aboutsummaryrefslogtreecommitdiffhomepage
path: root/internal/outcome/spcontainer.go
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-11-05 02:47:43 +0900
committerOphestra <cat@gensokyo.uk>2025-11-05 02:47:43 +0900
commitc1399f5030abde76728ba7982a7a22fd49e75359 (patch)
tree06e2a2ce11dbd7536150fd57824e406f101d50d9 /internal/outcome/spcontainer.go
parent9ac63aac0cb025d1de195dbc57d0c89ebd1d7cc5 (diff)
std: rename from comp
Seccomp lookup tables are going to be relocated here, and PNR constants. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal/outcome/spcontainer.go')
-rw-r--r--internal/outcome/spcontainer.go12
1 files changed, 6 insertions, 6 deletions
diff --git a/internal/outcome/spcontainer.go b/internal/outcome/spcontainer.go
index 13808ca1..a9eed191 100644
--- a/internal/outcome/spcontainer.go
+++ b/internal/outcome/spcontainer.go
@@ -12,9 +12,9 @@ import (
"hakurei.app/container"
"hakurei.app/container/check"
- "hakurei.app/container/comp"
"hakurei.app/container/fhs"
"hakurei.app/container/seccomp"
+ "hakurei.app/container/std"
"hakurei.app/hst"
"hakurei.app/internal/validate"
"hakurei.app/message"
@@ -76,16 +76,16 @@ func (s *spParamsOp) toContainer(state *outcomeStateParams) error {
}
if state.Container.Flags&hst.FSeccompCompat == 0 {
- state.params.SeccompPresets |= comp.PresetExt
+ state.params.SeccompPresets |= std.PresetExt
}
if state.Container.Flags&hst.FDevel == 0 {
- state.params.SeccompPresets |= comp.PresetDenyDevel
+ state.params.SeccompPresets |= std.PresetDenyDevel
}
if state.Container.Flags&hst.FUserns == 0 {
- state.params.SeccompPresets |= comp.PresetDenyNS
+ state.params.SeccompPresets |= std.PresetDenyNS
}
if state.Container.Flags&hst.FTty == 0 {
- state.params.SeccompPresets |= comp.PresetDenyTTY
+ state.params.SeccompPresets |= std.PresetDenyTTY
}
if state.Container.Flags&hst.FMapRealUID != 0 {
@@ -113,7 +113,7 @@ func (s *spParamsOp) toContainer(state *outcomeStateParams) error {
if state.Container.Flags&hst.FDevice == 0 {
state.params.DevWritable(fhs.AbsDev, true)
} else {
- state.params.Bind(fhs.AbsDev, fhs.AbsDev, comp.BindWritable|comp.BindDevice)
+ state.params.Bind(fhs.AbsDev, fhs.AbsDev, std.BindWritable|std.BindDevice)
}
// /dev is mounted readonly later on, this prevents /dev/shm from going readonly with it
state.params.Tmpfs(fhs.AbsDev.Append("shm"), 0, 01777)