Example #1
0
void
systrace_initcb(void)
{
	struct systrace_alias *alias;
	struct intercept_translate *tl;

	X(intercept_init());

	X(intercept_register_gencb(gen_cb, NULL));	
 
	X(intercept_register_sccb("linux", "chown", trans_cb, NULL));
	intercept_register_transfn("linux", "chown", 0);
	intercept_register_translation("linux", "chown", 1, &ic_uidt);
	intercept_register_translation("linux", "chown", 2, &ic_gidt);
	X(intercept_register_sccb("linux", "fchown", trans_cb, NULL));
	intercept_register_translation("linux", "fchown", 0, &ic_fdt);
	intercept_register_translation("linux", "fchown", 1, &ic_uidt);
	intercept_register_translation("linux", "fchown", 2, &ic_gidt);

	X(intercept_register_sccb("linux", "fchmod", trans_cb, NULL));
	intercept_register_translation("linux", "fchmod", 0, &ic_fdt);
	intercept_register_translation("linux", "fchmod", 1, &ic_modeflags);

	X(intercept_register_sccb("linux", "chdir", trans_cb, NULL));
	intercept_register_transfn("linux", "chdir", 0);
	X(intercept_register_sccb("linux", "chroot", trans_cb, NULL));
	intercept_register_transfn("linux", "chroot", 0);

	X(intercept_register_sccb("linux", "setuid", trans_cb, NULL));
	intercept_register_translation("linux", "setuid", 0, &ic_uidt);
	intercept_register_translation("linux", "setuid", 0, &ic_uname);

	X(intercept_register_sccb("linux", "setgid", trans_cb, NULL));
	intercept_register_translation("linux", "setgid", 0, &ic_gidt);

	X(intercept_register_sccb("linux", "open", trans_cb, NULL));
	tl = intercept_register_translink("linux", "open", 0);
	intercept_register_translation("linux", "open", 1, &ic_linux_oflags);
	alias = systrace_new_alias("linux", "open", "linux", "fswrite");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("linux", "stat", trans_cb, NULL));
	tl = intercept_register_translink("linux", "stat", 0);
	alias = systrace_new_alias("linux", "stat", "linux", "fsread");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "stat64", trans_cb, NULL));
	tl = intercept_register_translink("linux", "stat64", 0);
	alias = systrace_new_alias("linux", "stat64", "linux", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("linux", "lstat", trans_cb, NULL));
	tl = intercept_register_translink("linux", "lstat", 0);
	alias = systrace_new_alias("linux", "lstat", "linux", "fsread");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "lstat64", trans_cb, NULL));
	tl = intercept_register_translink("linux", "lstat64", 0);
	alias = systrace_new_alias("linux", "lstat64", "linux", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("linux", "execve", trans_cb, NULL));
	intercept_register_translink("linux", "execve", 0);
	X(intercept_register_sccb("linux", "access", trans_cb, NULL));
	tl = intercept_register_translink("linux", "access", 0);
	alias = systrace_new_alias("linux", "access", "linux", "fsread");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "symlink", trans_cb, NULL));
	intercept_register_transstring("linux", "symlink", 0);
	intercept_register_translink("linux", "symlink", 1);
	X(intercept_register_sccb("linux", "link", trans_cb, NULL));
	intercept_register_translink("linux", "link", 0);
	intercept_register_translink("linux", "link", 1);
	X(intercept_register_sccb("linux", "readlink", trans_cb, NULL));
	tl = intercept_register_translink("linux", "readlink", 0);
	alias = systrace_new_alias("linux", "readlink", "linux", "fsread");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "rename", trans_cb, NULL));
	intercept_register_translation("linux", "rename", 0,
	    &ic_translate_unlinkname);
	intercept_register_translink("linux", "rename", 1);
	X(intercept_register_sccb("linux", "mkdir", trans_cb, NULL));
	tl = intercept_register_translation("linux", "mkdir", 0,
	    &ic_translate_unlinkname);
	alias = systrace_new_alias("linux", "mkdir", "linux", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "rmdir", trans_cb, NULL));
	tl = intercept_register_translink("linux", "rmdir", 0);
	alias = systrace_new_alias("linux", "rmdir", "linux", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "unlink", trans_cb, NULL));
	tl = intercept_register_translink("linux", "unlink", 0);
	alias = systrace_new_alias("linux", "unlink", "linux", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "chmod", trans_cb, NULL));
	intercept_register_translink("linux", "chmod", 0);
	intercept_register_translation("linux", "chmod", 1, &ic_modeflags);

