// Code generated by cmd/cgo; DO NOT EDIT.

//line /build/output/build/runc-1.4.3/vendor/github.com/seccomp/libseccomp-golang/seccomp_internal.go:1:1
// Internal functions for libseccomp Go bindings
// No exported functions

package seccomp

import (
	"errors"
	"fmt"
	"syscall"
)

// Unexported C wrapping code - provides the C-Golang interface
// Get the seccomp header in scope
// Need stdlib.h for free() on cstrings

// To compile libseccomp-golang against a specific version of libseccomp:
// cd ../libseccomp && mkdir -p prefix
// ./configure --prefix=$PWD/prefix && make && make install
// cd ../libseccomp-golang
// PKG_CONFIG_PATH=$PWD/../libseccomp/prefix/lib/pkgconfig/ make
// LD_PRELOAD=$PWD/../libseccomp/prefix/lib/libseccomp.so.2.5.0 PKG_CONFIG_PATH=$PWD/../libseccomp/prefix/lib/pkgconfig/ make test

// #cgo pkg-config: libseccomp
/*
#include <errno.h>
#include <stdlib.h>
#include <seccomp.h>

#if (SCMP_VER_MAJOR < 2) || \
    (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 3) || \
    (SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR == 3 && SCMP_VER_MICRO < 1)
#error This package requires libseccomp >= v2.3.1
#endif

#define ARCH_BAD ~0

const uint32_t C_ARCH_BAD = ARCH_BAD;

#ifndef SCMP_ARCH_PPC
#define SCMP_ARCH_PPC ARCH_BAD
#endif

#ifndef SCMP_ARCH_PPC64
#define SCMP_ARCH_PPC64 ARCH_BAD
#endif

#ifndef SCMP_ARCH_PPC64LE
#define SCMP_ARCH_PPC64LE ARCH_BAD
#endif

#ifndef SCMP_ARCH_S390
#define SCMP_ARCH_S390 ARCH_BAD
#endif

#ifndef SCMP_ARCH_S390X
#define SCMP_ARCH_S390X ARCH_BAD
#endif

#ifndef SCMP_ARCH_PARISC
#define SCMP_ARCH_PARISC ARCH_BAD
#endif

#ifndef SCMP_ARCH_PARISC64
#define SCMP_ARCH_PARISC64 ARCH_BAD
#endif

#ifndef SCMP_ARCH_RISCV64
#define SCMP_ARCH_RISCV64 ARCH_BAD
#endif

#ifndef SCMP_ARCH_LOONGARCH64
#define SCMP_ARCH_LOONGARCH64 ARCH_BAD
#endif

#ifndef SCMP_ARCH_M68K
#define SCMP_ARCH_M68K ARCH_BAD
#endif

#ifndef SCMP_ARCH_SH
#define SCMP_ARCH_SH ARCH_BAD
#endif

#ifndef SCMP_ARCH_SHEB
#define SCMP_ARCH_SHEB ARCH_BAD
#endif

const uint32_t C_ARCH_NATIVE       = SCMP_ARCH_NATIVE;
const uint32_t C_ARCH_X86          = SCMP_ARCH_X86;
const uint32_t C_ARCH_X86_64       = SCMP_ARCH_X86_64;
const uint32_t C_ARCH_X32          = SCMP_ARCH_X32;
const uint32_t C_ARCH_ARM          = SCMP_ARCH_ARM;
const uint32_t C_ARCH_AARCH64      = SCMP_ARCH_AARCH64;
const uint32_t C_ARCH_MIPS         = SCMP_ARCH_MIPS;
const uint32_t C_ARCH_MIPS64       = SCMP_ARCH_MIPS64;
const uint32_t C_ARCH_MIPS64N32    = SCMP_ARCH_MIPS64N32;
const uint32_t C_ARCH_MIPSEL       = SCMP_ARCH_MIPSEL;
const uint32_t C_ARCH_MIPSEL64     = SCMP_ARCH_MIPSEL64;
const uint32_t C_ARCH_MIPSEL64N32  = SCMP_ARCH_MIPSEL64N32;
const uint32_t C_ARCH_PPC          = SCMP_ARCH_PPC;
const uint32_t C_ARCH_PPC64        = SCMP_ARCH_PPC64;
const uint32_t C_ARCH_PPC64LE      = SCMP_ARCH_PPC64LE;
const uint32_t C_ARCH_S390         = SCMP_ARCH_S390;
const uint32_t C_ARCH_S390X        = SCMP_ARCH_S390X;
const uint32_t C_ARCH_PARISC       = SCMP_ARCH_PARISC;
const uint32_t C_ARCH_PARISC64     = SCMP_ARCH_PARISC64;
const uint32_t C_ARCH_RISCV64      = SCMP_ARCH_RISCV64;
const uint32_t C_ARCH_LOONGARCH64  = SCMP_ARCH_LOONGARCH64;
const uint32_t C_ARCH_M68K         = SCMP_ARCH_M68K;
const uint32_t C_ARCH_SH           = SCMP_ARCH_SH;
const uint32_t C_ARCH_SHEB         = SCMP_ARCH_SHEB;

#ifndef SCMP_ACT_LOG
#define SCMP_ACT_LOG 0x7ffc0000U
#endif

#ifndef SCMP_ACT_KILL_PROCESS
#define SCMP_ACT_KILL_PROCESS 0x80000000U
#endif

#ifndef SCMP_ACT_KILL_THREAD
#define SCMP_ACT_KILL_THREAD	0x00000000U
#endif

#ifndef SCMP_ACT_NOTIFY
#define SCMP_ACT_NOTIFY 0x7fc00000U
#endif

const uint32_t C_ACT_KILL          = SCMP_ACT_KILL;
const uint32_t C_ACT_KILL_PROCESS  = SCMP_ACT_KILL_PROCESS;
const uint32_t C_ACT_KILL_THREAD   = SCMP_ACT_KILL_THREAD;
const uint32_t C_ACT_TRAP          = SCMP_ACT_TRAP;
const uint32_t C_ACT_ERRNO         = SCMP_ACT_ERRNO(0);
const uint32_t C_ACT_TRACE         = SCMP_ACT_TRACE(0);
const uint32_t C_ACT_LOG           = SCMP_ACT_LOG;
const uint32_t C_ACT_ALLOW         = SCMP_ACT_ALLOW;
const uint32_t C_ACT_NOTIFY        = SCMP_ACT_NOTIFY;

// The libseccomp SCMP_FLTATR_CTL_LOG member of the scmp_filter_attr enum was
// added in v2.4.0
#if SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 4
#define SCMP_FLTATR_CTL_LOG _SCMP_FLTATR_MIN
#endif

// The following SCMP_FLTATR_*  were added in libseccomp v2.5.0.
#if SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 5
#define SCMP_FLTATR_CTL_SSB      _SCMP_FLTATR_MIN
#define SCMP_FLTATR_CTL_OPTIMIZE _SCMP_FLTATR_MIN
#define SCMP_FLTATR_API_SYSRAWRC _SCMP_FLTATR_MIN
#endif

// Added in libseccomp v2.6.0.
#if SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 6
#define SCMP_FLTATR_CTL_WAITKILL _SCMP_FLTATR_MIN
#endif

const uint32_t C_ATTRIBUTE_DEFAULT  = (uint32_t)SCMP_FLTATR_ACT_DEFAULT;
const uint32_t C_ATTRIBUTE_BADARCH  = (uint32_t)SCMP_FLTATR_ACT_BADARCH;
const uint32_t C_ATTRIBUTE_NNP      = (uint32_t)SCMP_FLTATR_CTL_NNP;
const uint32_t C_ATTRIBUTE_TSYNC    = (uint32_t)SCMP_FLTATR_CTL_TSYNC;
const uint32_t C_ATTRIBUTE_LOG      = (uint32_t)SCMP_FLTATR_CTL_LOG;
const uint32_t C_ATTRIBUTE_SSB      = (uint32_t)SCMP_FLTATR_CTL_SSB;
const uint32_t C_ATTRIBUTE_OPTIMIZE = (uint32_t)SCMP_FLTATR_CTL_OPTIMIZE;
const uint32_t C_ATTRIBUTE_SYSRAWRC = (uint32_t)SCMP_FLTATR_API_SYSRAWRC;
const uint32_t C_ATTRIBUTE_WAITKILL = (uint32_t)SCMP_FLTATR_CTL_WAITKILL;

const int      C_CMP_NE            = (int)SCMP_CMP_NE;
const int      C_CMP_LT            = (int)SCMP_CMP_LT;
const int      C_CMP_LE            = (int)SCMP_CMP_LE;
const int      C_CMP_EQ            = (int)SCMP_CMP_EQ;
const int      C_CMP_GE            = (int)SCMP_CMP_GE;
const int      C_CMP_GT            = (int)SCMP_CMP_GT;
const int      C_CMP_MASKED_EQ     = (int)SCMP_CMP_MASKED_EQ;

unsigned int get_major_version()
{
        return seccomp_version()->major;
}

unsigned int get_minor_version()
{
        return seccomp_version()->minor;
}

unsigned int get_micro_version()
{
        return seccomp_version()->micro;
}

// The libseccomp API level functions were added in v2.4.0
#if SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 4
const unsigned int seccomp_api_get(void)
{
	// libseccomp-golang requires libseccomp v2.2.0, at a minimum, which
	// supported API level 2. However, the kernel may not support API level
	// 2 constructs which are the seccomp() system call and the TSYNC
	// filter flag. Return the "reserved" value of 0 here to indicate that
	// proper API level support is not available in libseccomp.
	return 0;
}

int seccomp_api_set(unsigned int level)
{
	return -EOPNOTSUPP;
}
#endif

typedef struct scmp_arg_cmp* scmp_cast_t;

void* make_arg_cmp_array(unsigned int length)
{
        return calloc(length, sizeof(struct scmp_arg_cmp));
}

// Wrapper to add an scmp_arg_cmp struct to an existing arg_cmp array
void add_struct_arg_cmp(
                        struct scmp_arg_cmp* arr,
                        unsigned int pos,
                        unsigned int arg,
                        int compare,
                        uint64_t a,
                        uint64_t b
                       )
{
        arr[pos].arg = arg;
        arr[pos].op = compare;
        arr[pos].datum_a = a;
        arr[pos].datum_b = b;

        return;
}

// The seccomp notify API functions were added in v2.5.0
#if SCMP_VER_MAJOR == 2 && SCMP_VER_MINOR < 5

struct seccomp_data {
	int nr;
	__u32 arch;
	__u64 instruction_pointer;
	__u64 args[6];
};

struct seccomp_notif {
	__u64 id;
	__u32 pid;
	__u32 flags;
	struct seccomp_data data;
};

struct seccomp_notif_resp {
	__u64 id;
	__s64 val;
	__s32 error;
	__u32 flags;
};

int seccomp_notify_alloc(struct seccomp_notif **req, struct seccomp_notif_resp **resp) {
	return -EOPNOTSUPP;
}
int seccomp_notify_fd(const scmp_filter_ctx ctx) {
	return -EOPNOTSUPP;
}
void seccomp_notify_free(struct seccomp_notif *req, struct seccomp_notif_resp *resp) {
}
int seccomp_notify_id_valid(int fd, uint64_t id) {
	return -EOPNOTSUPP;
}
int seccomp_notify_receive(int fd, struct seccomp_notif *req) {
	return -EOPNOTSUPP;
}
int seccomp_notify_respond(int fd, struct seccomp_notif_resp *resp) {
	return -EOPNOTSUPP;
}

#endif
*/
import _ "unsafe"

// Nonexported types
type scmpFilterAttr uint32

// Nonexported constants

const (
	filterAttrActDefault scmpFilterAttr = iota
	filterAttrActBadArch
	filterAttrNNP
	filterAttrTsync
	filterAttrLog
	filterAttrSSB
	filterAttrOptimize
	filterAttrRawRC
	filterAttrWaitKill
)

const (
	// An error return from certain libseccomp functions
	scmpError  /*line :297:12*/_Ctype_int /*line :297:17*/ = -1
	// Comparison boundaries to check for architecture validity
	archStart ScmpArch = ArchNative
	archEnd   ScmpArch = ArchSHEB
	// Comparison boundaries to check for action validity
	actionStart ScmpAction = ActKillThread
	actionEnd   ScmpAction = ActKillProcess
	// Comparison boundaries to check for comparison operator validity
	compareOpStart ScmpCompareOp = CompareNotEqual
	compareOpEnd   ScmpCompareOp = CompareMaskedEqual
)

var (
	// errBadFilter is thrown on bad filter context.
	errBadFilter = errors.New("filter is invalid or uninitialized")
	errDefAction = errors.New("requested action matches default action of filter")
	// Constants representing library major, minor, and micro versions
	verMajor = uint(( /*line :314:18*/_Cfunc_get_major_version /*line :314:36*/)())
	verMinor = uint(( /*line :315:18*/_Cfunc_get_minor_version /*line :315:36*/)())
	verMicro = uint(( /*line :316:18*/_Cfunc_get_micro_version /*line :316:36*/)())
)

// Nonexported functions

// checkVersion returns an error if the libseccomp version being used
// is less than the one specified by major, minor, and micro arguments.
// Argument op is an arbitrary non-empty operation description, which
// is used as a part of the error message returned.
//
// Most users should use checkAPI instead.
func checkVersion(op string, major, minor, micro uint) error {
	if (verMajor > major) ||
		(verMajor == major && verMinor > minor) ||
		(verMajor == major && verMinor == minor && verMicro >= micro) {
		return nil
	}
	return &VersionError{
		op:    op,
		major: major,
		minor: minor,
		micro: micro,
	}
}

func ensureSupportedVersion() error {
	return checkVersion("seccomp", 2, 3, 1)
}

// Get the API level
func getAPI() (uint, error) {
	api := ( /*line :347:9*/_Cfunc_seccomp_api_get /*line :347:25*/)()
	if api == 0 {
		return 0, errors.New("API level operations are not supported")
	}

	return uint(api), nil
}

// Set the API level
func setAPI(api uint) error {
	if retCode := ( /*line :357:16*/_Cfunc_seccomp_api_set /*line :357:32*/)( /*line :357:34*/_Ctype_uint /*line :357:40*/(api)); retCode != 0 {
		e := errRc(retCode)
		if e == syscall.EOPNOTSUPP {
			return errors.New("API level operations are not supported")
		}

		return fmt.Errorf("could not set API level: %w", e)
	}

	return nil
}

// Filter helpers

// Filter finalizer - ensure that kernel context for filters is freed
func filterFinalizer(f *ScmpFilter) {
	f.Release()
}

func errRc(rc  /*line :376:15*/_Ctype_int /*line :376:20*/) error {
	return syscall.Errno(-1 * rc)
}

// Get a raw filter attribute
func (f *ScmpFilter) getFilterAttr(attr scmpFilterAttr) ( /*line :381:58*/_Ctype_uint32_t /*line :381:68*/, error) {
	f.lock.Lock()
	defer f.lock.Unlock()

	if !f.valid {
		return 0x0, errBadFilter
	}

	var attribute  /*line :389:16*/_Ctype_uint32_t /*line :389:26*/

	retCode := func() _Ctype_int{ _cgo0 := /*line :391:32*/f.filterCtx; var _cgo1 uint32 = /*line :391:45*/attr.toNative(); var _cgo2 *_Ctype_uint32_t = /*line :391:62*/&attribute; _cgoCheckPointer(_cgo0, nil); return /*line :391:73*/_Cfunc_seccomp_attr_get(_cgo0, _cgo1, _cgo2); }()
	if retCode != 0 {
		return 0x0, errRc(retCode)
	}

	return attribute, nil
}

// Set a raw filter attribute
func (f *ScmpFilter) setFilterAttr(attr scmpFilterAttr, value  /*line :400:63*/_Ctype_uint32_t /*line :400:73*/) error {
	f.lock.Lock()
	defer f.lock.Unlock()

	if !f.valid {
		return errBadFilter
	}

	retCode := func() _Ctype_int{ _cgo0 := /*line :408:32*/f.filterCtx; var _cgo1 uint32 = /*line :408:45*/attr.toNative(); var _cgo2 _Ctype_uint32_t = /*line :408:62*/value; _cgoCheckPointer(_cgo0, nil); return /*line :408:68*/_Cfunc_seccomp_attr_set(_cgo0, _cgo1, _cgo2); }()
	if retCode != 0 {
		return errRc(retCode)
	}

	return nil
}

// DOES NOT LOCK OR CHECK VALIDITY
// Assumes caller has already done this
// Wrapper for seccomp_rule_add_... functions
func (f *ScmpFilter) addRuleWrapper(call ScmpSyscall, action ScmpAction, exact bool, length  /*line :419:93*/_Ctype_uint /*line :419:99*/, cond  /*line :419:106*/_Ctype_scmp_cast_t /*line :419:119*/) error {
	if length != 0 && cond == nil {
		return errors.New("null conditions list, but length is nonzero")
	}

	var retCode  /*line :424:14*/_Ctype_int /*line :424:19*/
	if exact {
		retCode = func() _Ctype_int{ _cgo0 := /*line :426:44*/f.filterCtx; var _cgo1 _Ctype_uint32_t = /*line :426:57*/action.toNative(); var _cgo2 _Ctype_int = _Ctype_int /*line :426:81*/(call); var _cgo3 _Ctype_uint = /*line :426:89*/length; var _cgo4 *_Ctype_struct_scmp_arg_cmp = /*line :426:97*/cond; _cgoCheckPointer(_cgo0, nil); return /*line :426:102*/_Cfunc_seccomp_rule_add_exact_array(_cgo0, _cgo1, _cgo2, _cgo3, _cgo4); }()
	} else {
		retCode = func() _Ctype_int{ _cgo0 := /*line :428:38*/f.filterCtx; var _cgo1 _Ctype_uint32_t = /*line :428:51*/action.toNative(); var _cgo2 _Ctype_int = _Ctype_int /*line :428:75*/(call); var _cgo3 _Ctype_uint = /*line :428:83*/length; var _cgo4 *_Ctype_struct_scmp_arg_cmp = /*line :428:91*/cond; _cgoCheckPointer(_cgo0, nil); return /*line :428:96*/_Cfunc_seccomp_rule_add_array(_cgo0, _cgo1, _cgo2, _cgo3, _cgo4); }()
	}

	if retCode != 0 {
		switch e := errRc(retCode); e {
		case syscall.EFAULT:
			return fmt.Errorf("unrecognized syscall %#x", int32(call))
		// libseccomp >= v2.5.0 returns EACCES, older versions return EPERM.
		// TODO: remove EPERM once libseccomp < v2.5.0 is not supported.
		case syscall.EPERM, syscall.EACCES:
			return errDefAction
		case syscall.EINVAL:
			return errors.New("two checks on same syscall argument")
		default:
			return e
		}
	}

	return nil
}

// Generic add function for filter rules
func (f *ScmpFilter) addRuleGeneric(call ScmpSyscall, action ScmpAction, exact bool, conds []ScmpCondition) error {
	f.lock.Lock()
	defer f.lock.Unlock()

	if !f.valid {
		return errBadFilter
	}

	if len(conds) == 0 {
		if err := f.addRuleWrapper(call, action, exact, 0, nil); err != nil {
			return err
		}
	} else {
		argsArr := ( /*line :463:14*/_Cfunc_make_arg_cmp_array /*line :463:33*/)( /*line :463:35*/_Ctype_uint /*line :463:41*/(len(conds)))
		if argsArr == nil {
			return errors.New("error allocating memory for conditions")
		}
		defer func() func() { _cgo0 := /*line :467:16*/argsArr; return func() { _cgoCheckPointer(_cgo0, nil); /*line :467:24*/_Cfunc_free(_cgo0); }}()()

		for i, cond := range conds {
			( /*line :470:4*/_Cfunc_add_struct_arg_cmp /*line :470:23*/)( /*line :470:25*/_Ctype_scmp_cast_t /*line :470:38*/(argsArr),  /*line :470:49*/_Ctype_uint /*line :470:55*/(i),
				 /*line :471:5*/_Ctype_uint /*line :471:11*/(cond.Argument), cond.Op.toNative(),
				 /*line :472:5*/_Ctype_uint64_t /*line :472:15*/(cond.Operand1),  /*line :472:32*/_Ctype_uint64_t /*line :472:42*/(cond.Operand2))
		}

		if err := f.addRuleWrapper(call, action, exact,  /*line :475:51*/_Ctype_uint /*line :475:57*/(len(conds)),  /*line :475:71*/_Ctype_scmp_cast_t /*line :475:84*/(argsArr)); err != nil {
			return err
		}
	}

	return nil
}

// Generic Helpers

// Helper - Sanitize Arch token input
func sanitizeArch(in ScmpArch) error {
	if in < archStart || in > archEnd {
		return fmt.Errorf("unrecognized architecture %#x", uint(in))
	}

	if in.toNative() == ( /*line :491:22*/*_Cvar_C_ARCH_BAD /*line :491:33*/) {
		return fmt.Errorf("architecture %v is not supported on this version of the library", in)
	}

	return nil
}

func sanitizeAction(in ScmpAction) error {
	inTmp := in & 0x0000FFFF
	if inTmp < actionStart || inTmp > actionEnd {
		return fmt.Errorf("unrecognized action %#x", uint(inTmp))
	}

	if inTmp != ActTrace && inTmp != ActErrno && (in&0xFFFF0000) != 0 {
		return errors.New("highest 16 bits must be zeroed except for Trace and Errno")
	}

	return nil
}

func sanitizeCompareOp(in ScmpCompareOp) error {
	if in < compareOpStart || in > compareOpEnd {
		return fmt.Errorf("unrecognized comparison operator %#x", uint(in))
	}

	return nil
}

func archFromNative(a  /*line :519:23*/_Ctype_uint32_t /*line :519:33*/) (ScmpArch, error) {
	switch a {
	case ( /*line :521:7*/*_Cvar_C_ARCH_X86 /*line :521:18*/):
		return ArchX86, nil
	case ( /*line :523:7*/*_Cvar_C_ARCH_X86_64 /*line :523:21*/):
		return ArchAMD64, nil
	case ( /*line :525:7*/*_Cvar_C_ARCH_X32 /*line :525:18*/):
		return ArchX32, nil
	case ( /*line :527:7*/*_Cvar_C_ARCH_ARM /*line :527:18*/):
		return ArchARM, nil
	case ( /*line :529:7*/*_Cvar_C_ARCH_NATIVE /*line :529:21*/):
		return ArchNative, nil
	case ( /*line :531:7*/*_Cvar_C_ARCH_AARCH64 /*line :531:22*/):
		return ArchARM64, nil
	case ( /*line :533:7*/*_Cvar_C_ARCH_MIPS /*line :533:19*/):
		return ArchMIPS, nil
	case ( /*line :535:7*/*_Cvar_C_ARCH_MIPS64 /*line :535:21*/):
		return ArchMIPS64, nil
	case ( /*line :537:7*/*_Cvar_C_ARCH_MIPS64N32 /*line :537:24*/):
		return ArchMIPS64N32, nil
	case ( /*line :539:7*/*_Cvar_C_ARCH_MIPSEL /*line :539:21*/):
		return ArchMIPSEL, nil
	case ( /*line :541:7*/*_Cvar_C_ARCH_MIPSEL64 /*line :541:23*/):
		return ArchMIPSEL64, nil
	case ( /*line :543:7*/*_Cvar_C_ARCH_MIPSEL64N32 /*line :543:26*/):
		return ArchMIPSEL64N32, nil
	case ( /*line :545:7*/*_Cvar_C_ARCH_PPC /*line :545:18*/):
		return ArchPPC, nil
	case ( /*line :547:7*/*_Cvar_C_ARCH_PPC64 /*line :547:20*/):
		return ArchPPC64, nil
	case ( /*line :549:7*/*_Cvar_C_ARCH_PPC64LE /*line :549:22*/):
		return ArchPPC64LE, nil
	case ( /*line :551:7*/*_Cvar_C_ARCH_S390 /*line :551:19*/):
		return ArchS390, nil
	case ( /*line :553:7*/*_Cvar_C_ARCH_S390X /*line :553:20*/):
		return ArchS390X, nil
	case ( /*line :555:7*/*_Cvar_C_ARCH_PARISC /*line :555:21*/):
		return ArchPARISC, nil
	case ( /*line :557:7*/*_Cvar_C_ARCH_PARISC64 /*line :557:23*/):
		return ArchPARISC64, nil
	case ( /*line :559:7*/*_Cvar_C_ARCH_RISCV64 /*line :559:22*/):
		return ArchRISCV64, nil
	case ( /*line :561:7*/*_Cvar_C_ARCH_LOONGARCH64 /*line :561:26*/):
		return ArchLOONGARCH64, nil
	case ( /*line :563:7*/*_Cvar_C_ARCH_M68K /*line :563:19*/):
		return ArchM68K, nil
	case ( /*line :565:7*/*_Cvar_C_ARCH_SH /*line :565:17*/):
		return ArchSH, nil
	case ( /*line :567:7*/*_Cvar_C_ARCH_SHEB /*line :567:19*/):
		return ArchSHEB, nil
	default:
		return 0x0, fmt.Errorf("unrecognized architecture %#x", uint32(a))
	}
}

