Skip to main content

seccompy

CI CodeQL OpenSSF Scorecard PyPI License: 0BSD

Dependency-free Python bindings for Linux seccomp-BPF syscall filtering. Filters are assembled in pure Python from symbolic instructions, checked against the native architecture to block ABI confusion, and installed through seccomp(2) with prctl(PR_SET_NO_NEW_PRIVS), so no compiler, libbpf or privileges are needed.

Requires Python 3.10+ and Linux 3.17+ on x86_64 or aarch64.

Install

pip install seccompy

Usage

import errno

from seccompy import Action, Filter

filt = Filter(default=Action.ALLOW)
filt.errno("openat", errno.EACCES)
filt.kill("ptrace")
filt.log("mount")
filt.load()

# openat now fails with EACCES for this thread and its children,
# ptrace kills the process, mount is allowed but logged

Rules can also match on 64-bit syscall arguments:

filt.errno("write", errno.EIO, args={0: 1})  # deny write() on fd 1 only

Beyond equality, ArgCmp conditions support unsigned comparisons and masked equality over the whole 64-bit argument:

import os

from seccompy import ArgCmp, CmpOp

filt.errno("write", errno.EIO, args=[ArgCmp(0, CmpOp.GT, 4096)])
# deny openat(O_RDONLY): masked equality is needed since O_RDONLY is 0
filt.errno(
    "openat", errno.EACCES, args=[ArgCmp(2, CmpOp.MASKED_EQ, 0, mask=os.O_ACCMODE)]
)

With FilterFlag.NEW_LISTENER, load() returns a notification fd wrapped in seccompy.notify.Listener, and Filter.notify() rules delegate matching syscalls to a supervisor process (kernel 5.0+):

import ctypes
import errno
import os

from seccompy import Action, Filter, FilterFlag, notify

filt = Filter(default=Action.ALLOW, flags=FilterFlag.NEW_LISTENER)
filt.notify("mount")
listener = filt.load()
assert listener is not None

libc = ctypes.CDLL(None, use_errno=True)
pid = os.fork()
if pid == 0:  # target: inherits the filter and the listener fd
    libc.mount(None, None, None, 0, None)  # blocks until answered
    os._exit(0)

req = listener.recv()  # struct seccomp_notif: id, pid, args
listener.respond(req.id, error=errno.EPERM)  # spoof a failure
# or: listener.respond(req.id, flags=notify.RespFlag.CONTINUE)
os.waitpid(pid, 0)
listener.close()

The listener fd is pollable and also supports valid(), addfd() for fd injection and set_flags(). notify.pidfd_open/pidfd_getfd cover the supervisor-in-another-process case. The supervisor process must never call a notified syscall itself, or it blocks on its own listener. See seccomp_unotify(2) for the protocol and its caveats.

seccompy.supported() reports whether the running kernel can install filters, seccompy.action_supported(Action.X) probes a return action and seccompy.flag_supported(FilterFlag.X) probes a load flag. The compiled BPF program is available as filt.program for inspection, and seccompy.testing.probe() runs a callable under a filter in a forked child to preview enforcement.

Documentation

License: 0BSD.

Metadata

Release files for seccompy 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for seccompy 0.2.0
File Size Uploaded
seccompy-0.2.0.tar.gz 115.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for seccompy 0.2.0
File Interpreter ABI Platform
seccompy-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 141.7 kB

Release files / seccompy-0.2.0.tar.gz

Download URL seccompy-0.2.0.tar.gz
Size 115.7 kB
Tags Source
SHA-256 checksum
How to use checksums
9663248a433bb78cfb7cfdbb6fe498ddae23ff2bdc1b4cd9d2777ee1148924d9
BLAKE2b-256 checksum
How to use checksums
74a9eaab3f46648170644d6ff0fcb8fe70fc1b782f693ae13b8fb301877360f1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release files / seccompy-0.2.0-py3-none-any.whl

Download URL seccompy-0.2.0-py3-none-any.whl
Size 26.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
993e14f0175c8c05c11b44e6333a3e40e5e0924b4d7c53154322b1797db7a375
BLAKE2b-256 checksum
How to use checksums
d50104453465374492bbceb941317c44e55c27465218754a8a79a319fa643b9e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page