mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
feat: Add support for Landlock based Sandbox for Linux (#238)
* feat: Initial implementation of landlock based sandbox driver * fix: Handle seccom probe failure * fix: Remove unnecessary seccomp probe * fix: Use file based policy load * fix: Keep bpf filter in memory * fix: Use TSYNC for seccom filter * fix: Use TSYNC for seccom filter * fix: Update landlock translator * fix: Landlock sandbox implementation * fix: Landlock + seccomp based sandboxing on Linux * fix: Misc fixes * fix: Cleanup sandbox files * fix: Handle mandatory deny API change post merge * fix: Landlock write access translation * chore: Fix linter issues * ci: Use /tmp for npm cache for landlock
This commit is contained in:
@@ -9,6 +9,7 @@ import (
|
||||
"github.com/safedep/dry/log"
|
||||
"github.com/safedep/pmg/cmd/cloud"
|
||||
"github.com/safedep/pmg/cmd/executors"
|
||||
landlockCmd "github.com/safedep/pmg/cmd/landlock"
|
||||
"github.com/safedep/pmg/cmd/npm"
|
||||
"github.com/safedep/pmg/cmd/pypi"
|
||||
"github.com/safedep/pmg/cmd/setup"
|
||||
@@ -136,6 +137,13 @@ func main() {
|
||||
cmd.AddCommand(setup.NewRemoveCommand())
|
||||
cmd.AddCommand(cloud.NewCloudCommand())
|
||||
|
||||
if subcmd := landlockCmd.NewLandlockSandboxExecCommand(); subcmd != nil {
|
||||
cmd.AddCommand(subcmd)
|
||||
}
|
||||
if subcmd := landlockCmd.NewLandlockShimCommand(); subcmd != nil {
|
||||
cmd.AddCommand(subcmd)
|
||||
}
|
||||
|
||||
// Print Banner on --help / -h
|
||||
cmd.SetHelpFunc(func(command *cobra.Command, args []string) {
|
||||
fmt.Print(ui.GeneratePMGBanner(appVersion.Version, appVersion.Commit))
|
||||
|
||||
Reference in New Issue
Block a user