// Only use with sanitized arches, no error handling
func (a ScmpArch) toNative()  /*line :575:30*/_Ctype_uint32_t /*line :575:40*/ {
	switch a {
	case ArchX86:
		return ( /*line :578:10*/*_Cvar_C_ARCH_X86 /*line :578:21*/)
	case ArchAMD64:
		return ( /*line :580:10*/*_Cvar_C_ARCH_X86_64 /*line :580:24*/)
	case ArchX32:
		return ( /*line :582:10*/*_Cvar_C_ARCH_X32 /*line :582:21*/)
	case ArchARM:
		return ( /*line :584:10*/*_Cvar_C_ARCH_ARM /*line :584:21*/)
	case ArchARM64:
		return ( /*line :586:10*/*_Cvar_C_ARCH_AARCH64 /*line :586:25*/)
	case ArchMIPS:
		return ( /*line :588:10*/*_Cvar_C_ARCH_MIPS /*line :588:22*/)
	case ArchMIPS64:
		return ( /*line :590:10*/*_Cvar_C_ARCH_MIPS64 /*line :590:24*/)
	case ArchMIPS64N32:
		return ( /*line :592:10*/*_Cvar_C_ARCH_MIPS64N32 /*line :592:27*/)
	case ArchMIPSEL:
		return ( /*line :594:10*/*_Cvar_C_ARCH_MIPSEL /*line :594:24*/)
	case ArchMIPSEL64:
		return ( /*line :596:10*/*_Cvar_C_ARCH_MIPSEL64 /*line :596:26*/)
	case ArchMIPSEL64N32:
		return ( /*line :598:10*/*_Cvar_C_ARCH_MIPSEL64N32 /*line :598:29*/)
	case ArchPPC:
		return ( /*line :600:10*/*_Cvar_C_ARCH_PPC /*line :600:21*/)
	case ArchPPC64:
		return ( /*line :602:10*/*_Cvar_C_ARCH_PPC64 /*line :602:23*/)
	case ArchPPC64LE:
		return ( /*line :604:10*/*_Cvar_C_ARCH_PPC64LE /*line :604:25*/)
	case ArchS390:
		return ( /*line :606:10*/*_Cvar_C_ARCH_S390 /*line :606:22*/)
	case ArchS390X:
		return ( /*line :608:10*/*_Cvar_C_ARCH_S390X /*line :608:23*/)
	case ArchPARISC:
		return ( /*line :610:10*/*_Cvar_C_ARCH_PARISC /*line :610:24*/)
	case ArchPARISC64:
		return ( /*line :612:10*/*_Cvar_C_ARCH_PARISC64 /*line :612:26*/)
	case ArchRISCV64:
		return ( /*line :614:10*/*_Cvar_C_ARCH_RISCV64 /*line :614:25*/)
	case ArchLOONGARCH64:
		return ( /*line :616:10*/*_Cvar_C_ARCH_LOONGARCH64 /*line :616:29*/)
	case ArchM68K:
		return ( /*line :618:10*/*_Cvar_C_ARCH_M68K /*line :618:22*/)
	case ArchSH:
		return ( /*line :620:10*/*_Cvar_C_ARCH_SH /*line :620:20*/)
	case ArchSHEB:
		return ( /*line :622:10*/*_Cvar_C_ARCH_SHEB /*line :622:22*/)
	case ArchNative:
		return ( /*line :624:10*/*_Cvar_C_ARCH_NATIVE /*line :624:24*/)
	default:
		return 0x0
	}
}

// Only use with sanitized ops, no error handling
func (a ScmpCompareOp) toNative()  /*line :631:35*/_Ctype_int /*line :631:40*/ {
	switch a {
	case CompareNotEqual:
		return ( /*line :634:10*/*_Cvar_C_CMP_NE /*line :634:19*/)
	case CompareLess:
		return ( /*line :636:10*/*_Cvar_C_CMP_LT /*line :636:19*/)
	case CompareLessOrEqual:
		return ( /*line :638:10*/*_Cvar_C_CMP_LE /*line :638:19*/)
	case CompareEqual:
		return ( /*line :640:10*/*_Cvar_C_CMP_EQ /*line :640:19*/)
	case CompareGreaterEqual:
		return ( /*line :642:10*/*_Cvar_C_CMP_GE /*line :642:19*/)
	case CompareGreater:
		return ( /*line :644:10*/*_Cvar_C_CMP_GT /*line :644:19*/)
	case CompareMaskedEqual:
		return ( /*line :646:10*/*_Cvar_C_CMP_MASKED_EQ /*line :646:26*/)
	default:
		return 0x0
	}
}

func actionFromNative(a  /*line :652:25*/_Ctype_uint32_t /*line :652:35*/) (ScmpAction, error) {
	aTmp := a & 0xFFFF
	switch a & 0xFFFF0000 {
	case ( /*line :655:7*/*_Cvar_C_ACT_KILL_PROCESS /*line :655:26*/):
		return ActKillProcess, nil
	case ( /*line :657:7*/*_Cvar_C_ACT_KILL_THREAD /*line :657:25*/):
		return ActKillThread, nil
	case ( /*line :659:7*/*_Cvar_C_ACT_TRAP /*line :659:18*/):
		return ActTrap, nil
	case ( /*line :661:7*/*_Cvar_C_ACT_ERRNO /*line :661:19*/):
		return ActErrno.SetReturnCode(int16(aTmp)), nil
	case ( /*line :663:7*/*_Cvar_C_ACT_TRACE /*line :663:19*/):
		return ActTrace.SetReturnCode(int16(aTmp)), nil
	case ( /*line :665:7*/*_Cvar_C_ACT_LOG /*line :665:17*/):
		return ActLog, nil
	case ( /*line :667:7*/*_Cvar_C_ACT_ALLOW /*line :667:19*/):
		return ActAllow, nil
	case ( /*line :669:7*/*_Cvar_C_ACT_NOTIFY /*line :669:20*/):
		return ActNotify, nil
	default:
		return 0x0, fmt.Errorf("unrecognized action %#x", uint32(a))
	}
}

