aboutsummaryrefslogtreecommitdiffhomepage
path: root/hst
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-07-02 04:38:28 +0900
committerOphestra <cat@gensokyo.uk>2025-07-02 04:47:13 +0900
commit31aef905fa819310ee7694775a836c294ff742e4 (patch)
tree168eb9f598d2cbb46695d2c3e9864cb9ba8d76c6 /hst
parenta6887f7253ae822357f0d4d019675acc8c3e0b4d (diff)
sandbox: expose seccomp interface
There's no point in artificially limiting and abstracting away these options. The higher level hakurei package is responsible for providing a secure baseline and sane defaults. The sandbox package should present everything to the caller. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'hst')
-rw-r--r--hst/container.go2
1 files changed, 2 insertions, 0 deletions
diff --git a/hst/container.go b/hst/container.go
index 43d7577a..bc36bef8 100644
--- a/hst/container.go
+++ b/hst/container.go
@@ -14,6 +14,8 @@ type (
SeccompFlags seccomp.ExportFlag `json:"seccomp_flags"`
// extra seccomp presets
SeccompPresets seccomp.FilterPreset `json:"seccomp_presets"`
+ // disable project-specific filter extensions
+ SeccompCompat bool `json:"seccomp_compat,omitempty"`
// allow ptrace and friends
Devel bool `json:"devel,omitempty"`
// allow userns creation in container