diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-09-29 07:07:16 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-09-29 07:07:16 +0900 |
| commit | 1ba1cb886584966b4e6e65284a04dfaf8962ed65 (patch) | |
| tree | 12a96d2220e88d410173ede47f25c74b5b4f9ae5 /cmd | |
| parent | 44ba7a5f02b7575a706a22aac53c8ac608d18f23 (diff) | |
hst/config: remove seccomp bit fields
These serve little purpose and are not friendly for use from other languages.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'cmd')
| -rw-r--r-- | cmd/hakurei/print_test.go | 6 | ||||
| -rw-r--r-- | cmd/hpkg/app.go | 8 | ||||
| -rw-r--r-- | cmd/hpkg/with.go | 17 |
3 files changed, 9 insertions, 22 deletions
diff --git a/cmd/hakurei/print_test.go b/cmd/hakurei/print_test.go index a0978981..49579a82 100644 --- a/cmd/hakurei/print_test.go +++ b/cmd/hakurei/print_test.go @@ -259,8 +259,6 @@ App "container": { "hostname": "localhost", "wait_delay": -1, - "seccomp_flags": 1, - "seccomp_presets": 1, "seccomp_compat": true, "devel": true, "userns": true, @@ -415,8 +413,6 @@ App "container": { "hostname": "localhost", "wait_delay": -1, - "seccomp_flags": 1, - "seccomp_presets": 1, "seccomp_compat": true, "devel": true, "userns": true, @@ -625,8 +621,6 @@ func Test_printPs(t *testing.T) { "container": { "hostname": "localhost", "wait_delay": -1, - "seccomp_flags": 1, - "seccomp_presets": 1, "seccomp_compat": true, "devel": true, "userns": true, diff --git a/cmd/hpkg/app.go b/cmd/hpkg/app.go index 5fd5e640..1a1437ff 100644 --- a/cmd/hpkg/app.go +++ b/cmd/hpkg/app.go @@ -6,7 +6,6 @@ import ( "os" "hakurei.app/container" - "hakurei.app/container/seccomp" "hakurei.app/hst" "hakurei.app/system/dbus" ) @@ -92,6 +91,7 @@ func (app *appInfo) toHst(pathSet *appPathSet, pathname *container.Absolute, arg Device: app.Device, Tty: app.Tty || flagDropShell, MapRealUID: app.MapRealUID, + Multiarch: app.Multiarch, Filesystem: []hst.FilesystemConfigJSON{ {FilesystemConfig: &hst.FSBind{Target: container.AbsFHSEtc, Source: pathSet.cacheDir.Append("etc"), Special: true}}, {FilesystemConfig: &hst.FSBind{Source: pathSet.nixPath.Append("store"), Target: pathNixStore}}, @@ -113,12 +113,6 @@ func (app *appInfo) toHst(pathSet *appPathSet, pathname *container.Absolute, arg {Ensure: true, Path: pathSet.baseDir, Read: true, Write: true, Execute: true}, }, } - if app.Multiarch { - config.Container.SeccompFlags |= seccomp.AllowMultiarch - } - if app.Bluetooth { - config.Container.SeccompFlags |= seccomp.AllowBluetooth - } return config } diff --git a/cmd/hpkg/with.go b/cmd/hpkg/with.go index 578d5251..59545c62 100644 --- a/cmd/hpkg/with.go +++ b/cmd/hpkg/with.go @@ -6,7 +6,6 @@ import ( "strings" "hakurei.app/container" - "hakurei.app/container/seccomp" "hakurei.app/hst" ) @@ -43,11 +42,11 @@ func withNixDaemon( Identity: app.Identity, Container: &hst.ContainerConfig{ - Hostname: formatHostname(app.Name) + "-" + action, - Userns: true, // nix sandbox requires userns - HostNet: net, - SeccompFlags: seccomp.AllowMultiarch, - Tty: dropShell, + Hostname: formatHostname(app.Name) + "-" + action, + Userns: true, // nix sandbox requires userns + HostNet: net, + Multiarch: true, + Tty: dropShell, Filesystem: []hst.FilesystemConfigJSON{ {FilesystemConfig: &hst.FSBind{Target: container.AbsFHSEtc, Source: pathSet.cacheDir.Append("etc"), Special: true}}, {FilesystemConfig: &hst.FSBind{Source: pathSet.nixPath, Target: pathNix, Write: true}}, @@ -83,9 +82,9 @@ func withCacheDir( Identity: app.Identity, Container: &hst.ContainerConfig{ - Hostname: formatHostname(app.Name) + "-" + action, - SeccompFlags: seccomp.AllowMultiarch, - Tty: dropShell, + Hostname: formatHostname(app.Name) + "-" + action, + Multiarch: true, + Tty: dropShell, Filesystem: []hst.FilesystemConfigJSON{ {FilesystemConfig: &hst.FSBind{Target: container.AbsFHSEtc, Source: workDir.Append(container.FHSEtc), Special: true}}, {FilesystemConfig: &hst.FSBind{Source: workDir.Append("nix"), Target: pathNix}}, |
