Unshare-all with bubblewrap.
Should have been --unshare-all from the start. One of the advantages of the ucspi model is exactly that the server program doesn't even need network access.
This commit is contained in:
parent
9ff087020e
commit
a3b376a1b2
3
host.sh
3
host.sh
|
@ -5,5 +5,6 @@ exec env \
|
|||
s6-tlsserver -k1 0.0.0.0 1965 \
|
||||
bwrap --ro-bind /usr /usr --symlink usr/lib /lib \
|
||||
--proc /proc --dev /dev \
|
||||
--ro-bind $PWD/gemini /gemini --ro-bind $PWD/lc19 /lc19 --unshare-pid \
|
||||
--ro-bind $PWD/gemini /gemini --ro-bind $PWD/lc19 /lc19 \
|
||||
--unshare-all \
|
||||
/lc19 --data-dir=/gemini
|
||||
|
|
Loading…
Reference in New Issue