Say I have a process with seccomp filters installed. At runtime, i would like to see all the seccomp filtered installed within this process.
How can I achieve that? Reading through seccomp man page does not seem to find the answers.
Say I have a process with seccomp filters installed. At runtime, i would like to see all the seccomp filtered installed within this process.
How can I achieve that? Reading through seccomp man page does not seem to find the answers.
Copyright © 2021 Jogjafile Inc.
You can use
ptrace(PTRACE_SECCOMP_GET_FILTER, pid, (void *)i, data)whereiis the index of the filter with the must recently installed being 0, anddatais an array ofstruct sock_filterorNULLto read the size. The return value is the number of instructions in the filter.