 	X(intercept_register_sccb("linux", "fcntl", trans_cb, NULL));
 	intercept_register_translation("linux", "fcntl", 1, &ic_fcntlcmd);

	/* i386 specific translation */
	X(intercept_register_sccb("linux", "old_mmap", trans_cb, NULL));
	intercept_register_translation("linux", "old_mmap", 0,
	    &ic_linux_memprot);

	X(intercept_register_sccb("linux", "mmap2", trans_cb, NULL));
	intercept_register_translation("linux", "mmap2", 2, &ic_memprot);
	X(intercept_register_sccb("linux", "mprotect", trans_cb, NULL));
	intercept_register_translation("linux", "mprotect", 2, &ic_memprot);

	X(intercept_register_sccb("linux", "mknod", trans_cb, NULL));
	intercept_register_translation("linux", "mknod", 0,
	    &ic_translate_unlinkname);
	intercept_register_translation("linux", "mknod", 1, &ic_modeflags);

	X(intercept_register_sccb("linux", "socketcall", trans_cb, NULL));
 	tl = intercept_register_translation("linux", "socketcall", 1, &ic_linux_socket_sockdom);
	alias = systrace_new_alias("linux", "socketcall", "linux", "_socketcall");
	systrace_alias_add_trans(alias, tl);
 	tl = intercept_register_translation("linux", "socketcall", 1, &ic_linux_socket_socktype);
	systrace_alias_add_trans(alias, tl);
 	tl = intercept_register_translation("linux", "socketcall", 1, &ic_linux_connect_sockaddr);
	systrace_alias_add_trans(alias, tl);
 	tl = intercept_register_translation("linux", "socketcall", 1, &ic_linux_sendto_sockaddr);
	systrace_alias_add_trans(alias, tl);
 	tl = intercept_register_translation("linux", "socketcall", 1, &ic_linux_sendmsg_sockaddr);
	systrace_alias_add_trans(alias, tl);
 	tl = intercept_register_translation("linux", "socketcall", 1, &ic_linux_bind_sockaddr);
	systrace_alias_add_trans(alias, tl);
 	tl = intercept_register_translation("linux", "socketcall", 0, &ic_linux_socketcall_catchall);
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("linux", "kill", trans_cb, NULL));
	intercept_register_translation("linux", "kill", 0, &ic_pidname);
	intercept_register_translation("linux", "kill", 1, &ic_signame);

#ifdef PTRACE_LINUX64
	X(intercept_register_sccb("linux64", "chown", trans_cb, NULL));
	intercept_register_transfn("linux64", "chown", 0);
	intercept_register_translation("linux64", "chown", 1, &ic_uidt);
	intercept_register_translation("linux64", "chown", 2, &ic_gidt);
	X(intercept_register_sccb("linux64", "fchown", trans_cb, NULL));
	intercept_register_translation("linux64", "fchown", 0, &ic_fdt);
	intercept_register_translation("linux64", "fchown", 1, &ic_uidt);
	intercept_register_translation("linux64", "fchown", 2, &ic_gidt);

	X(intercept_register_sccb("linux64", "fchmod", trans_cb, NULL));
	intercept_register_translation("linux64", "fchmod", 0, &ic_fdt);
	intercept_register_translation("linux64", "fchmod", 1, &ic_modeflags);

