From 8ad53be223dbea0cc1368f73f9ca6ea772e618d8 Mon Sep 17 00:00:00 2001 From: pufferffish Date: Sat, 13 Apr 2024 02:35:48 +0100 Subject: [PATCH] remove /dev/std{in,out,err} from landlock restriction --- cmd/wireproxy/main.go | 3 --- 1 file changed, 3 deletions(-) diff --git a/cmd/wireproxy/main.go b/cmd/wireproxy/main.go index 86f7a12..a4e6a8d 100644 --- a/cmd/wireproxy/main.go +++ b/cmd/wireproxy/main.go @@ -93,9 +93,6 @@ func lock(stage string) { landlock.RWFiles("/dev/log"), landlock.RWFiles("/dev/null"), landlock.RWFiles("/dev/full"), - landlock.RWFiles("/dev/stdin"), - landlock.RWFiles("/dev/stdout"), - landlock.RWFiles("/dev/stderr"), landlock.RWFiles("/proc/self/fd"), )) default: