diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-10-21 20:54:03 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-10-21 20:54:03 +0900 |
| commit | e94acc424c5746eb6cf903ed97b4e71223fda50f (patch) | |
| tree | c55f4b467ed11149006a799421936845bf64de99 /internal/app/spcontainer.go | |
| parent | b1a4d801be033b41c559e9642ee05e2f0ec43d5b (diff) | |
container/comp: rename from bits
This package will also hold syscall lookup tables for seccomp.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal/app/spcontainer.go')
| -rw-r--r-- | internal/app/spcontainer.go | 12 |
1 files changed, 6 insertions, 6 deletions
diff --git a/internal/app/spcontainer.go b/internal/app/spcontainer.go index c6fcada0..65071f7c 100644 --- a/internal/app/spcontainer.go +++ b/internal/app/spcontainer.go @@ -11,8 +11,8 @@ import ( "syscall" "hakurei.app/container" - "hakurei.app/container/bits" "hakurei.app/container/check" + "hakurei.app/container/comp" "hakurei.app/container/fhs" "hakurei.app/container/seccomp" "hakurei.app/hst" @@ -75,16 +75,16 @@ func (s *spParamsOp) toContainer(state *outcomeStateParams) error { } if state.Container.Flags&hst.FSeccompCompat == 0 { - state.params.SeccompPresets |= bits.PresetExt + state.params.SeccompPresets |= comp.PresetExt } if state.Container.Flags&hst.FDevel == 0 { - state.params.SeccompPresets |= bits.PresetDenyDevel + state.params.SeccompPresets |= comp.PresetDenyDevel } if state.Container.Flags&hst.FUserns == 0 { - state.params.SeccompPresets |= bits.PresetDenyNS + state.params.SeccompPresets |= comp.PresetDenyNS } if state.Container.Flags&hst.FTty == 0 { - state.params.SeccompPresets |= bits.PresetDenyTTY + state.params.SeccompPresets |= comp.PresetDenyTTY } if state.Container.Flags&hst.FMapRealUID != 0 { @@ -112,7 +112,7 @@ func (s *spParamsOp) toContainer(state *outcomeStateParams) error { if state.Container.Flags&hst.FDevice == 0 { state.params.DevWritable(fhs.AbsDev, true) } else { - state.params.Bind(fhs.AbsDev, fhs.AbsDev, bits.BindWritable|bits.BindDevice) + state.params.Bind(fhs.AbsDev, fhs.AbsDev, comp.BindWritable|comp.BindDevice) } // /dev is mounted readonly later on, this prevents /dev/shm from going readonly with it state.params.Tmpfs(fhs.AbsDev.Append("shm"), 0, 01777) |
