Skip to main content

seccompy

CI CodeQL OpenSSF Scorecard PyPI License: 0BSD

Dependency-free Python bindings for Linux seccomp-BPF syscall filtering. Filters are assembled in pure Python from symbolic instructions, checked against the native architecture to block ABI confusion, and installed through seccomp(2) with prctl(PR_SET_NO_NEW_PRIVS), so no compiler, libbpf or privileges are needed.

Requires Python 3.10+ and Linux 3.17+ on x86_64 or aarch64.

Install

pip install seccompy

Usage

import errno

from seccompy import Action, Filter

filt = Filter(default=Action.ALLOW)
filt.errno("openat", errno.EACCES)
filt.kill("ptrace")
filt.log("mount")
filt.load()

# openat now fails with EACCES for this thread and its children,
# ptrace kills the process, mount is allowed but logged

Rules can also match on 64-bit syscall arguments:

filt.errno("write", errno.EIO, args={0: 1})  # deny write() on fd 1 only

seccompy.supported() reports whether the running kernel can install filters, seccompy.action_supported(Action.X) probes a return action and seccompy.flag_supported(FilterFlag.X) probes a load flag. The compiled BPF program is available as filt.program for inspection, and seccompy.testing.probe() runs a callable under a filter in a forked child to preview enforcement.

Documentation

License: 0BSD.

Metadata

Release files for seccompy 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for seccompy 0.1.0
File Size Uploaded
seccompy-0.1.0.tar.gz 86.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for seccompy 0.1.0
File Interpreter ABI Platform
seccompy-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 104.5 kB

Release files / seccompy-0.1.0.tar.gz

Download URL seccompy-0.1.0.tar.gz
Size 86.3 kB
Tags Source
SHA-256 checksum
How to use checksums
4e6d397ec4f7e4d650d1d8af4ed3600ab1ea639c886e4197f1daecbfb9c7ed11
BLAKE2b-256 checksum
How to use checksums
c3cb850b1f9b155fd7b3a22b7092e5a3681564bb204631caa775142feb8b446a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release files / seccompy-0.1.0-py3-none-any.whl

Download URL seccompy-0.1.0-py3-none-any.whl
Size 18.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
000c016f5863e3ade615b63434cfa1cb6f2fd5fbc77afede3d6f352242f0917e
BLAKE2b-256 checksum
How to use checksums
df309d02bee6c15122697b8077811fd4a7a714849ca213bf88b491343a2f2c6b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.0

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page