]> glassweightruler.freedombox.rocks Git - waydroid.git/blobdiff - data/configs/config_1
A seccomp profile for the entire container has been added.
[waydroid.git] / data / configs / config_1
index 9cc28f92ba8630ff9e65d2a7b687f1adf2561f18..33671c4c4a536c4b9525dbb3d24cdddd41ec24ab 100644 (file)
@@ -6,6 +6,9 @@ lxc.arch = LXCARCH
 lxc.autodev = 0
 # lxc.autodev.tmpfs.size = 25000000
 lxc.aa_profile = unconfined
+lxc.seccomp = /var/lib/waydroid/lxc/waydroid/waydroid.seccomp
+
+lxc.cap.keep = audit_control sys_nice wake_alarm setpcap setgid setuid sys_ptrace sys_admin wake_alarm block_suspend sys_time net_admin net_raw net_bind_service kill dac_override dac_read_search fsetid mknod syslog chown sys_resource fowner sys_module ipc_lock sys_chroot
 
 lxc.init_cmd = /init