	X(intercept_register_sccb("linux64", "chdir", trans_cb, NULL));
	intercept_register_transfn("linux64", "chdir", 0);
	X(intercept_register_sccb("linux64", "chroot", trans_cb, NULL));
	intercept_register_transfn("linux64", "chroot", 0);

	X(intercept_register_sccb("linux64", "setuid", trans_cb, NULL));
	intercept_register_translation("linux64", "setuid", 0, &ic_uidt);
	intercept_register_translation("linux64", "setuid", 0, &ic_uname);

	X(intercept_register_sccb("linux64", "setgid", trans_cb, NULL));
	intercept_register_translation("linux64", "setgid", 0, &ic_gidt);

	X(intercept_register_sccb("linux64", "open", trans_cb, NULL));
	tl = intercept_register_translink("linux64", "open", 0);
	intercept_register_translation("linux64", "open", 1, &ic_linux_oflags);
	alias = systrace_new_alias("linux64", "open", "linux64", "fswrite");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("linux64", "stat", trans_cb, NULL));
	tl = intercept_register_translink("linux64", "stat", 0);
	alias = systrace_new_alias("linux64", "stat", "linux64", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("linux64", "lstat", trans_cb, NULL));
	tl = intercept_register_translink("linux64", "lstat", 0);
	alias = systrace_new_alias("linux64", "lstat", "linux64", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("linux64", "execve", trans_cb, NULL));
	intercept_register_translink("linux64", "execve", 0);
	X(intercept_register_sccb("linux64", "access", trans_cb, NULL));
	tl = intercept_register_translink("linux64", "access", 0);
	alias = systrace_new_alias("linux64", "access", "linux64", "fsread");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux64", "symlink", trans_cb, NULL));
	intercept_register_transstring("linux64", "symlink", 0);
	intercept_register_translink("linux64", "symlink", 1);
	X(intercept_register_sccb("linux64", "link", trans_cb, NULL));
	intercept_register_translink("linux64", "link", 0);
	intercept_register_translink("linux64", "link", 1);
	X(intercept_register_sccb("linux64", "readlink", trans_cb, NULL));
	tl = intercept_register_translink("linux64", "readlink", 0);
	alias = systrace_new_alias("linux64", "readlink", "linux64", "fsread");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux64", "rename", trans_cb, NULL));
	intercept_register_translation("linux64", "rename", 0,
	    &ic_translate_unlinkname);
	intercept_register_translink("linux64", "rename", 1);
	X(intercept_register_sccb("linux64", "mkdir", trans_cb, NULL));
	tl = intercept_register_translation("linux64", "mkdir", 0,
	    &ic_translate_unlinkname);
	alias = systrace_new_alias("linux64", "mkdir", "linux64", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux64", "rmdir", trans_cb, NULL));
	tl = intercept_register_translink("linux64", "rmdir", 0);
	alias = systrace_new_alias("linux64", "rmdir", "linux64", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux64", "unlink", trans_cb, NULL));
	tl = intercept_register_translink("linux64", "unlink", 0);
	alias = systrace_new_alias("linux64", "unlink", "linux64", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux64", "chmod", trans_cb, NULL));
	intercept_register_translink("linux64", "chmod", 0);
	intercept_register_translation("linux64", "chmod", 1, &ic_modeflags);

	X(intercept_register_sccb("linux64", "fcntl", trans_cb, NULL));
	intercept_register_translation("linux64", "fcntl", 1, &ic_fcntlcmd);

	X(intercept_register_sccb("linux64", "mmap", trans_cb, NULL));
	intercept_register_translation("linux64", "mmap", 2, &ic_memprot);
	X(intercept_register_sccb("linux64", "mprotect", trans_cb, NULL));
	intercept_register_translation("linux64", "mprotect", 2, &ic_memprot);

