From 13c7083bc028616e258e5e6919db7b11c6e739a6 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Wed, 20 Aug 2025 00:27:45 +0900 Subject: container: ptrace protection via Yama LSM This is only a nice to have feature as the init process has no additional privileges and the monitor process was never reachable anyway. Closes #4. Signed-off-by: Ophestra --- cmd/hakurei/main.go | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'cmd') diff --git a/cmd/hakurei/main.go b/cmd/hakurei/main.go index 7e223cdf..a636cfcb 100644 --- a/cmd/hakurei/main.go +++ b/cmd/hakurei/main.go @@ -30,6 +30,11 @@ func main() { // early init path, skips root check and duplicate PR_SET_DUMPABLE container.TryArgv0(hlog.Output{}, hlog.Prepare, internal.InstallOutput) + if err := container.SetPtracer(0); err != nil { + hlog.Verbosef("cannot enable ptrace protection via Yama LSM: %v", err) + // not fatal: this program runs as the privileged user + } + if err := container.SetDumpable(container.SUID_DUMP_DISABLE); err != nil { log.Printf("cannot set SUID_DUMP_DISABLE: %s", err) // not fatal: this program runs as the privileged user -- cgit v1.3.1