commit 09799565d1eac169f71b288efc7dd37d818f19ee
parent 8f2dbafcb9232a7c7724eef61cb258de78a70065
Author: Jan Pobrislo <ccx@te2000.cz>
Date: Mon, 5 May 2025 22:35:11 +0000
Validate that seccomp-run with filter can run.
Diffstat:
17 files changed, 33 insertions(+), 30 deletions(-)
diff --git a/templates/pkg/container-bin-image b/templates/pkg/container-bin-image
@@ -46,6 +46,7 @@ for cmd in if busybox umount chpst spawn-pty ptsname applyuidgid-caps; do
fi
done
./true
+./seccomp-run ./seccomp-default.bpf ./true
touch "$pthbs_destdir{{versions}}/$pthbs_package/.install-links"
diff --git a/variants/ccx-x86_64/container-bin-image b/variants/ccx-x86_64/container-bin-image
@@ -45,6 +45,7 @@ for cmd in if busybox umount chpst spawn-pty ptsname applyuidgid-caps; do
fi
done
./true
+./seccomp-run ./seccomp-default.bpf ./true
touch "$pthbs_destdir/home/ccx/versions/$pthbs_package/.install-links"
diff --git a/variants/ccx-x86_64/containers b/variants/ccx-x86_64/containers
@@ -6,7 +6,7 @@
#+alpine-keys.dedc78b0b50e461d33a449adf40691698925b5eb9af8a6b69e7c0ece6b708ef4
#+apk-tools.69a8c172d8dc6f60957469c555cfa3627fef38bb076dde5f758fd64854ecb275
#+xbps.0c1ece8bbd380938c5c0744cf9d37f2a2f402dd2f16dfe9b9ec891a5c84b9646
-#+container-bin-image.e6f30e71f261c10834f69d5b5bef43d289d123b603c80588d84a65185336b313
+#+container-bin-image.4c84a6f58f3b3192604256b2ab28c850f9a44103d68c92b766ca02ef904c857d
#@git:407c24d106815e8f7d2563b88f348d171e441b9b:containers
: ${JOBS:=1}
@@ -58,9 +58,9 @@ for f in '/home/ccx/versions/xbps.0c1ece8bbd380938c5c0744cf9d37f2a2f402dd2f16dfe
ln -sf "$f" "$pkgdir/deps/keys/void/"
done
-test -d '/home/ccx/versions/container-bin-image.e6f30e71f261c10834f69d5b5bef43d289d123b603c80588d84a65185336b313/container-bin-image'
-test -f '/home/ccx/versions/container-bin-image.e6f30e71f261c10834f69d5b5bef43d289d123b603c80588d84a65185336b313/container-bin-image/if'
-ln -sf '/home/ccx/versions/container-bin-image.e6f30e71f261c10834f69d5b5bef43d289d123b603c80588d84a65185336b313/container-bin-image' "$pkgdir/deps/"
+test -d '/home/ccx/versions/container-bin-image.4c84a6f58f3b3192604256b2ab28c850f9a44103d68c92b766ca02ef904c857d/container-bin-image'
+test -f '/home/ccx/versions/container-bin-image.4c84a6f58f3b3192604256b2ab28c850f9a44103d68c92b766ca02ef904c857d/container-bin-image/if'
+ln -sf '/home/ccx/versions/container-bin-image.4c84a6f58f3b3192604256b2ab28c850f9a44103d68c92b766ca02ef904c857d/container-bin-image' "$pkgdir/deps/"
cd "$pthbs_destdir/home/ccx/versions/$pthbs_package"
find -type d -o -print | awk -F/ '