// Only use with sanitized actions, no error handling
func (a ScmpAction) toNative()  /*line :677:32*/_Ctype_uint32_t /*line :677:42*/ {
	switch a & 0xFFFF {
	case ActKillProcess:
		return ( /*line :680:10*/*_Cvar_C_ACT_KILL_PROCESS /*line :680:29*/)
	case ActKillThread:
		return ( /*line :682:10*/*_Cvar_C_ACT_KILL_THREAD /*line :682:28*/)
	case ActTrap:
		return ( /*line :684:10*/*_Cvar_C_ACT_TRAP /*line :684:21*/)
	case ActErrno:
		return ( /*line :686:10*/*_Cvar_C_ACT_ERRNO /*line :686:22*/) | ( /*line :686:27*/_Ctype_uint32_t /*line :686:37*/(a) >> 16)
	case ActTrace:
		return ( /*line :688:10*/*_Cvar_C_ACT_TRACE /*line :688:22*/) | ( /*line :688:27*/_Ctype_uint32_t /*line :688:37*/(a) >> 16)
	case ActLog:
		return ( /*line :690:10*/*_Cvar_C_ACT_LOG /*line :690:20*/)
	case ActAllow:
		return ( /*line :692:10*/*_Cvar_C_ACT_ALLOW /*line :692:22*/)
	case ActNotify:
		return ( /*line :694:10*/*_Cvar_C_ACT_NOTIFY /*line :694:23*/)
	default:
		return 0x0
	}
}

// Internal only, assumes safe attribute
func (a scmpFilterAttr) toNative() uint32 {
	switch a {
	case filterAttrActDefault:
		return uint32(( /*line :704:17*/*_Cvar_C_ATTRIBUTE_DEFAULT /*line :704:37*/))
	case filterAttrActBadArch:
		return uint32(( /*line :706:17*/*_Cvar_C_ATTRIBUTE_BADARCH /*line :706:37*/))
	case filterAttrNNP:
		return uint32(( /*line :708:17*/*_Cvar_C_ATTRIBUTE_NNP /*line :708:33*/))
	case filterAttrTsync:
		return uint32(( /*line :710:17*/*_Cvar_C_ATTRIBUTE_TSYNC /*line :710:35*/))
	case filterAttrLog:
		return uint32(( /*line :712:17*/*_Cvar_C_ATTRIBUTE_LOG /*line :712:33*/))
	case filterAttrSSB:
		return uint32(( /*line :714:17*/*_Cvar_C_ATTRIBUTE_SSB /*line :714:33*/))
	case filterAttrOptimize:
		return uint32(( /*line :716:17*/*_Cvar_C_ATTRIBUTE_OPTIMIZE /*line :716:38*/))
	case filterAttrRawRC:
		return uint32(( /*line :718:17*/*_Cvar_C_ATTRIBUTE_SYSRAWRC /*line :718:38*/))
	case filterAttrWaitKill:
		return uint32(( /*line :720:17*/*_Cvar_C_ATTRIBUTE_WAITKILL /*line :720:38*/))
	default:
		return 0x0
	}
}

func syscallFromNative(a  /*line :726:26*/_Ctype_int /*line :726:31*/) ScmpSyscall {
	return ScmpSyscall(a)
}

func notifReqFromNative(req * /*line :730:30*/_Ctype_struct_seccomp_notif /*line :730:52*/) (*ScmpNotifReq, error) {
	scmpArgs := make([]uint64, 6)
	for i := 0; i < len(scmpArgs); i++ {
		scmpArgs[i] = uint64(req.data.args[i])
	}

	arch, err := archFromNative(req.data.arch)
	if err != nil {
		return nil, err
	}

	scmpData := ScmpNotifData{
		Syscall:      syscallFromNative(req.data.nr),
		Arch:         arch,
		InstrPointer: uint64(req.data.instruction_pointer),
		Args:         scmpArgs,
	}

	scmpReq := &ScmpNotifReq{
		ID:    uint64(req.id),
		Pid:   uint32(req.pid),
		Flags: uint32(req.flags),
		Data:  scmpData,
	}

	return scmpReq, nil
}

func (scmpResp *ScmpNotifResp) toNative(resp * /*line :758:47*/_Ctype_struct_seccomp_notif_resp /*line :758:74*/) {
	resp.id =  /*line :759:12*/_Ctype___u64 /*line :759:19*/(scmpResp.ID)
	resp.val =  /*line :760:13*/_Ctype___s64 /*line :760:20*/(scmpResp.Val)
	resp.error = ( /*line :761:16*/_Ctype___s32 /*line :761:23*/(scmpResp.Error) * -1) // kernel requires a negated value
	resp.flags =  /*line :762:15*/_Ctype___u32 /*line :762:22*/(scmpResp.Flags)
}