	X(intercept_register_sccb("linux64", "mknod", trans_cb, NULL));
	intercept_register_translation("linux64", "mknod", 0,
	    &ic_translate_unlinkname);
	intercept_register_translation("linux64", "mknod", 1, &ic_modeflags);
	
	X(intercept_register_sccb("linux64", "sendmsg", trans_cb, NULL));
	intercept_register_translation("linux64", "sendmsg", 1,
	    &ic_translate_sendmsg);
	X(intercept_register_sccb("linux64", "connect", trans_cb, NULL));
	intercept_register_translation("linux64", "connect", 1,
	    &ic_translate_connect);
	X(intercept_register_sccb("linux64", "sendto", trans_cb, NULL));
	intercept_register_translation("linux64", "sendto", 4,
	    &ic_translate_connect);
	X(intercept_register_sccb("linux64", "bind", trans_cb, NULL));
	intercept_register_translation("linux64", "bind", 1,
	    &ic_translate_connect);

#endif  /* PTRACE_LINUX64 */

	X(intercept_register_execcb(execres_cb, NULL));
	X(intercept_register_pfreecb(policyfree_cb, NULL));
}
Example #2
0
void
systrace_initcb(void)
{
	struct systrace_alias *alias;
	struct intercept_translate *tl;

	X(intercept_init());

	X(intercept_register_gencb(gen_cb, NULL));
	X(intercept_register_sccb("native", "open", trans_cb, NULL));
	tl = intercept_register_transfn("native", "open", 0);
	intercept_register_translation("native", "open", 1, &ic_oflags);
	alias = systrace_new_alias("native", "open", "native", "fswrite");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "sendmsg", trans_cb, NULL));
	intercept_register_translation("native", "sendmsg", 1,
	    &ic_translate_sendmsg);
	X(intercept_register_sccb("native", "connect", trans_cb, NULL));
	intercept_register_translation("native", "connect", 1,
	    &ic_translate_connect);
	X(intercept_register_sccb("native", "sendto", trans_cb, NULL));
	intercept_register_translation("native", "sendto", 4,
	    &ic_translate_connect);
	X(intercept_register_sccb("native", "bind", trans_cb, NULL));
	intercept_register_translation("native", "bind", 1,
	    &ic_translate_connect);
	X(intercept_register_sccb("native", "execve", trans_cb, NULL));
	intercept_register_transfn("native", "execve", 0);
	intercept_register_translation("native", "execve", 1, &ic_trargv);
	X(intercept_register_sccb("native", "stat", trans_cb, NULL));
	tl = intercept_register_transfn("native", "stat", 0);
	alias = systrace_new_alias("native", "stat", "native", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "lstat", trans_cb, NULL));
	tl = intercept_register_translation("native", "lstat", 0,
	    &ic_translate_unlinkname);
	alias = systrace_new_alias("native", "lstat", "native", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "unlink", trans_cb, NULL));
	tl = intercept_register_translation("native", "unlink", 0,
	    &ic_translate_unlinkname);
	alias = systrace_new_alias("native", "unlink", "native", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("native", "truncate", trans_cb, NULL));
	tl = intercept_register_transfn("native", "truncate", 0);
	alias = systrace_new_alias("native", "truncate", "native", "fswrite");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "mkfifo", trans_cb, NULL));
	tl = intercept_register_transfn("native", "mkfifo", 0);
	intercept_register_translation("native", "mkfifo", 1, &ic_modeflags);
	alias = systrace_new_alias("native", "mkfifo", "native", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("native", "mknod", trans_cb, NULL));
	intercept_register_transfn("native", "mknod", 0);
	intercept_register_translation("native", "mknod", 1, &ic_modeflags);

