@@ -28,7 +28,6 @@ import (
2828 specs "github.com/opencontainers/runtime-spec/specs-go"
2929 "golang.org/x/sys/unix"
3030 "gvisor.dev/gvisor/pkg/abi/linux"
31- "gvisor.dev/gvisor/pkg/bpf"
3231 "gvisor.dev/gvisor/pkg/cleanup"
3332 "gvisor.dev/gvisor/pkg/context"
3433 "gvisor.dev/gvisor/pkg/coverage"
@@ -84,7 +83,6 @@ import (
8483 "gvisor.dev/gvisor/runsc/config"
8584 "gvisor.dev/gvisor/runsc/profile"
8685 "gvisor.dev/gvisor/runsc/specutils"
87- "gvisor.dev/gvisor/runsc/specutils/seccomp"
8886
8987 // Top-level inet providers.
9088 "gvisor.dev/gvisor/pkg/sentry/socket/hostinet"
@@ -1361,27 +1359,15 @@ func (l *Loader) createContainerProcess(info *containerInfo) (*kernel.ThreadGrou
13611359 info .procArgs .FDTable .DecRef (ctx )
13621360
13631361 // Install seccomp filters with the new task if there are any.
1364- if info .conf .OCISeccomp {
1365- if info .spec .Linux != nil && info .spec .Linux .Seccomp != nil {
1366- program , err := seccomp .BuildProgram (info .spec .Linux .Seccomp )
1367- if err != nil {
1368- return nil , nil , fmt .Errorf ("building seccomp program: %w" , err )
1369- }
1370-
1371- if log .IsLogging (log .Debug ) {
1372- out , _ := bpf .DecodeProgram (program )
1373- log .Debugf ("Installing OCI seccomp filters\n Program:\n %s" , out )
1374- }
1375-
1376- task := tg .Leader ()
1377- // NOTE: It seems Flags are ignored by runc so we ignore them too.
1378- if err := task .AppendSyscallFilter (program , true ); err != nil {
1379- return nil , nil , fmt .Errorf ("appending seccomp filters: %w" , err )
1380- }
1381- }
1382- } else {
1383- if info .spec .Linux != nil && info .spec .Linux .Seccomp != nil {
1384- log .Warningf ("Seccomp spec is being ignored" )
1362+ program , err := buildOCISeccompProgram (info .conf , info .spec )
1363+ if err != nil {
1364+ return nil , nil , err
1365+ }
1366+ if program != nil {
1367+ task := tg .Leader ()
1368+ // NOTE: It seems Flags are ignored by runc so we ignore them too.
1369+ if err := task .AppendSyscallFilter (* program , true ); err != nil {
1370+ return nil , nil , fmt .Errorf ("appending seccomp filters: %w" , err )
13851371 }
13861372 }
13871373
@@ -1524,6 +1510,16 @@ func (l *Loader) executeAsync(args *control.ExecArgs) (kernel.ThreadID, error) {
15241510 return 0 , fmt .Errorf ("creating limits: %w" , err )
15251511 }
15261512
1513+ containerName := l .k .ContainerName (args .ContainerID )
1514+ spec := l .containerSpecs [containerName ]
1515+ if spec != nil {
1516+ seccompProgram , err := buildOCISeccompProgram (l .root .conf , spec )
1517+ if err != nil {
1518+ return 0 , err
1519+ }
1520+ args .SeccompProgram = seccompProgram
1521+ }
1522+
15271523 // Start the process.
15281524 proc := control.Proc {Kernel : l .k }
15291525 newTG , tgid , ttyFile , err := control .ExecAsync (& proc , args )
0 commit comments