device->major = -1;
device->minor = -1;
device->global_rule = device->allow
- ? LXC_BPF_DEVICE_CGROUP_BLACKLIST
- : LXC_BPF_DEVICE_CGROUP_WHITELIST;
+ ? LXC_BPF_DEVICE_CGROUP_DENYLIST
+ : LXC_BPF_DEVICE_CGROUP_ALLOWLIST;
device->allow = -1;
return 0;
}
/*
* By default a whitelist is used unless the user tells us otherwise.
*/
- prog->device_list_type = LXC_BPF_DEVICE_CGROUP_WHITELIST;
+ prog->device_list_type = LXC_BPF_DEVICE_CGROUP_ALLOWLIST;
return move_ptr(prog);
}
return ret_set_errno(-1, EINVAL);
TRACE("Implementing %s bpf device cgroup program",
- prog->device_list_type == LXC_BPF_DEVICE_CGROUP_BLACKLIST
+ prog->device_list_type == LXC_BPF_DEVICE_CGROUP_DENYLIST
? "blacklist"
: "whitelist");
if (cur->global_rule > LXC_BPF_DEVICE_CGROUP_LOCAL_RULE &&
device->global_rule > LXC_BPF_DEVICE_CGROUP_LOCAL_RULE) {
TRACE("Switched from %s to %s",
- cur->global_rule == LXC_BPF_DEVICE_CGROUP_WHITELIST
+ cur->global_rule == LXC_BPF_DEVICE_CGROUP_ALLOWLIST
? "whitelist"
: "blacklist",
- device->global_rule == LXC_BPF_DEVICE_CGROUP_WHITELIST
+ device->global_rule == LXC_BPF_DEVICE_CGROUP_ALLOWLIST
? "whitelist"
: "blacklist");
cur->global_rule = device->global_rule;
enum {
LXC_BPF_DEVICE_CGROUP_LOCAL_RULE = -1,
- LXC_BPF_DEVICE_CGROUP_WHITELIST = 0,
- LXC_BPF_DEVICE_CGROUP_BLACKLIST = 1,
+ LXC_BPF_DEVICE_CGROUP_ALLOWLIST = 0,
+ LXC_BPF_DEVICE_CGROUP_DENYLIST = 1,
};
struct device_item {
int allow;
/*
* LXC_BPF_DEVICE_CGROUP_LOCAL_RULE -> no global rule
- * LXC_BPF_DEVICE_CGROUP_WHITELIST -> whitelist (deny all)
- * LXC_BPF_DEVICE_CGROUP_BLACKLIST -> blacklist (allow all)
+ * LXC_BPF_DEVICE_CGROUP_ALLOWLIST -> allowlist (deny all)
+ * LXC_BPF_DEVICE_CGROUP_DENYLIST -> denylist (allow all)
*/
int global_rule;
};