diff --git a/variants/ccx-x86_64/containers.environment b/variants/ccx-x86_64/containers.environment
@@ -7,7 +7,7 @@
#+s6-linux-utils.1990b55837ff2c28a81500d80292c6d530c8516347eb896007eb5aed2af6c425
#+zsh.f79a20125b2f520d3719411e6f0895cf4f2e0657565c3fef07b3069436b8960f
#+confz.9733b0a5d832c848bfeeb2dc737c05a77163fc4d8aca4156a18f2074f2902b8a
-#+containers.7563bf7d40a4ff58200a8280fb76436498ec57f519160db1e6aa34aef4159bc4
+#+containers.d2c7115fcba11b929a3dac4ef0f2552630358ede6feda350bb0ca42118599a28
#+xbps.0c1ece8bbd380938c5c0744cf9d37f2a2f402dd2f16dfe9b9ec891a5c84b9646
#+zstd.8b11bd81c450d61aa6a44ffd019654c590439df68ebd8987db4cdbbcf182d67c
#+apk-tools.69a8c172d8dc6f60957469c555cfa3627fef38bb076dde5f758fd64854ecb275
diff --git a/variants/ccx-x86_64/default.environment b/variants/ccx-x86_64/default.environment
@@ -21,7 +21,7 @@
#+pthbs-banginstall.7ddbf08ba8b1298841fad793d4ed7ba4979b9346155195489fc5e492ed5f0fe2
#+aat.0698d0082830b7f8bcf3840f3f8c25382ef2d9f174dd6d5407c5e2132d1f16e4
#+confz.9733b0a5d832c848bfeeb2dc737c05a77163fc4d8aca4156a18f2074f2902b8a
-#+containers.7563bf7d40a4ff58200a8280fb76436498ec57f519160db1e6aa34aef4159bc4
+#+containers.d2c7115fcba11b929a3dac4ef0f2552630358ede6feda350bb0ca42118599a28
#+fileset.4e84d6846c9db82c5ad691b8a6b63b6364b367e84f9d1490b0942b3fa28f3737
#+logincaps.04accf875f567934eb11016453454f691d056c66e0dc36a971f98aaaefdbe360
#+snaprep.00aa9b9a8cd250e823959881ee26d93cab1be5fe7bbb06ad9abc7242c481b4f7
@@ -37,8 +37,8 @@
#+ccx-utils.ab28a8d701f60db69818ef22c546d02eca1ba3900bcdeaf5676bcc13d4b7f114
#+user-env.4e95a5387aa403e1d16a22254f21fb4cec046c69341a5eae764dd8126fb638a8
#+strace.53097be3dbf67dbf52aa675a59980a7d965fd8cdf965ef3005035e70fc7e4103
-#+system-config.b37446f0d6108dc2b1117d704a934d58a4a9dd2840b41492829ccacae0a86923
-#+system-config-rc.d9d351c57a9b58ef2fecd50e0e61c1d071eb7a9843c63fe2b1693226a3dc7112
+#+system-config.77496a65e140bd5a044907a4ef2caa8589a55baee12349c9f1596453637e7149
+#+system-config-rc.cc22d6358a81052208b053cdf49418f3beb94816f09130264b7b796db6ab6236
#+system-config-scripts.bdedb957b96fc1efd8259d16dac786d1d9c220dcde66996a16688989f104925d
-#+system-config-init.be709024368e88c46ecd583b850421938885d73be1e5b84ccfa138fe4fb2259c
+#+system-config-init.8ca336ed10b28842c76a22422713239fcca10993fe60c58f161f859414253da9
#+system-config-zsh.250277c1fe17ccb13b5efbacd35ecb3b8342e30910cdd709f89475773bb7f309
\ No newline at end of file
diff --git a/variants/ccx-x86_64/system-config b/variants/ccx-x86_64/system-config
@@ -52,7 +52,7 @@ printf '%s\n' >config/etc/skel/loginexec \
chmod +x config/etc/skel/loginexec
