oz icon indicating copy to clipboard operation
oz copied to clipboard

Remove seccomp policy files from container filesystem

Open dma opened this issue 9 years ago • 0 comments

Right now seccomp policy files are hand-whitelisted in the oz profile document. This was a temporary hack for a time when there was no oz-seccomp support at all in Oz.

Ideally the seccomp policy is read from outside of the Oz sandbox filesystem entirely, as is the JSON Oz profile, which is passed to oz-init via stdin.

dma avatar Feb 07 '16 19:02 dma