Skip to content
This repository was archived by the owner on Aug 18, 2026. It is now read-only.

backend: support per-rule seccomp actions - #102

Closed
lu-zero wants to merge 1 commit into
rust-vmm:mainfrom
lu-zero:pr/per-rule-actions
Closed

backend: support per-rule seccomp actions#102
lu-zero wants to merge 1 commit into
rust-vmm:mainfrom
lu-zero:pr/per-rule-actions

Conversation

@lu-zero

@lu-zero lu-zero commented Jul 30, 2026

Copy link
Copy Markdown

Allow each SeccompRule to carry an optional action that overrides the filter-level match_action when set. Add SeccompRule::new_with_action and SeccompRule::always; emit the rule's own RET in the generated BPF. Condition-less rules are valid only when they specify an action.

Rules without a per-rule action keep the previous behavior (empty rule vectors and SeccompRule::new still use match_action).

Cover BPF emission in unit tests and install-time behavior for always() and new_with_action() in integration tests.

Spun off from #99

Allow each SeccompRule to carry an optional action that overrides
the filter-level match_action when set. Add SeccompRule::new_with_action
and SeccompRule::always; emit the rule's own RET in the generated BPF.
Condition-less rules are valid only when they specify an action.

Rules without a per-rule action keep the previous behavior (empty rule
vectors and SeccompRule::new still use match_action).

Cover BPF emission in unit tests and install-time behavior for always()
and new_with_action() in integration tests.

Signed-off-by: Luca Barbato <lu_zero@gentoo.org>
@andreeaflorescu

Copy link
Copy Markdown
Member

@lu-zero are you still interested in getting this PR merged? If yes, could you please re-open it in https://github.com/rust-vmm/rust-vmm/. We moved seccompiler there.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants