diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-11-05 02:47:43 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-11-05 02:47:43 +0900 |
| commit | c1399f5030abde76728ba7982a7a22fd49e75359 (patch) | |
| tree | 06e2a2ce11dbd7536150fd57824e406f101d50d9 /container/std | |
| parent | 9ac63aac0cb025d1de195dbc57d0c89ebd1d7cc5 (diff) | |
std: rename from comp
Seccomp lookup tables are going to be relocated here, and PNR constants.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container/std')
| -rw-r--r-- | container/std/bits.go | 32 |
1 files changed, 32 insertions, 0 deletions
diff --git a/container/std/bits.go b/container/std/bits.go new file mode 100644 index 00000000..f1ddbd89 --- /dev/null +++ b/container/std/bits.go @@ -0,0 +1,32 @@ +// Package std contains constants from container packages without depending on cgo. +package std + +const ( + // BindOptional skips nonexistent host paths. + BindOptional = 1 << iota + // BindWritable mounts filesystem read-write. + BindWritable + // BindDevice allows access to devices (special files) on this filesystem. + BindDevice + // BindEnsure attempts to create the host path if it does not exist. + BindEnsure +) + +// FilterPreset specifies parts of the syscall filter preset to enable. +type FilterPreset int + +const ( + // PresetExt are project-specific extensions. + PresetExt FilterPreset = 1 << iota + // PresetDenyNS denies namespace setup syscalls. + PresetDenyNS + // PresetDenyTTY denies faking input. + PresetDenyTTY + // PresetDenyDevel denies development-related syscalls. + PresetDenyDevel + // PresetLinux32 sets PER_LINUX32. + PresetLinux32 + + // PresetStrict is a strict preset useful as a default value. + PresetStrict = PresetExt | PresetDenyNS | PresetDenyTTY | PresetDenyDevel +) |
