aboutsummaryrefslogtreecommitdiffhomepage
path: root/container/std
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-11-05 02:47:43 +0900
committerOphestra <cat@gensokyo.uk>2025-11-05 02:47:43 +0900
commitc1399f5030abde76728ba7982a7a22fd49e75359 (patch)
tree06e2a2ce11dbd7536150fd57824e406f101d50d9 /container/std
parent9ac63aac0cb025d1de195dbc57d0c89ebd1d7cc5 (diff)
std: rename from comp
Seccomp lookup tables are going to be relocated here, and PNR constants. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container/std')
-rw-r--r--container/std/bits.go32
1 files changed, 32 insertions, 0 deletions
diff --git a/container/std/bits.go b/container/std/bits.go
new file mode 100644
index 00000000..f1ddbd89
--- /dev/null
+++ b/container/std/bits.go
@@ -0,0 +1,32 @@
+// Package std contains constants from container packages without depending on cgo.
+package std
+
+const (
+ // BindOptional skips nonexistent host paths.
+ BindOptional = 1 << iota
+ // BindWritable mounts filesystem read-write.
+ BindWritable
+ // BindDevice allows access to devices (special files) on this filesystem.
+ BindDevice
+ // BindEnsure attempts to create the host path if it does not exist.
+ BindEnsure
+)
+
+// FilterPreset specifies parts of the syscall filter preset to enable.
+type FilterPreset int
+
+const (
+ // PresetExt are project-specific extensions.
+ PresetExt FilterPreset = 1 << iota
+ // PresetDenyNS denies namespace setup syscalls.
+ PresetDenyNS
+ // PresetDenyTTY denies faking input.
+ PresetDenyTTY
+ // PresetDenyDevel denies development-related syscalls.
+ PresetDenyDevel
+ // PresetLinux32 sets PER_LINUX32.
+ PresetLinux32
+
+ // PresetStrict is a strict preset useful as a default value.
+ PresetStrict = PresetExt | PresetDenyNS | PresetDenyTTY | PresetDenyDevel
+)