env 'pthbs_path_system-config'="$prefix" \
- 'pthbs_path_containers=/home/ccx/versions/env.0aec3dc10c3d2eb0cfd7cb80658528b5d5c2d631a0790cb2cd041a5398b20d87' \
+ 'pthbs_path_containers=/home/ccx/versions/env.8f095befa23780afd171865c03d6523aebbc72b8f89596dc5766ad72464f4fec' \
'pthbs_path_mdevd=/home/ccx/versions/env.5049027ea8b6b4d373e16aadd3cdc63a940582ff297656e395f2131eef181671' \
make -j${JOBS:-1} -l$((1+${JOBS:-1})) all
diff --git a/variants/ccx-x86_64/system-config-init b/variants/ccx-x86_64/system-config-init
@@ -5,9 +5,9 @@
#+s6-portable-utils.1b8fd31be72bfe84afb28c3dfff03b1fc45121d11fc85f79c90f085fe61bc132
#+s6-linux-init.cd3e307b62e7dde98e1572eed297bd544e888d2589d4c1e7fd79271c4078ddf2
#+execline.1505a32c24aa5dbf362550f39283c9ff1936e717e5a82d220f8212cd9e604d8f
-#+system-config-rc.d9d351c57a9b58ef2fecd50e0e61c1d071eb7a9843c63fe2b1693226a3dc7112
+#+system-config-rc.cc22d6358a81052208b053cdf49418f3beb94816f09130264b7b796db6ab6236
-s6rcdb=/home/ccx/versions/system-config-rc.d9d351c57a9b58ef2fecd50e0e61c1d071eb7a9843c63fe2b1693226a3dc7112/config/s6-rc-db
+s6rcdb=/home/ccx/versions/system-config-rc.cc22d6358a81052208b053cdf49418f3beb94816f09130264b7b796db6ab6236/config/s6-rc-db
prefix=/home/ccx/versions/$pthbs_package
pkgdir="$pthbs_destdir/$prefix"
diff --git a/variants/ccx-x86_64/system-config-rc b/variants/ccx-x86_64/system-config-rc
@@ -3,7 +3,7 @@
#+busybox-diffutils.c2ebcfcad050ad71b8e30322a463b5c009f254c7a42e95c627d32665e17134dc
#+s6-rc.fecfa43aebb0615904e0e120b9ce8c0596c9b6c577611cbadc8fbaca75196ed9
#+fileset.4e84d6846c9db82c5ad691b8a6b63b6364b367e84f9d1490b0942b3fa28f3737
-#+system-config.b37446f0d6108dc2b1117d704a934d58a4a9dd2840b41492829ccacae0a86923
+#+system-config.77496a65e140bd5a044907a4ef2caa8589a55baee12349c9f1596453637e7149
def_prefix() {
prefix=/home/ccx/versions/$pthbs_package
@@ -13,7 +13,7 @@ def_dest() {
}
def_dest
-src=/home/ccx/versions/system-config.b37446f0d6108dc2b1117d704a934d58a4a9dd2840b41492829ccacae0a86923/config/s6-rc-source
+src=/home/ccx/versions/system-config.77496a65e140bd5a044907a4ef2caa8589a55baee12349c9f1596453637e7149/config/s6-rc-source
s6-rc-compile ./s6-rc-db "$src"
mkdir -p "$dest/config"
mv -v s6-rc-db "$dest/config/"
diff --git a/variants/ccx-x86_64/userspace.environment b/variants/ccx-x86_64/userspace.environment
@@ -21,7 +21,7 @@
#+pthbs-banginstall.7ddbf08ba8b1298841fad793d4ed7ba4979b9346155195489fc5e492ed5f0fe2
#+aat.0698d0082830b7f8bcf3840f3f8c25382ef2d9f174dd6d5407c5e2132d1f16e4
#+confz.9733b0a5d832c848bfeeb2dc737c05a77163fc4d8aca4156a18f2074f2902b8a