	X(intercept_register_sccb("native", "chown", trans_cb, NULL));
	intercept_register_transfn("native", "chown", 0);
	intercept_register_translation("native", "chown", 1, &ic_uidt);
	intercept_register_translation("native", "chown", 2, &ic_gidt);
	X(intercept_register_sccb("native", "fchown", trans_cb, NULL));
	intercept_register_translation("native", "fchown", 0, &ic_fdt);
	intercept_register_translation("native", "fchown", 1, &ic_uidt);
	intercept_register_translation("native", "fchown", 2, &ic_gidt);
	X(intercept_register_sccb("native", "lchown", trans_cb, NULL));
	intercept_register_translation("native", "lchown", 0,
	    &ic_translate_unlinkname);
	intercept_register_translation("native", "lchown", 1, &ic_uidt);
	intercept_register_translation("native", "lchown", 2, &ic_gidt);
	X(intercept_register_sccb("native", "chmod", trans_cb, NULL));
	intercept_register_transfn("native", "chmod", 0);
	intercept_register_translation("native", "chmod", 1, &ic_modeflags);
	X(intercept_register_sccb("native", "fchmod", trans_cb, NULL));
	intercept_register_translation("native", "fchmod", 0, &ic_fdt);
	intercept_register_translation("native", "fchmod", 1, &ic_modeflags);
	X(intercept_register_sccb("native", "chflags", trans_cb, NULL));
	intercept_register_transfn("native", "chflags", 0);
	intercept_register_translation("native", "chflags", 1, &ic_fileflags);
	X(intercept_register_sccb("native", "readlink", trans_cb, NULL));
	tl = intercept_register_translation("native", "readlink", 0,
	    &ic_translate_unlinkname);
	alias = systrace_new_alias("native", "readlink", "native", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "chdir", trans_cb, NULL));
	intercept_register_transfn("native", "chdir", 0);
	X(intercept_register_sccb("native", "chroot", trans_cb, NULL));
	intercept_register_transfn("native", "chroot", 0);
	X(intercept_register_sccb("native", "access", trans_cb, NULL));
	tl = intercept_register_transfn("native", "access", 0);
	alias = systrace_new_alias("native", "access", "native", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "mkdir", trans_cb, NULL));
	tl = intercept_register_translation("native", "mkdir", 0,
	    &ic_translate_unlinkname);
	alias = systrace_new_alias("native", "mkdir", "native", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("native", "rmdir", trans_cb, NULL));
	tl = intercept_register_transfn("native", "rmdir", 0);
	alias = systrace_new_alias("native", "rmdir", "native", "fswrite");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "rename", trans_cb, NULL));
	intercept_register_translation("native", "rename", 0,
	    &ic_translate_unlinkname);
	intercept_register_translation("native", "rename", 1,
	    &ic_translate_unlinkname);
	X(intercept_register_sccb("native", "symlink", trans_cb, NULL));
	intercept_register_transstring("native", "symlink", 0);
	intercept_register_translation("native", "symlink", 1,
	    &ic_translate_unlinkname);
	X(intercept_register_sccb("native", "link", trans_cb, NULL));
	intercept_register_transfn("native", "link", 0);
	intercept_register_transfn("native", "link", 1);

	X(intercept_register_sccb("native", "setuid", trans_cb, NULL));
	intercept_register_translation("native", "setuid", 0, &ic_uidt);
	intercept_register_translation("native", "setuid", 0, &ic_uname);
	X(intercept_register_sccb("native", "seteuid", trans_cb, NULL));
	intercept_register_translation("native", "seteuid", 0, &ic_uidt);
	intercept_register_translation("native", "seteuid", 0, &ic_uname);
	X(intercept_register_sccb("native", "setgid", trans_cb, NULL));
	intercept_register_translation("native", "setgid", 0, &ic_gidt);
	X(intercept_register_sccb("native", "setegid", trans_cb, NULL));
	intercept_register_translation("native", "setegid", 0, &ic_gidt);

