#pragma once #include #include #include #include #include #include #define ISOLATED_MAGIC "isolated" namespace DenyRequest { enum : int { ENFORCE, DISABLE, ADD, REMOVE, LIST, STATUS, END }; } namespace DenyResponse { enum : int { OK, ENFORCED, NOT_ENFORCED, ITEM_EXIST, ITEM_NOT_EXIST, INVALID_PKG, NO_NS, ERROR, END }; } // CLI entries int enable_deny(); int disable_deny(); int add_list(int client); int rm_list(int client); void ls_list(int client); // Utility functions bool is_deny_target(int uid, std::string_view process); void revert_unmount(); extern std::atomic denylist_enforced; extern std::atomic cached_manager_app_id;