From e94acc424c5746eb6cf903ed97b4e71223fda50f Mon Sep 17 00:00:00 2001 From: Ophestra Date: Tue, 21 Oct 2025 20:54:03 +0900 Subject: container/comp: rename from bits This package will also hold syscall lookup tables for seccomp. Signed-off-by: Ophestra --- container/comp/bits.go | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 container/comp/bits.go (limited to 'container/comp') diff --git a/container/comp/bits.go b/container/comp/bits.go new file mode 100644 index 00000000..d0993444 --- /dev/null +++ b/container/comp/bits.go @@ -0,0 +1,32 @@ +// Package comp contains constants from container packages without depending on cgo. +package comp + +const ( + // BindOptional skips nonexistent host paths. + BindOptional = 1 << iota + // BindWritable mounts filesystem read-write. + BindWritable + // BindDevice allows access to devices (special files) on this filesystem. + BindDevice + // BindEnsure attempts to create the host path if it does not exist. + BindEnsure +) + +// FilterPreset specifies parts of the syscall filter preset to enable. +type FilterPreset int + +const ( + // PresetExt are project-specific extensions. + PresetExt FilterPreset = 1 << iota + // PresetDenyNS denies namespace setup syscalls. + PresetDenyNS + // PresetDenyTTY denies faking input. + PresetDenyTTY + // PresetDenyDevel denies development-related syscalls. + PresetDenyDevel + // PresetLinux32 sets PER_LINUX32. + PresetLinux32 + + // PresetStrict is a strict preset useful as a default value. + PresetStrict = PresetExt | PresetDenyNS | PresetDenyTTY | PresetDenyDevel +) -- cgit v1.3.1