From 72b0160aadac590bc479b9ec86e0378a95d2bdc0 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Sat, 15 Feb 2025 03:12:28 +0900 Subject: helper/bwrap: implement file copy flags These are significantly more efficient and less error-prone than mounting an external tmpfile. This should also reduce attack surface as the resulting files are private to its specific sandbox. Signed-off-by: Ophestra --- helper/bwrap/config.go | 3 --- 1 file changed, 3 deletions(-) (limited to 'helper/bwrap/config.go') diff --git a/helper/bwrap/config.go b/helper/bwrap/config.go index b9fa0c12..fdda14a4 100644 --- a/helper/bwrap/config.go +++ b/helper/bwrap/config.go @@ -71,9 +71,6 @@ type Config struct { --ro-bind-fd FD DEST Bind open directory or path fd read-only on DEST --exec-label LABEL Exec label for the sandbox --file-label LABEL File label for temporary sandbox content - --file FD DEST Copy from FD to destination DEST - --bind-data FD DEST Copy from FD to file which is bind-mounted on DEST - --ro-bind-data FD DEST Copy from FD to file which is readonly bind-mounted on DEST --add-seccomp-fd FD Load and use seccomp rules from FD (repeatable) --block-fd FD Block on FD until some data to read is available --userns-block-fd FD Block on FD until the user namespace is ready -- cgit v1.3.1