# Waydroid LXC Config
-lxc.rootfs.path = /home/.waydroid/rootfs
+lxc.rootfs.path = /var/lib/waydroid/rootfs
lxc.uts.name = waydroid
lxc.arch = LXCARCH
lxc.autodev = 0
# lxc.autodev.tmpfs.size = 25000000
lxc.apparmor.profile = unconfined
+lxc.seccomp.profile = /var/lib/waydroid/lxc/waydroid/waydroid.seccomp
+lxc.seccomp.allow_nesting = 1
+
+lxc.cap.keep = audit_control sys_nice wake_alarm setpcap setgid setuid sys_ptrace sys_admin wake_alarm block_suspend sys_time net_admin net_raw net_bind_service kill dac_override dac_read_search fsetid mknod syslog chown sys_resource fowner sys_module ipc_lock sys_chroot
+lxc.no_new_privs = 1
lxc.init.cmd = /init
lxc.net.0.mtu = 1500
lxc.console.path = none
+lxc.pty.max = 10
-lxc.include = /home/.waydroid/lxc/waydroid/config_nodes
+lxc.include = /var/lib/waydroid/lxc/waydroid/config_nodes
lxc.hook.post-stop = /dev/null