+#define NUM_SYSCALLS ARRAY_SIZE(syscall_names)
+#define NUM_ACTIONS (NUM_SYSCALLS+64)
+
+enum action {
+ A_DEFAULT, // Use the default action
+ A_NO, // Always forbid
+ A_YES, // Always permit
+ A_FILENAME, // Permit if arg1 is a known filename
+ A_LIBERAL = 128, // Valid only in liberal mode
+};
+
+static unsigned char syscall_action[NUM_ACTIONS] = {
+#define S(x) [__NR_##x]
+
+ // Syscalls permitted for specific file names
+ S(open) = A_FILENAME,
+ S(creat) = A_FILENAME,
+ S(unlink) = A_FILENAME,
+ S(oldstat) = A_FILENAME,
+ S(access) = A_FILENAME,
+ S(oldlstat) = A_FILENAME,
+ S(truncate) = A_FILENAME,
+ S(stat) = A_FILENAME,
+ S(lstat) = A_FILENAME,
+ S(truncate64) = A_FILENAME,
+ S(stat64) = A_FILENAME,
+ S(lstat64) = A_FILENAME,
+ S(readlink) = A_FILENAME,
+
+ // Syscalls permitted always
+ S(exit) = A_YES,
+ S(read) = A_YES,
+ S(write) = A_YES,
+ S(close) = A_YES,
+ S(lseek) = A_YES,
+ S(getpid) = A_YES,
+ S(getuid) = A_YES,
+ S(oldfstat) = A_YES,
+ S(dup) = A_YES,
+ S(brk) = A_YES,
+ S(getgid) = A_YES,
+ S(geteuid) = A_YES,
+ S(getegid) = A_YES,
+ S(dup2) = A_YES,
+ S(ftruncate) = A_YES,
+ S(fstat) = A_YES,
+ S(personality) = A_YES,
+ S(_llseek) = A_YES,
+ S(readv) = A_YES,
+ S(writev) = A_YES,
+ S(getresuid) = A_YES,
+#ifdef __NR_pread64
+ S(pread64) = A_YES,
+ S(pwrite64) = A_YES,
+#else
+ S(pread) = A_YES,
+ S(pwrite) = A_YES,
+#endif
+ S(ftruncate64) = A_YES,
+ S(fstat64) = A_YES,
+ S(fcntl) = A_YES,
+ S(fcntl64) = A_YES,
+ S(mmap) = A_YES,
+ S(munmap) = A_YES,
+ S(ioctl) = A_YES,
+ S(uname) = A_YES,
+ S(gettid) = A_YES,
+ S(set_thread_area) = A_YES,
+ S(get_thread_area) = A_YES,
+ S(exit_group) = A_YES,
+
+ // Syscalls permitted only in liberal mode
+ S(time) = A_YES | A_LIBERAL,
+ S(alarm) = A_YES | A_LIBERAL,
+ S(pause) = A_YES | A_LIBERAL,
+ S(signal) = A_YES | A_LIBERAL,
+ S(fchmod) = A_YES | A_LIBERAL,
+ S(sigaction) = A_YES | A_LIBERAL,
+ S(sgetmask) = A_YES | A_LIBERAL,
+ S(ssetmask) = A_YES | A_LIBERAL,
+ S(sigsuspend) = A_YES | A_LIBERAL,
+ S(sigpending) = A_YES | A_LIBERAL,
+ S(getrlimit) = A_YES | A_LIBERAL,
+ S(getrusage) = A_YES | A_LIBERAL,
+ S(ugetrlimit) = A_YES | A_LIBERAL,
+ S(gettimeofday) = A_YES | A_LIBERAL,
+ S(select) = A_YES | A_LIBERAL,
+ S(readdir) = A_YES | A_LIBERAL,
+ S(setitimer) = A_YES | A_LIBERAL,
+ S(getitimer) = A_YES | A_LIBERAL,
+ S(sigreturn) = A_YES | A_LIBERAL,
+ S(mprotect) = A_YES | A_LIBERAL,
+ S(sigprocmask) = A_YES | A_LIBERAL,
+ S(getdents) = A_YES | A_LIBERAL,
+ S(getdents64) = A_YES | A_LIBERAL,
+ S(_newselect) = A_YES | A_LIBERAL,
+ S(fdatasync) = A_YES | A_LIBERAL,
+ S(mremap) = A_YES | A_LIBERAL,
+ S(poll) = A_YES | A_LIBERAL,
+ S(getcwd) = A_YES | A_LIBERAL,
+ S(nanosleep) = A_YES | A_LIBERAL,
+ S(rt_sigreturn) = A_YES | A_LIBERAL,
+ S(rt_sigaction) = A_YES | A_LIBERAL,
+ S(rt_sigprocmask) = A_YES | A_LIBERAL,
+ S(rt_sigpending) = A_YES | A_LIBERAL,
+ S(rt_sigtimedwait) = A_YES | A_LIBERAL,
+ S(rt_sigqueueinfo) = A_YES | A_LIBERAL,
+ S(rt_sigsuspend) = A_YES | A_LIBERAL,
+ S(mmap2) = A_YES | A_LIBERAL,
+ S(_sysctl) = A_YES | A_LIBERAL,
+#undef S
+};