From 69a4ab81053ef31d745ac0d92531cefb7d3a3e44 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Mon, 18 Aug 2025 11:46:02 +0900 Subject: container: move PR_SET_NO_NEW_PRIVS to parent This allows some LSM setup in the parent. Signed-off-by: Ophestra --- container/init.go | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) (limited to 'container/init.go') diff --git a/container/init.go b/container/init.go index f162de26..885b543d 100644 --- a/container/init.go +++ b/container/init.go @@ -218,10 +218,6 @@ func Init(prepare func(prefix string), setVerbose func(verbose bool)) { } } - if _, _, errno := Syscall(SYS_PRCTL, PR_SET_NO_NEW_PRIVS, 1, 0); errno != 0 { - log.Fatalf("prctl(PR_SET_NO_NEW_PRIVS): %v", errno) - } - if _, _, errno := Syscall(SYS_PRCTL, PR_CAP_AMBIENT, PR_CAP_AMBIENT_CLEAR_ALL, 0); errno != 0 { log.Fatalf("cannot clear the ambient capability set: %v", errno) } @@ -256,6 +252,7 @@ func Init(prepare func(prefix string), setVerbose func(verbose bool)) { rules = seccomp.Preset(params.SeccompPresets, params.SeccompFlags) } if err := seccomp.Load(rules, params.SeccompFlags); err != nil { + // this also indirectly asserts PR_SET_NO_NEW_PRIVS log.Fatalf("cannot load syscall filter: %v", err) } msg.Verbosef("%d filter rules loaded", len(rules)) -- cgit v1.3.1