Sitelet https://github.com/ceccomp/ceccomp
Skip to content
ceccompPublic

About

C reimplementation of seccomp-tools with advanced features

Topics

Resources

Contributing

Security policy

Stars

82 stars

Watchers

3 watching

Forks

Repository files navigation

Ceccomp ceccomp icon

→ Read this in 简体中文 ←

C reimplementation of seccomp-tools with advanced features. We basically pronounce ceccomp in "C-comp" (/siːˈkɒmp/) or "seccomp" (/ˈsɛk.kɒmp/).

Features

  • ⚙️ Robust assembler and disassembler
  • 📘 Complete documentation
  • 🔢 Various architecture support powered by libseccomp
  • 🌐 Multi-language support
  • 🪶 Minimum build dependencies for core binary
  • 🖌️ Enhanced syntax highlighting
  • 💯 Informational error messages
  • 🐚 Powerful Zshell completion
  • 🚫 Pure C without LLM-generated garbage
  • 🐝 Advanced function powered by eBPF

Doc & Screenshots

English Version | 中文文档

Install

Important

This software requires features from Linux, so kernels other than Linux are not supported.

  • Arch Linux users:

    ceccomp is available in official extra repo now: Arch Manjaro Stable

  • Debian, Ubuntu or Kali users:

    ceccomp is available with apt now if you are using distros below:

    Debian testing Debian unstable Ubuntu 26.04 Ubuntu 26.10 Kali Linux

  • NixOS users:

    @tesuji helps us submit a PR at NixOS, but it's blocked as currently... If you like our software, please 👍 in NixOS/nixpkgs#462592 to help ceccomp into nixpkgs!

  • Other Linux distros:

    Sorry, you may need to install ceccomp manually. Please follow instructions below.

Build

  • Stable installation:

    Clone the whole repo, then run ./configure. Dependencies will be detected automatically, please keep an eye on the output since components are automatically disabled if not available. For documentation generation, you need asciidoctor. For multi-language support, you need gettext package. For eBPF support, you need libbpf, bpftool and a bpf C compiler, clang with llvm package or gcc-bpf>=15. You could use --without-doc, --without-i18n and --without-ebpf to disable them explicitly. Please run ./configure --help for more details.

    git clone https://github.com/ceccomp/ceccomp.git
    cd Ceccomp
    ./configure
    ./configure # run this again if Makefile is not generated
    make
    make install # install at /usr/local/bin
  • Testing installation:

    Clone the whole repo, and then run ./configure --devmode.

    git clone https://github.com/ceccomp/ceccomp.git
    cd Ceccomp
    ./configure --devmode
    make

Note

To build this project or enable some features, the lowest denpendency version baselines are:

  • Linux >= 5.3, libseccomp >= 2.5.0 (functions excluding capture)
  • Linux >= 5.11, libbpf >= 0.6.0 (global capture, only x86_64 guaranteed)
  • Linux >= 6.2, libbpf >= 0.6.0 (capture pid)

Run Test

Run configure and make, then invoke pytest test from repo root. Trace pid case will be skipped if no CAP_SYS_ADMIN. If you find some checks failed, please submit an issue to report your case.

To run the test, you need 2 extra packages: pkgconf (required by pkg-config) and python-pytest (required by pytest).

CheatSheet

image

Credits

  • libseccomp: The library to support syscall lookups
  • libbpf: The library to support eBPF functions
  • seccomp-tools: The tool in Ruby inspires us to write ceccomp
  • Bootswatch: Provides awesome css for html doc under MIT
  • Linux kernel: Port some bpf checks
  • Verstable: High-performance hash table implementation in C
  • a5hash: High-performance hash implementation for short strings in C

Any Issue or PR are welcome! ❤️ Please read CONTRIBUTING.md for details.

License

Copyright (C) 2025-present, ceccomp contributors, distributed under GNU General Public License v3.0 or Later

About

C reimplementation of seccomp-tools with advanced features

Topics

Resources

Contributing

Security policy

Stars

82 stars

Watchers

3 watching

Forks

Releases

Contributors

Languages