-#+containers.7563bf7d40a4ff58200a8280fb76436498ec57f519160db1e6aa34aef4159bc4
+#+containers.d2c7115fcba11b929a3dac4ef0f2552630358ede6feda350bb0ca42118599a28
#+fileset.4e84d6846c9db82c5ad691b8a6b63b6364b367e84f9d1490b0942b3fa28f3737
#+logincaps.04accf875f567934eb11016453454f691d056c66e0dc36a971f98aaaefdbe360
#+snaprep.00aa9b9a8cd250e823959881ee26d93cab1be5fe7bbb06ad9abc7242c481b4f7
diff --git a/variants/root-x86_64/container-bin-image b/variants/root-x86_64/container-bin-image
@@ -45,6 +45,7 @@ for cmd in if busybox umount chpst spawn-pty ptsname applyuidgid-caps; do
fi
done
./true
+./seccomp-run ./seccomp-default.bpf ./true
touch "$pthbs_destdir/versions/$pthbs_package/.install-links"
diff --git a/variants/root-x86_64/containers b/variants/root-x86_64/containers
@@ -6,7 +6,7 @@
#+alpine-keys.4ecd9fac6efcc329a98af1b0b1318771a77eb83ac10832c6e769ebf11c14cae1
#+apk-tools.f56b624a4ea26318bf9117754fb5e0c564f7f466fedde43e1c45e86278dc2552
#+xbps.e82f8c85f25413cdfa1e23926d635ec0d5aa6059a953750d63de49eeacf3c672
-#+container-bin-image.746d8918ab62aeb0bfceb2dcd1b6cf7c4e50ad85f16513e85d1466c2607ff9d0
+#+container-bin-image.1fe318e09d22c2bd14afd4c2ba1e1b0b6cff2a31e18c9417c25a1e284730fb47
#@git:407c24d106815e8f7d2563b88f348d171e441b9b:containers
: ${JOBS:=1}
@@ -58,9 +58,9 @@ for f in '/versions/xbps.e82f8c85f25413cdfa1e23926d635ec0d5aa6059a953750d63de49e
ln -sf "$f" "$pkgdir/deps/keys/void/"
done
-test -d '/versions/container-bin-image.746d8918ab62aeb0bfceb2dcd1b6cf7c4e50ad85f16513e85d1466c2607ff9d0/container-bin-image'
-test -f '/versions/container-bin-image.746d8918ab62aeb0bfceb2dcd1b6cf7c4e50ad85f16513e85d1466c2607ff9d0/container-bin-image/if'
-ln -sf '/versions/container-bin-image.746d8918ab62aeb0bfceb2dcd1b6cf7c4e50ad85f16513e85d1466c2607ff9d0/container-bin-image' "$pkgdir/deps/"
+test -d '/versions/container-bin-image.1fe318e09d22c2bd14afd4c2ba1e1b0b6cff2a31e18c9417c25a1e284730fb47/container-bin-image'
+test -f '/versions/container-bin-image.1fe318e09d22c2bd14afd4c2ba1e1b0b6cff2a31e18c9417c25a1e284730fb47/container-bin-image/if'
+ln -sf '/versions/container-bin-image.1fe318e09d22c2bd14afd4c2ba1e1b0b6cff2a31e18c9417c25a1e284730fb47/container-bin-image' "$pkgdir/deps/"
cd "$pthbs_destdir/versions/$pthbs_package"
find -type d -o -print | awk -F/ '
diff --git a/variants/root-x86_64/containers.environment b/variants/root-x86_64/containers.environment
@@ -7,7 +7,7 @@
#+s6-linux-utils.f7e0654375f11beedafd731ad1dd66c0de8d03452bb8e38bb647cc51cc3adb2e
#+zsh.4ac9e4166454e8d60c15837b7ca4938abe99db029b3fffa11b1cfd54d40ae09b
#+confz.2c5f5b9bb69976bb57be5de332d8e7a2cf69c0b41c006ee7e6912abe8e8a0edf
