aboutsummaryrefslogtreecommitdiffhomepage
path: root/hst
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-09-29 07:07:16 +0900
committerOphestra <cat@gensokyo.uk>2025-09-29 07:07:16 +0900
commit1ba1cb886584966b4e6e65284a04dfaf8962ed65 (patch)
tree12a96d2220e88d410173ede47f25c74b5b4f9ae5 /hst
parent44ba7a5f02b7575a706a22aac53c8ac608d18f23 (diff)
hst/config: remove seccomp bit fields
These serve little purpose and are not friendly for use from other languages. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'hst')
-rw-r--r--hst/config.go5
-rw-r--r--hst/hst.go25
-rw-r--r--hst/hst_test.go2
3 files changed, 11 insertions, 21 deletions
diff --git a/hst/config.go b/hst/config.go
index bd8f637b..3aa71aa4 100644
--- a/hst/config.go
+++ b/hst/config.go
@@ -4,7 +4,6 @@ import (
"time"
"hakurei.app/container"
- "hakurei.app/container/seccomp"
"hakurei.app/system/dbus"
)
@@ -66,10 +65,6 @@ type (
// a negative value causes the container to be terminated immediately on cancellation
WaitDelay time.Duration `json:"wait_delay,omitempty"`
- // extra seccomp flags
- SeccompFlags seccomp.ExportFlag `json:"seccomp_flags"`
- // extra seccomp presets
- SeccompPresets seccomp.FilterPreset `json:"seccomp_presets"`
// disable project-specific filter extensions
SeccompCompat bool `json:"seccomp_compat,omitempty"`
// allow ptrace and friends
diff --git a/hst/hst.go b/hst/hst.go
index 5399cba0..8a72b509 100644
--- a/hst/hst.go
+++ b/hst/hst.go
@@ -7,7 +7,6 @@ import (
"os"
"hakurei.app/container"
- "hakurei.app/container/seccomp"
"hakurei.app/system/dbus"
)
@@ -106,19 +105,17 @@ func Template() *Config {
Groups: []string{"video", "dialout", "plugdev"},
Container: &ContainerConfig{
- Hostname: "localhost",
- Devel: true,
- Userns: true,
- HostNet: true,
- HostAbstract: true,
- Device: true,
- WaitDelay: -1,
- SeccompFlags: seccomp.AllowMultiarch,
- SeccompPresets: seccomp.PresetExt,
- SeccompCompat: true,
- Tty: true,
- Multiarch: true,
- MapRealUID: true,
+ Hostname: "localhost",
+ Devel: true,
+ Userns: true,
+ HostNet: true,
+ HostAbstract: true,
+ Device: true,
+ WaitDelay: -1,
+ SeccompCompat: true,
+ Tty: true,
+ Multiarch: true,
+ MapRealUID: true,
// example API credentials pulled from Google Chrome
// DO NOT USE THESE IN A REAL BROWSER
Env: map[string]string{
diff --git a/hst/hst_test.go b/hst/hst_test.go
index 70f7e531..0c25fa7c 100644
--- a/hst/hst_test.go
+++ b/hst/hst_test.go
@@ -166,8 +166,6 @@ func TestTemplate(t *testing.T) {
"container": {
"hostname": "localhost",
"wait_delay": -1,
- "seccomp_flags": 1,
- "seccomp_presets": 1,
"seccomp_compat": true,
"devel": true,
"userns": true,