	X(intercept_register_sccb("native", "socket", trans_cb, NULL));
	intercept_register_translation("native", "socket", 0, &ic_sockdom);
	intercept_register_translation("native", "socket", 1, &ic_socktype);
	X(intercept_register_sccb("native", "kill", trans_cb, NULL));
	intercept_register_translation("native", "kill", 0, &ic_pidname);
	intercept_register_translation("native", "kill", 1, &ic_signame);
	X(intercept_register_sccb("native", "fcntl", trans_cb, NULL));
	intercept_register_translation("native", "fcntl", 1, &ic_fcntlcmd);

	X(intercept_register_sccb("native", "mmap", trans_cb, NULL));
	intercept_register_translation("native", "mmap", 2, &ic_memprot);
	X(intercept_register_sccb("native", "mprotect", trans_cb, NULL));
	intercept_register_translation("native", "mprotect", 2, &ic_memprot);

	X(intercept_register_sccb("native", "openat", trans_cb, NULL));
	tl = intercept_register_translation("native", "openat", 1,
	    &ic_translate_filenameat);
	intercept_register_translation("native", "openat", 2, &ic_oflags);
	alias = systrace_new_alias("native", "openat", "native", "fswrite");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "mkdirat", trans_cb, NULL));
	tl = intercept_register_translation("native", "mkdirat", 1,
	    &ic_translate_unlinknameat);
	alias = systrace_new_alias("native", "mkdirat", "native", "fswrite");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "mkfifoat", trans_cb, NULL));
	tl = intercept_register_translation("native", "mkfifoat", 1,
	    &ic_translate_unlinknameat);
	intercept_register_translation("native", "mkfifoat", 2, &ic_modeflags);
	alias = systrace_new_alias("native", "mkfifoat", "native", "fswrite");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "mknodat", trans_cb, NULL));
	intercept_register_translation("native", "mknodat", 1,
	    &ic_translate_unlinknameat);
	intercept_register_translation("native", "mknodat", 2, &ic_modeflags);

	X(intercept_register_sccb("native", "symlinkat", trans_cb, NULL));
	intercept_register_transstring("native", "symlinkat", 0);
	intercept_register_translation("native", "symlinkat", 2,
	    &ic_translate_unlinknameat);

	X(intercept_register_sccb("native", "faccessat", trans_cb, NULL));
	tl = intercept_register_translation("native", "faccessat", 1,
	    &ic_translate_filenameat);
	alias = systrace_new_alias("native", "faccessat", "native", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "unlinkat", trans_cb, NULL));
	tl = intercept_register_translation("native", "unlinkat", 1,
	    &ic_translate_unlinknameat);
	alias = systrace_new_alias("native", "unlinkat", "native", "fswrite");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "readlinkat", trans_cb, NULL));
	tl = intercept_register_translation("native", "readlinkat", 1,
	    &ic_translate_unlinknameat);
	alias = systrace_new_alias("native", "readlinkat", "native", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "renameat", trans_cb, NULL));
	intercept_register_translation("native", "renameat", 1,
	    &ic_translate_unlinknameat);
	intercept_register_translation("native", "renameat", 3,
	    &ic_translate_unlinknameat);

	X(intercept_register_sccb("native", "fchownat", trans_cb, NULL));
	intercept_register_translation("native", "fchownat", 1,
	    &ic_translate_filenameatflag);
	intercept_register_translation("native", "fchownat", 2, &ic_uidt);
	intercept_register_translation("native", "fchownat", 3, &ic_gidt);
	X(intercept_register_sccb("native", "fchmodat", trans_cb, NULL));
	intercept_register_translation("native", "fchmodat", 1,
	    &ic_translate_filenameatflag);
	intercept_register_translation("native", "fchmodat", 2, &ic_modeflags);
	X(intercept_register_sccb("native", "fstatat", trans_cb, NULL));
	tl = intercept_register_translation("native", "fstatat", 1,
	    &ic_translate_filenameatflag);
	alias = systrace_new_alias("native", "fstatat", "native", "fsread");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("native", "linkat", trans_cb, NULL));
	intercept_register_translation("native", "linkat", 1,
	    &ic_translate_unlinknameatflag);
	intercept_register_translation("native", "linkat", 3,
	    &ic_translate_unlinknameat);

