From 27f5922d5c4d4432246d6de6eb0d81d574cdc8c7 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Mon, 20 Jan 2025 21:12:39 +0900 Subject: fst: include syscall filter configuration This value is passed through to shim. Signed-off-by: Ophestra --- fst/config.go | 10 ++++++++++ 1 file changed, 10 insertions(+) (limited to 'fst') diff --git a/fst/config.go b/fst/config.go index 7075c6a0..171c29f7 100644 --- a/fst/config.go +++ b/fst/config.go @@ -31,6 +31,8 @@ type ConfinementConfig struct { Outer string `json:"home"` // bwrap sandbox confinement configuration Sandbox *SandboxConfig `json:"sandbox"` + // seccomp syscall filter configuration + Syscall *SyscallConfig `json:"syscall"` // extra acl entries to append ExtraPerms []*ExtraPermConfig `json:"extra_perms,omitempty"` @@ -45,6 +47,14 @@ type ConfinementConfig struct { Enablements system.Enablements `json:"enablements"` } +type SyscallConfig struct { + DenyDevel bool `json:"deny_devel"` + Multiarch bool `json:"multiarch"` + Linux32 bool `json:"linux32"` + Can bool `json:"can"` + Bluetooth bool `json:"bluetooth"` +} + type ExtraPermConfig struct { Ensure bool `json:"ensure,omitempty"` Path string `json:"path"` -- cgit v1.3.1