From 3b8a3d3b004695d79745c34821b33cfbe41048a9 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Fri, 1 Aug 2025 23:54:33 +0900 Subject: app: remount root readonly This does nothing for security, but should help avoid hiding bugs of programs developed in a hakurei container. Signed-off-by: Ophestra --- internal/app/seal_linux.go | 3 +++ 1 file changed, 3 insertions(+) (limited to 'internal/app/seal_linux.go') diff --git a/internal/app/seal_linux.go b/internal/app/seal_linux.go index cc92db29..b25b5c4f 100644 --- a/internal/app/seal_linux.go +++ b/internal/app/seal_linux.go @@ -478,6 +478,9 @@ func (seal *outcome) finalise(ctx context.Context, sys sys.State, config *hst.Co seal.container.Tmpfs(dest, 1<<13, 0755) } + // mount root read-only as the final setup Op + seal.container.Remount("/", syscall.MS_RDONLY) + // append ExtraPerms last for _, p := range config.ExtraPerms { if p == nil { -- cgit v1.3.1