-#+containers.8c6eaef822dc88dfd9e8903b3a37115a9238408bb9504ca1485800f9fb8a986e
+#+containers.448e316caaabf795f9fdfe82ea26481ccff3d02cfb908a98123d1410fc7bbe95
#+xbps.e82f8c85f25413cdfa1e23926d635ec0d5aa6059a953750d63de49eeacf3c672
#+zstd.a83f72c5953bd6b7afc171528a503710b3144bf9197961833fd27926b0a18137
#+apk-tools.f56b624a4ea26318bf9117754fb5e0c564f7f466fedde43e1c45e86278dc2552
diff --git a/variants/root-x86_64/default.environment b/variants/root-x86_64/default.environment
@@ -21,7 +21,7 @@
#+pthbs-banginstall.30ed98ef3fedfb6b25b3f58c27e845f123a22a756b37a5cd75764315bba23571
#+aat.9432aa485263e75ca3e43d6511c561a9cd328c417ebe26b890ed4a8061fee06f
#+confz.2c5f5b9bb69976bb57be5de332d8e7a2cf69c0b41c006ee7e6912abe8e8a0edf
-#+containers.8c6eaef822dc88dfd9e8903b3a37115a9238408bb9504ca1485800f9fb8a986e
+#+containers.448e316caaabf795f9fdfe82ea26481ccff3d02cfb908a98123d1410fc7bbe95
#+fileset.7159458f5e8c9237e1e1708cafced263dd342d5fd24ccec97ae8092d9b1c5150
#+logincaps.3c7957125c5700c2436df091d2fba6324b1ac5f2bfcd54948f6a5b8049047afc
#+snaprep.73784e7863284b4cc1597b76b0d869eb2eaaa5eed08245e629937044a2c0c3b5
@@ -37,8 +37,8 @@
#+ccx-utils.ccaa449ada3142ef075f3c80a6e475520219814490557f308ded4685231a70ac
#+user-env.8ad55eebe32b11f005f7b5c6dc204fdccc0a53cd7294f87c1e959ea47793dbca
#+strace.ce1707d2cf1dfcd965827af80a18c6b97ca20b563b8967be8297322e8adf9296
-#+system-config.9a42af2bc16fa1b8e9a1d8e5bf97dd87ef4625539b683a17f88705f5774b844e
-#+system-config-rc.2e32a114ee9404f6d327b002b673c22e66a10decb7e713c94ce6d51962242d00
+#+system-config.7d83666dabed7929982173b00e506e05a81b9e4acd4a87f2ff55ac7ff750aef0
+#+system-config-rc.d13eeff8d6496045a8714e23dc129b8ff961650fa2ea5fc1b5894855395b193d
#+system-config-scripts.4c00e32b8c4f6feef53b562356abd54830cc7e889149e4f8bcb928d6e6e93378
-#+system-config-init.331b1d98f190a8f83091db8651f09824e71d2e65af7fd046dd378b423e6a0170
+#+system-config-init.fb9e66f20e380e6bf4050e48b837a7b01eb2ad450acf66e14ec164e0b0335703
#+system-config-zsh.01286ec545c7035b2e08ded96e40b73f912f33fd7eec44993a1e93e12577dc0f
\ No newline at end of file
diff --git a/variants/root-x86_64/system-config b/variants/root-x86_64/system-config
@@ -52,7 +52,7 @@ printf '%s\n' >config/etc/skel/loginexec \
chmod +x config/etc/skel/loginexec
env 'pthbs_path_system-config'="$prefix" \
- 'pthbs_path_containers=/versions/env.abc4d5a5c1e69b8e20a871c6686aaf31d3cfa3e48a2f566993bd16f9aa814d67' \
+ 'pthbs_path_containers=/versions/env.bf96972a0fbbd37fa1d3eafc87500d03c5e1ce2168c68f1ec1ccbfed6ca4e4eb' \