// checkAPI checks that both the API level and the seccomp version is equal to
// or greater than the specified minLevel and major, minor, micro,
// respectively, and returns an error otherwise. Argument op is an arbitrary
// non-empty operation description, used as a part of the error message
// returned.
func checkAPI(op string, minLevel uint, major, minor, micro uint) error {
	// Ignore error from getAPI, as it returns level == 0 in case of error.
	level, _ := getAPI()
	if level >= minLevel {
		return checkVersion(op, major, minor, micro)
	}
	return &VersionError{
		op:     op,
		curAPI: level,
		minAPI: minLevel,
		major:  major,
		minor:  minor,
		micro:  micro,
	}
}

// Userspace Notification API
// Calls to C.seccomp_notify* hidden from seccomp.go

func notifSupported() error {
	return checkAPI("seccomp notification", 6, 2, 5, 0)
}

func (f *ScmpFilter) getNotifFd() (ScmpFd, error) {
	f.lock.Lock()
	defer f.lock.Unlock()

	if !f.valid {
		return -1, errBadFilter
	}
	if err := notifSupported(); err != nil {
		return -1, err
	}

	fd := func() _Ctype_int{ _cgo0 := /*line :804:28*/f.filterCtx; _cgoCheckPointer(_cgo0, nil); return /*line :804:40*/_Cfunc_seccomp_notify_fd(_cgo0); }()

	return ScmpFd(fd), nil
}

func notifReceive(fd ScmpFd) (*ScmpNotifReq, error) {
	var req * /*line :810:11*/_Ctype_struct_seccomp_notif /*line :810:33*/
	var resp * /*line :811:12*/_Ctype_struct_seccomp_notif_resp /*line :811:39*/

	if err := notifSupported(); err != nil {
		return nil, err
	}

	// we only use the request here; the response is unused
	if retCode := func() _Ctype_int{ _cgoBase0 := /*line :818:39*/&req; _cgo0 := _cgoBase0; _cgoBase1 := /*line :818:45*/&resp; _cgo1 := _cgoBase1; _cgoCheckPointer(_cgoBase0, 0 == 0); _cgoCheckPointer(_cgoBase1, 0 == 0); return /*line :818:51*/_Cfunc_seccomp_notify_alloc(_cgo0, _cgo1); }(); retCode != 0 {
		return nil, errRc(retCode)
	}
	defer ( /*line :821:8*/_Cfunc_seccomp_notify_free /*line :821:28*/)(req, resp)

	for {
		retCode, errno := ( /*line :824:21*/_C2func_seccomp_notify_receive /*line :824:44*/)( /*line :824:46*/_Ctype_int /*line :824:51*/(fd), req)
		if retCode == 0 {
			break
		}

		if errno == syscall.EINTR {
			continue
		}

		if errno == syscall.ENOENT {
			return nil, errno
		}

		return nil, errRc(retCode)
	}

	return notifReqFromNative(req)
}

func notifRespond(fd ScmpFd, scmpResp *ScmpNotifResp) error {
	var req * /*line :844:11*/_Ctype_struct_seccomp_notif /*line :844:33*/
	var resp * /*line :845:12*/_Ctype_struct_seccomp_notif_resp /*line :845:39*/

	if err := notifSupported(); err != nil {
		return err
	}

	// we only use the response here; the request is discarded
	if retCode := func() _Ctype_int{ _cgoBase0 := /*line :852:39*/&req; _cgo0 := _cgoBase0; _cgoBase1 := /*line :852:45*/&resp; _cgo1 := _cgoBase1; _cgoCheckPointer(_cgoBase0, 0 == 0); _cgoCheckPointer(_cgoBase1, 0 == 0); return /*line :852:51*/_Cfunc_seccomp_notify_alloc(_cgo0, _cgo1); }(); retCode != 0 {
		return errRc(retCode)
	}
	defer ( /*line :855:8*/_Cfunc_seccomp_notify_free /*line :855:28*/)(req, resp)

	scmpResp.toNative(resp)

	for {
		retCode, errno := ( /*line :860:21*/_C2func_seccomp_notify_respond /*line :860:44*/)( /*line :860:46*/_Ctype_int /*line :860:51*/(fd), resp)
		if retCode == 0 {
			break
		}

		if errno == syscall.EINTR {
			continue
		}

		if errno == syscall.ENOENT {
			return errno
		}

		return errRc(retCode)
	}

	return nil
}

func notifIDValid(fd ScmpFd, id uint64) error {
	if err := notifSupported(); err != nil {
		return err
	}

	for {
		retCode, errno := ( /*line :885:21*/_C2func_seccomp_notify_id_valid /*line :885:45*/)( /*line :885:47*/_Ctype_int /*line :885:52*/(fd),  /*line :885:58*/_Ctype_uint64_t /*line :885:68*/(id))
		if retCode == 0 {
			break
		}

		if errno == syscall.EINTR {
			continue
		}

		if errno == syscall.ENOENT {
			return errno
		}

		return errRc(retCode)
	}

	return nil
}
