aboutsummaryrefslogtreecommitdiffhomepage
path: root/cmd
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-07-01 20:23:33 +0900
committerOphestra <cat@gensokyo.uk>2025-07-01 22:11:32 +0900
commit1a8840bebc673672235b6e10b1b9386f24751757 (patch)
treed1e6772bfd685e2162d047e3640bd3ee55c1a1f7 /cmd
parent1fb453dffe4c83866fedfa4590be30ec65e815ff (diff)
sandbox/seccomp: resolve rules natively
This enables loading syscall filter policies from external cross-platform config files. This also removes a significant amount of C code. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'cmd')
-rw-r--r--cmd/planterette/app.go4
-rw-r--r--cmd/planterette/with.go16
2 files changed, 10 insertions, 10 deletions
diff --git a/cmd/planterette/app.go b/cmd/planterette/app.go
index 257956d9..6d0993f4 100644
--- a/cmd/planterette/app.go
+++ b/cmd/planterette/app.go
@@ -115,10 +115,10 @@ func (app *appInfo) toFst(pathSet *appPathSet, argv []string, flagDropShell bool
},
}
if app.Multiarch {
- config.Container.Seccomp |= seccomp.FilterMultiarch
+ config.Container.SeccompFlags |= seccomp.AllowMultiarch
}
if app.Bluetooth {
- config.Container.Seccomp |= seccomp.FilterBluetooth
+ config.Container.SeccompFlags |= seccomp.AllowBluetooth
}
return config
}
diff --git a/cmd/planterette/with.go b/cmd/planterette/with.go
index ffacec71..f2f4541d 100644
--- a/cmd/planterette/with.go
+++ b/cmd/planterette/with.go
@@ -43,11 +43,11 @@ func withNixDaemon(
Identity: app.Identity,
Container: &hst.ContainerConfig{
- Hostname: formatHostname(app.Name) + "-" + action,
- Userns: true, // nix sandbox requires userns
- Net: net,
- Seccomp: seccomp.FilterMultiarch,
- Tty: dropShell,
+ Hostname: formatHostname(app.Name) + "-" + action,
+ Userns: true, // nix sandbox requires userns
+ Net: net,
+ SeccompFlags: seccomp.AllowMultiarch,
+ Tty: dropShell,
Filesystem: []*hst.FilesystemConfig{
{Src: pathSet.nixPath, Dst: "/nix", Write: true, Must: true},
},
@@ -85,9 +85,9 @@ func withCacheDir(
Identity: app.Identity,
Container: &hst.ContainerConfig{
- Hostname: formatHostname(app.Name) + "-" + action,
- Seccomp: seccomp.FilterMultiarch,
- Tty: dropShell,
+ Hostname: formatHostname(app.Name) + "-" + action,
+ SeccompFlags: seccomp.AllowMultiarch,
+ Tty: dropShell,
Filesystem: []*hst.FilesystemConfig{
{Src: path.Join(workDir, "nix"), Dst: "/nix", Must: true},
{Src: workDir, Dst: path.Join(hst.Tmp, "bundle"), Must: true},