'pthbs_path_mdevd=/versions/env.699c310193b7957c8ec17e16d6846443f99c198e3e2ce6425066f4523de2cf1e' \
make -j${JOBS:-1} -l$((1+${JOBS:-1})) all
diff --git a/variants/root-x86_64/system-config-init b/variants/root-x86_64/system-config-init
@@ -5,9 +5,9 @@
#+s6-portable-utils.f6171ad521d6be72875f1d5c1b28f966662ba93cfe5790e1ef010f9e76211bc3
#+s6-linux-init.8fbed3537ce9accc1a31e36f4648d1a0df0f1d155fcfa8fb5b1079786cf1442c
#+execline.c89bee1b1207461afa2d2ab9250f0940a2a6bbca3e45bdd60037049a75f4adf9
-#+system-config-rc.2e32a114ee9404f6d327b002b673c22e66a10decb7e713c94ce6d51962242d00
+#+system-config-rc.d13eeff8d6496045a8714e23dc129b8ff961650fa2ea5fc1b5894855395b193d
-s6rcdb=/versions/system-config-rc.2e32a114ee9404f6d327b002b673c22e66a10decb7e713c94ce6d51962242d00/config/s6-rc-db
+s6rcdb=/versions/system-config-rc.d13eeff8d6496045a8714e23dc129b8ff961650fa2ea5fc1b5894855395b193d/config/s6-rc-db
prefix=/versions/$pthbs_package
pkgdir="$pthbs_destdir/$prefix"
diff --git a/variants/root-x86_64/system-config-rc b/variants/root-x86_64/system-config-rc
@@ -3,7 +3,7 @@
#+busybox-diffutils.4a0933977737282afcd82b39d435b50946a700fe13472d24e4580a41fa852123
#+s6-rc.c131bb99b2054bcd9705c5a5652822938265a8587a54d2894667b8b620815c7f
#+fileset.7159458f5e8c9237e1e1708cafced263dd342d5fd24ccec97ae8092d9b1c5150
-#+system-config.9a42af2bc16fa1b8e9a1d8e5bf97dd87ef4625539b683a17f88705f5774b844e
+#+system-config.7d83666dabed7929982173b00e506e05a81b9e4acd4a87f2ff55ac7ff750aef0
def_prefix() {
prefix=/versions/$pthbs_package
@@ -13,7 +13,7 @@ def_dest() {
}
def_dest
-src=/versions/system-config.9a42af2bc16fa1b8e9a1d8e5bf97dd87ef4625539b683a17f88705f5774b844e/config/s6-rc-source
+src=/versions/system-config.7d83666dabed7929982173b00e506e05a81b9e4acd4a87f2ff55ac7ff750aef0/config/s6-rc-source
s6-rc-compile ./s6-rc-db "$src"
mkdir -p "$dest/config"
mv -v s6-rc-db "$dest/config/"
diff --git a/variants/root-x86_64/userspace.environment b/variants/root-x86_64/userspace.environment
@@ -21,7 +21,7 @@
#+pthbs-banginstall.30ed98ef3fedfb6b25b3f58c27e845f123a22a756b37a5cd75764315bba23571
#+aat.9432aa485263e75ca3e43d6511c561a9cd328c417ebe26b890ed4a8061fee06f
#+confz.2c5f5b9bb69976bb57be5de332d8e7a2cf69c0b41c006ee7e6912abe8e8a0edf
-#+containers.8c6eaef822dc88dfd9e8903b3a37115a9238408bb9504ca1485800f9fb8a986e
+#+containers.448e316caaabf795f9fdfe82ea26481ccff3d02cfb908a98123d1410fc7bbe95
#+fileset.7159458f5e8c9237e1e1708cafced263dd342d5fd24ccec97ae8092d9b1c5150
#+logincaps.3c7957125c5700c2436df091d2fba6324b1ac5f2bfcd54948f6a5b8049047afc
#+snaprep.73784e7863284b4cc1597b76b0d869eb2eaaa5eed08245e629937044a2c0c3b5