	X(intercept_register_sccb("linux", "open", trans_cb, NULL));
	tl = intercept_register_translink("linux", "open", 0);
	intercept_register_translation("linux", "open", 1, &ic_linux_oflags);
	alias = systrace_new_alias("linux", "open", "linux", "fswrite");
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("linux", "stat", trans_cb, NULL));
	tl = intercept_register_translink("linux", "stat", 0);
	alias = systrace_new_alias("linux", "stat", "linux", "fsread");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "lstat", trans_cb, NULL));
	tl = intercept_register_translink("linux", "lstat", 0);
	alias = systrace_new_alias("linux", "lstat", "linux", "fsread");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "execve", trans_cb, NULL));
	intercept_register_translink("linux", "execve", 0);
	X(intercept_register_sccb("linux", "access", trans_cb, NULL));
	tl = intercept_register_translink("linux", "access", 0);
	alias = systrace_new_alias("linux", "access", "linux", "fsread");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "symlink", trans_cb, NULL));
	intercept_register_transstring("linux", "symlink", 0);
	intercept_register_translink("linux", "symlink", 1);
	X(intercept_register_sccb("linux", "link", trans_cb, NULL));
	intercept_register_translink("linux", "link", 0);
	intercept_register_translink("linux", "link", 1);
	X(intercept_register_sccb("linux", "readlink", trans_cb, NULL));
	tl = intercept_register_translink("linux", "readlink", 0);
	alias = systrace_new_alias("linux", "readlink", "linux", "fsread");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "rename", trans_cb, NULL));
	intercept_register_translink("linux", "rename", 0);
	intercept_register_translink("linux", "rename", 1);
	X(intercept_register_sccb("linux", "mkdir", trans_cb, NULL));
	tl = intercept_register_translink("linux", "mkdir", 0);
	alias = systrace_new_alias("linux", "mkdir", "linux", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "rmdir", trans_cb, NULL));
	tl = intercept_register_translink("linux", "rmdir", 0);
	alias = systrace_new_alias("linux", "rmdir", "linux", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "unlink", trans_cb, NULL));
	tl = intercept_register_translink("linux", "unlink", 0);
	alias = systrace_new_alias("linux", "unlink", "linux", "fswrite");
	systrace_alias_add_trans(alias, tl);
	X(intercept_register_sccb("linux", "chmod", trans_cb, NULL));
	intercept_register_translink("linux", "chmod", 0);
	intercept_register_translation("linux", "chmod", 1, &ic_modeflags);

	X(intercept_register_sccb("linux", "socketcall", trans_cb, NULL));
	alias = systrace_new_alias("linux", "socketcall", "linux", "_socketcall");
	tl = intercept_register_translation("linux", "socketcall", 1, &ic_linux_socket_sockdom);
	systrace_alias_add_trans(alias, tl);
	tl = intercept_register_translation("linux", "socketcall", 1, &ic_linux_socket_socktype);
	systrace_alias_add_trans(alias, tl);
	tl = intercept_register_translation("linux", "socketcall", 1, &ic_linux_connect_sockaddr);
	systrace_alias_add_trans(alias, tl);
	tl = intercept_register_translation("linux", "socketcall", 1, &ic_linux_bind_sockaddr);
	systrace_alias_add_trans(alias, tl);
	tl = intercept_register_translation("linux", "socketcall", 0, &ic_linux_socketcall_catchall);
	systrace_alias_add_trans(alias, tl);

	X(intercept_register_sccb("linux", "kill", trans_cb, NULL));
	intercept_register_translation("linux", "kill", 0, &ic_pidname);
	intercept_register_translation("linux", "kill", 1, &ic_signame);

	X(intercept_register_execcb(execres_cb, NULL));
	X(intercept_register_pfreecb(policyfree_cb, NULL));
}