From b852402f67b22a3a850ce4eb1305a3ce5898d128 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Tue, 17 Mar 2026 15:48:40 +0900 Subject: ext: move syscall wrappers from container These are generally useful, and none of them are container-specific. Syscalls subtle to use and requiring container-specific setup remains in container. Signed-off-by: Ophestra --- cmd/hakurei/main.go | 5 +++-- cmd/mbf/main.go | 3 ++- 2 files changed, 5 insertions(+), 3 deletions(-) (limited to 'cmd') diff --git a/cmd/hakurei/main.go b/cmd/hakurei/main.go index 169ac6c0..b7722bc3 100644 --- a/cmd/hakurei/main.go +++ b/cmd/hakurei/main.go @@ -13,6 +13,7 @@ import ( "syscall" "hakurei.app/container" + "hakurei.app/ext" "hakurei.app/message" ) @@ -35,8 +36,8 @@ func main() { msg := message.New(log.Default()) early := earlyHardeningErrs{ - yamaLSM: container.SetPtracer(0), - dumpable: container.SetDumpable(container.SUID_DUMP_DISABLE), + yamaLSM: ext.SetPtracer(0), + dumpable: ext.SetDumpable(ext.SUID_DUMP_DISABLE), } if os.Geteuid() == 0 { diff --git a/cmd/mbf/main.go b/cmd/mbf/main.go index 3dc1f06e..484423da 100644 --- a/cmd/mbf/main.go +++ b/cmd/mbf/main.go @@ -24,6 +24,7 @@ import ( "hakurei.app/container/fhs" "hakurei.app/container/seccomp" "hakurei.app/container/std" + "hakurei.app/ext" "hakurei.app/internal/pkg" "hakurei.app/internal/rosa" "hakurei.app/message" @@ -271,7 +272,7 @@ func main() { return errors.New("report requires 1 argument") } - if container.Isatty(int(w.Fd())) { + if ext.Isatty(int(w.Fd())) { return errors.New("output appears to be a terminal") } return rosa.WriteReport(msg, w, cache) -- cgit v1.3.1