Skip to content
CAI
Software that uses CAICheck a score

david942j/seccomp-tools

77.1

Strong · 5 October 2026

7.3k

lines of production code

Ruby

with C

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Seccomp-tools is a Ruby-based toolkit for analyzing, constructing, and auditing Linux seccomp BPF filters. It provides capabilities to disassemble raw bytecode into human-readable assembly, assemble high-level rules into bytecode, and emulate or symbolically execute filters to verify their behavior. The system also includes an audit engine to detect security weaknesses and a dumper to extract active filters from running processes, supporting multiple CPU architectures.

How it got here

2017 — Initial release and core feature development

17 changes.

This period established the seccomp-tools Ruby gem, introducing a modular CLI and core libraries for assembling, disassembling, and auditing seccomp BPF filters. Key features included a new audit engine, an emulator for filter simulation, and a C extension for process-level filter inspection via ptrace. The work also involved comprehensive test coverage and automated tooling for maintaining syscall data across multiple architectures.

2019–2026 — symbolic analysis and security auditing

8 changes.

This period focused on expanding seccomp-tools with a symbolic execution engine to analyze BPF filters across multiple architectures and an audit engine to detect security weaknesses. It also introduced an explain command to generate human-readable policy summaries and added shell completions for improved usability.

Features

Add BPF disassembler with syscall argument inference

The library now includes a new disassembler module that converts raw BPF bytecode into a human-readable format. This tool emulates the filter execution to track register states, allowing it to infer and display syscall names and argument positions as comments within the disassembly output. Users can control the output verbosity via options to show or hide raw BPF fields and to toggle the inclusion of inferred argument details.

lib/seccomp-tools/disasm · high confidence

Add Linux-specific ptrace extension for seccomp filter inspection

The \ext/ptrace\ directory now contains a C extension (\ptrace.c\) and build script (\extconf.rb\) that wraps Linux ptrace syscalls for the \SeccompTools::Ptrace\ Ruby module. This addition enables inspecting seccomp BPF filters of existing processes via \seccomp\_get\_filter\ and provides low-level utilities (such as \peekuser\, \attach\_and\_wait\, and \detach\) required for advanced process tracing and child-process following on Linux. The extension is compiled only on Linux; on other platforms it produces an empty object to ensure installation succeeds without errors.

ext · high confidence

Add seccomp-tools CLI executable

A new executable script \bin/seccomp-tools\ has been added to the project. This script serves as the entry point for the command-line interface, invoking the \SeccompTools::CLI.work\ method with command-line arguments.

bin · high confidence

Add shell completion for bash, zsh, and fish

Users of bash, zsh, and fish shells can now enable tab-completion for seccomp-tools commands and arguments. The completions cover subcommands (asm, audit, disasm, dump, emu, explain, completion) and their specific flags (such as --arch, --format, --output, --pid, etc.), providing context-aware suggestions for options and file paths.

completions · high confidence

Added syscall number mappings for aarch64, amd64, i386, riscv64, and s390x

The seccomp-tools library now includes syscall number constant files for five additional architectures: aarch64, amd64, i386, riscv64, and s390x. These new files in \lib/seccomp-tools/consts/sys\_nr\ allow the tool to correctly identify and disassemble syscalls on these platforms, extending support beyond previously available architectures.

_lib/seccomp-tools/consts/sys\nr · high confidence

Automated generation of syscall tables and documentation

New Rake tasks have been added to automate the maintenance of seccomp-tools' syscall data and documentation. The \sys\_nr\ task fetches syscall number tables directly from the upstream Linux kernel source (defaulting to v7.1, configurable via \LINUX\_VERSION\) and regenerates the architecture-specific constant files, supporting amd64, i386, aarch64, riscv64, and s390x, including x32 ABI aliases. The \sys\_arg\ task parses Linux syscall prototypes to regenerate argument name constants. Additionally, the \readme\ task allows regenerating the README from a template by executing embedded shell commands, with safeguards to ensure it only runs on amd64 and fails loudly if commands produce no output or errors.

tasks · high confidence

CLI restructured into modular subcommands with new asm, audit, and completion capabilities

