diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-07-01 20:23:33 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-07-01 22:11:32 +0900 |
| commit | 1a8840bebc673672235b6e10b1b9386f24751757 (patch) | |
| tree | d1e6772bfd685e2162d047e3640bd3ee55c1a1f7 /cmd | |
| parent | 1fb453dffe4c83866fedfa4590be30ec65e815ff (diff) | |
sandbox/seccomp: resolve rules natively
This enables loading syscall filter policies from external cross-platform config files.
This also removes a significant amount of C code.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'cmd')
| -rw-r--r-- | cmd/planterette/app.go | 4 | ||||
| -rw-r--r-- | cmd/planterette/with.go | 16 |
2 files changed, 10 insertions, 10 deletions
diff --git a/cmd/planterette/app.go b/cmd/planterette/app.go index 257956d9..6d0993f4 100644 --- a/cmd/planterette/app.go +++ b/cmd/planterette/app.go @@ -115,10 +115,10 @@ func (app *appInfo) toFst(pathSet *appPathSet, argv []string, flagDropShell bool }, } if app.Multiarch { - config.Container.Seccomp |= seccomp.FilterMultiarch + config.Container.SeccompFlags |= seccomp.AllowMultiarch } if app.Bluetooth { - config.Container.Seccomp |= seccomp.FilterBluetooth + config.Container.SeccompFlags |= seccomp.AllowBluetooth } return config } diff --git a/cmd/planterette/with.go b/cmd/planterette/with.go index ffacec71..f2f4541d 100644 --- a/cmd/planterette/with.go +++ b/cmd/planterette/with.go @@ -43,11 +43,11 @@ func withNixDaemon( Identity: app.Identity, Container: &hst.ContainerConfig{ - Hostname: formatHostname(app.Name) + "-" + action, - Userns: true, // nix sandbox requires userns - Net: net, - Seccomp: seccomp.FilterMultiarch, - Tty: dropShell, + Hostname: formatHostname(app.Name) + "-" + action, + Userns: true, // nix sandbox requires userns + Net: net, + SeccompFlags: seccomp.AllowMultiarch, + Tty: dropShell, Filesystem: []*hst.FilesystemConfig{ {Src: pathSet.nixPath, Dst: "/nix", Write: true, Must: true}, }, @@ -85,9 +85,9 @@ func withCacheDir( Identity: app.Identity, Container: &hst.ContainerConfig{ - Hostname: formatHostname(app.Name) + "-" + action, - Seccomp: seccomp.FilterMultiarch, - Tty: dropShell, + Hostname: formatHostname(app.Name) + "-" + action, + SeccompFlags: seccomp.AllowMultiarch, + Tty: dropShell, Filesystem: []*hst.FilesystemConfig{ {Src: path.Join(workDir, "nix"), Dst: "/nix", Must: true}, {Src: workDir, Dst: path.Join(hst.Tmp, "bundle"), Must: true}, |
