminijail, but not visible to |
| 7 | * the outside world. |
| 8 | */ |
| 9 | |
| 10 | #ifndef LIBMINIJAIL_PRIVATE_H |
| 11 | #define LIBMINIJAIL_PRIVATE_H |
| 12 | |
Will Drewry | 6ac9112 | 2011-10-21 16:38:58 -0500 | [diff] [blame^] | 13 | /* Explicitly declare exported functions so that -fvisibility tricks |
| 14 | * can be used for testing and minimal symbol leakage occurs. |
| 15 | */ |
| 16 | #define API __attribute__ ((visibility("default"))) |
| 17 | |
Will Drewry | 2f54b6a | 2011-09-16 13:45:31 -0500 | [diff] [blame] | 18 | static const char *kFdEnvVar = "__MINIJAIL_FD"; |
Ben Chan | 541c7e5 | 2011-08-26 14:55:53 -0700 | [diff] [blame] | 19 | static const char *kLdPreloadEnvVar = "LD_PRELOAD"; |
Elly Jones | cd7a904 | 2011-07-22 13:56:51 -0400 | [diff] [blame] | 20 | |
Will Drewry | 32ac9f5 | 2011-08-18 21:36:27 -0500 | [diff] [blame] | 21 | #define MINIJAIL_MAX_SECCOMP_FILTER_LINE 512 |
| 22 | |
Will Drewry | f89aef5 | 2011-09-16 16:48:57 -0500 | [diff] [blame] | 23 | struct minijail; |
Elly Jones | e1749eb | 2011-10-07 13:54:59 -0400 | [diff] [blame] | 24 | |
| 25 | /* minijail_size: returns the size (in bytes) of @j if marshalled |
| 26 | * @j jail to compute size of |
| 27 | * |
| 28 | * Returns 0 on error. |
Will Drewry | 2ddaad0 | 2011-09-16 11:36:08 -0500 | [diff] [blame] | 29 | */ |
| 30 | extern size_t minijail_size(const struct minijail *j); |
Elly Jones | e1749eb | 2011-10-07 13:54:59 -0400 | [diff] [blame] | 31 | |
| 32 | /* minijail_marshal: serializes @j to @buf |
| 33 | * @j minijail to serialize |
| 34 | * @buf buffer to serialize to |
| 35 | * @size size of @buf |
| 36 | * |
| 37 | * Returns 0 on success. |
| 38 | * |
Will Drewry | 2ddaad0 | 2011-09-16 11:36:08 -0500 | [diff] [blame] | 39 | * Writes |j| to |buf| such that it can be reparsed by the same |
| 40 | * library on the same architecture. This is meant to be used |
| 41 | * by minijail0.c and libminijailpreload.c. minijail flags that |
| 42 | * require minijail_run() will be excluded. |
| 43 | * |
| 44 | * The marshalled data is not robust to differences between the child |
| 45 | * and parent process (personality, etc). |
Will Drewry | 2ddaad0 | 2011-09-16 11:36:08 -0500 | [diff] [blame] | 46 | */ |
| 47 | extern int minijail_marshal(const struct minijail *j, |
| 48 | char *buf, |
Elly Jones | e1749eb | 2011-10-07 13:54:59 -0400 | [diff] [blame] | 49 | size_t size); |
| 50 | |
| 51 | /* minijail_unmarshal: initializes @j from @serialized |
| 52 | * @j minijail to initialize |
| 53 | * @serialized serialized jail buffer |
| 54 | * @length length of buffer |
| 55 | * |
| 56 | * Returns 0 on success. |
| 57 | */ |
Will Drewry | 2ddaad0 | 2011-09-16 11:36:08 -0500 | [diff] [blame] | 58 | extern int minijail_unmarshal(struct minijail *j, |
| 59 | char *serialized, |
| 60 | size_t length); |
Elly Jones | e1749eb | 2011-10-07 13:54:59 -0400 | [diff] [blame] | 61 | |
| 62 | /* minijail_from_fd: builds @j from @fd |
| 63 | * @j minijail to initialize |
| 64 | * @fd fd to initialize from |
| 65 | * |
| 66 | * Returns 0 on success. |
| 67 | */ |
Will Drewry | fe4a372 | 2011-09-16 14:50:50 -0500 | [diff] [blame] | 68 | extern int minijail_from_fd(int fd, struct minijail *j); |
Elly Jones | e1749eb | 2011-10-07 13:54:59 -0400 | [diff] [blame] | 69 | |
| 70 | /* minijail_to_fd: sends @j over @fd |
| 71 | * @j minijail to send |
| 72 | * @fd fd to send over |
| 73 | * |
| 74 | * Returns 0 on success. |
| 75 | */ |
Will Drewry | fe4a372 | 2011-09-16 14:50:50 -0500 | [diff] [blame] | 76 | extern int minijail_to_fd(struct minijail *j, int fd); |
Elly Jones | e1749eb | 2011-10-07 13:54:59 -0400 | [diff] [blame] | 77 | |
| 78 | /* minijail_preexec: strips @j of all options handled by minijail_enter() |
| 79 | * @j jail to strip |
| 80 | */ |
Will Drewry | fe4a372 | 2011-09-16 14:50:50 -0500 | [diff] [blame] | 81 | extern void minijail_preexec(struct minijail *j); |
Elly Jones | e1749eb | 2011-10-07 13:54:59 -0400 | [diff] [blame] | 82 | |
| 83 | /* minijail_preenter: strips @j of all options handled by minijail_run() |
| 84 | * @j jail to strip |
| 85 | */ |
Will Drewry | 2ddaad0 | 2011-09-16 11:36:08 -0500 | [diff] [blame] | 86 | extern void minijail_preenter(struct minijail *j); |
| 87 | |
Elly Jones | cd7a904 | 2011-07-22 13:56:51 -0400 | [diff] [blame] | 88 | #endif /* !LIBMINIJAIL_PRIVATE_H */ |