The command-line interface has been refactored from a single monolithic handler into a modular architecture with a shared base class and distinct subcommand classes. This introduces new capabilities: the \asm\ command now assembles BPF bytecode into C arrays, source code, or assembly; the \audit\ command assesses filters for security weaknesses and escape routes; and the \completion\ command generates shell completion scripts for bash, zsh, and fish. Existing commands (\disasm\, \dump\, \emu\, \explain\) have been extracted into their own handlers, sharing common input parsing logic via the \FilterInput\ module and output handling via the \Base\ class, which also enforces architecture detection and file output serialization.

lib/seccomp-tools/cli · high confidence

Initial release of SeccompTools library

The library is now available as a Ruby gem, providing a toolkit for working with seccomp BPF filters. Users can compile assembly into raw BPF using Asm.asm, disassemble raw BPF back into readable assembly with Disasm.disasm, capture installed filters via Dumper.dump, and test filters against hypothetical syscalls using the Emulator.

lib · high confidence

New explain command to summarize seccomp filters as per-action policies

The \lib/seccomp-tools/explain\ directory introduces a new \explain\ command that analyzes a compiled seccomp filter and outputs a human-readable summary of its policy. This summary groups actions (such as ALLOW, KILL, or ERRNO) by architecture and specific conditions, making it easier to understand what a filter actually does. The implementation includes \Analysis\ to determine reachable paths and architecture splits, \PathFacts\ to extract syscall numbers and argument constraints, \QwordFusion\ to correctly reassemble 64-bit argument checks from 32-bit word operations, and a \Renderer\ to format these conditions into readable C-like expressions.

lib/seccomp-tools/explain · high confidence

New seccomp assembly language compiler

Users can now write seccomp BPF rules using a human-readable assembly syntax (e.g., \A == read ? ok : next\) instead of manually constructing BPF instructions. This new compiler, located in \lib/seccomp-tools/asm\, parses assembly source code, resolves labels and jump targets, and emits raw BPF bytecode. It supports architecture-specific syscall names (e.g., \x86\_64.read\), arithmetic operations, conditional jumps, and scratch memory access, providing a higher-level interface for defining seccomp filters.

lib/seccomp-tools/asm · high confidence

New seccomp filter audit engine to detect security weaknesses

The \lib/seccomp-tools/audit\ directory introduces a new audit engine that scans seccomp filters for common security weaknesses. It identifies issues such as permissive default actions (allowlists), dangerous syscalls being reachable, equivalent syscall gaps (e.g., \execve\ blocked but \execveat\ allowed), and the ability to read/write files (ORW chain). It also flags filters that do not validate the architecture, potentially allowing bypasses via different ABIs, and includes an architecture-specific check for the amd64 x32 ABI quirk. The engine provides findings with severity levels, details, and remediation advice, rendered in a human-readable report or JSON format.

lib/seccomp-tools/audit · high confidence

New symbolic execution engine for BPF filters

Seccomp-tools now includes a symbolic execution engine (SeccompTools::Symbolic::Executor) that analyzes classic BPF programs by exploring all possible execution paths simultaneously rather than running them with concrete inputs. This engine tracks symbolic values (Expr), path constraints (Constraint), and machine state (State) to produce a complete, input-independent description of a filter's behavior, including the specific conditions under which each return value is reached. It supports pruning infeasible branches and handles standard BPF operations like register manipulation, memory access, and arithmetic.

lib/seccomp-tools/symbolic · high confidence

Seccomp-tools 1.7.1 release with audit engine and emulator

Seccomp-tools has been updated to version 1.7.1, introducing a new Audit engine that scans seccomp filters for weaknesses and escape routes, and an Emulator that simulates filter execution against hypothetical syscalls. The release also adds support for dumping seccomp filters from existing processes via PTRACE\_SECCOMP\_GET\_FILTER, improves disassembly with syscall argument display, and adds architecture support for RISC-V 64-bit (riscv64).

lib/seccomp-tools · high confidence

Behavioural changes

Refactored BPF instruction disassembly into a class-based hierarchy

The \lib/seccomp-tools/instruction\ module has been restructured from a procedural implementation into an object-oriented hierarchy. A new \Base\ class defines the interface for decompilation, symbolic representation, and state branching, while specific instruction types (ALU, JMP, LD, LDX, RET, ST, STX, MISC) are now distinct classes. This change improves the maintainability and clarity of the disassembler logic, allowing each BPF instruction class to encapsulate its own decompilation and state-transition rules.

lib/seccomp-tools/instruction · high confidence

Syscall argument names updated to Linux 7.1

The syscall argument names used in disassembly output have been updated to match the Linux 7.1 kernel definitions. This ensures that the tool displays accurate and current argument names for system calls, improving the clarity and correctness of the disassembled output for users analyzing system call behavior.

lib/seccomp-tools/consts · high confidence

Test coverage

Added seccomp test fixtures and build infrastructure; Added test coverage for audit, policy, dumper, emulator, and explain components; Added test coverage for new CLI subcommands and options; Added test coverage for the new symbolic execution engine; Added test fixtures and generator for seccomp assembly and BPF instructions; Added test suite for the disassembler; Added test suite for the new Racc-based assembler; Added tests for the explain command components.

Dependencies

Initial release of seccomp-tools gem

This change introduces the initial release of the seccomp-tools gem, providing tools to analyze seccomp rules. The package includes the core library, a C extension for ptrace support, and shell completions for bash, zsh, and fish. It requires Ruby 3.1 or higher and bundles dependencies including logger and racc, along with development tools like RSpec, RuboCop, and YARD.

(dependencies) · high confidence

Housekeeping

Initial project scaffolding and documentation

This change establishes the project's foundational structure by adding essential configuration and documentation files. It introduces a \.gitignore\ to exclude build artifacts and IDE files, an \.rspec\ configuration for test execution, and a \.rubocop.yml\ to enforce code style standards. Additionally, it provides a comprehensive \CHANGELOG.md\ documenting the tool's history from v0.1.0 through the unreleased version, and updates the \README.md\ with detailed usage examples for commands like \dump\, \disasm\, \asm\, \emu\, \explain\, and \audit\, along with shell completion instructions.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 78 → 77 (-0.4)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 100 → 88 (-12.4)
  • Maturity 69 → 69 (+0.0)
  • Readiness 77 → 78 (+1.7)
  • Security 88 → 91 (+2.3)

Resolved (4)

  • Duplicate functionality: BPF#disasm appears to be a convenience wrapper around the standalone Disasm.disasm method. The BPF instance already holds raw and arch, making the standalone method redundant for users who have a BPF object.
  • Hotspot: lib/seccomp-tools/asm/scanner.rb (lib/seccomp-tools/asm/scanner.rb)
  • Inconsistent naming and argument structure for similar operations. dump takes a generic args object (likely a Syscall or similar), while dump_by_pid takes a raw pid. This splits the dumping logic between a high-level object method and a low-level procedural method, confusing the API surface.
  • Redundant methods with identical names but different mutability semantics (bang vs non-bang) without clear distinction in signature or documentation context. In Ruby, validate! typically raises on error while validate returns boolean, but having both exposed on the same class without distinct behavior in the signature suggests duplication or confusion.

New (3)

  • Duplicate functionality across types. SeccompTools.BPF (an instruction object) has a disasm method, while SeccompTools.Disasm (a utility class) also has a disasm method. It is unclear if BPF.disasm delegates to Disasm.disasm or implements its own logic. This creates two entry points for the same operation.
  • Projects may be oversized for their cohesion
  • Redundant methods with ambiguous distinction. Having both validate! and validate suggests a mutation vs. read distinction or a strict vs. lenient mode, but without documentation, it is unclear if they perform different logic or if one is just an alias. In Ruby, ! often implies mutation, but Scanner properties are not shown as mutable in a way that suggests validate! modifies state differently than validate.

Changes since last survey

  • 3 commits — 3 feature/other, 0 fixes

By area

  • (root) — 2 commits
  • spec/data — 1 commit

Notable commits

  • change: Drop facts a pinned value already implies from explain rules (#406)
  • change: Place gen.rb's encoding comment where Ruby reads it (#405)
  • change: Prune infeasible branches during the symbolic walk (#404)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

david942j/seccomp-tools was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 5 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 8fc771a98837d9e21afde75a8adffc073b2ddb87 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-3f806db95659.