From 714718794236245e81d4552f30731157d731aa9d Mon Sep 17 00:00:00 2001 From: Brent Baude Date: Tue, 14 Apr 2020 14:13:06 -0500 Subject: v2specgen prune libpod use libpod only in the specgen/generate package so that the remote clients do not inherit libpod bloat. Signed-off-by: Brent Baude --- pkg/specgen/config_linux_cgo.go | 61 ----------------------------------------- 1 file changed, 61 deletions(-) delete mode 100644 pkg/specgen/config_linux_cgo.go (limited to 'pkg/specgen/config_linux_cgo.go') diff --git a/pkg/specgen/config_linux_cgo.go b/pkg/specgen/config_linux_cgo.go deleted file mode 100644 index ef6c6e951..000000000 --- a/pkg/specgen/config_linux_cgo.go +++ /dev/null @@ -1,61 +0,0 @@ -// +build linux,cgo - -package specgen - -import ( - "context" - "io/ioutil" - - "github.com/containers/libpod/libpod/image" - "github.com/containers/libpod/pkg/seccomp" - spec "github.com/opencontainers/runtime-spec/specs-go" - "github.com/pkg/errors" - goSeccomp "github.com/seccomp/containers-golang" - "github.com/sirupsen/logrus" -) - -func (s *SpecGenerator) getSeccompConfig(configSpec *spec.Spec, img *image.Image) (*spec.LinuxSeccomp, error) { - var seccompConfig *spec.LinuxSeccomp - var err error - scp, err := seccomp.LookupPolicy(s.SeccompPolicy) - if err != nil { - return nil, err - } - - if scp == seccomp.PolicyImage { - labels, err := img.Labels(context.Background()) - if err != nil { - return nil, err - } - imagePolicy := labels[seccomp.ContainerImageLabel] - if len(imagePolicy) < 1 { - return nil, errors.New("no seccomp policy defined by image") - } - logrus.Debug("Loading seccomp profile from the security config") - seccompConfig, err = goSeccomp.LoadProfile(imagePolicy, configSpec) - if err != nil { - return nil, errors.Wrap(err, "loading seccomp profile failed") - } - return seccompConfig, nil - } - - if s.SeccompProfilePath != "" { - logrus.Debugf("Loading seccomp profile from %q", s.SeccompProfilePath) - seccompProfile, err := ioutil.ReadFile(s.SeccompProfilePath) - if err != nil { - return nil, errors.Wrapf(err, "opening seccomp profile (%s) failed", s.SeccompProfilePath) - } - seccompConfig, err = goSeccomp.LoadProfile(string(seccompProfile), configSpec) - if err != nil { - return nil, errors.Wrapf(err, "loading seccomp profile (%s) failed", s.SeccompProfilePath) - } - } else { - logrus.Debug("Loading default seccomp profile") - seccompConfig, err = goSeccomp.GetDefaultProfile(configSpec) - if err != nil { - return nil, errors.Wrapf(err, "loading seccomp profile (%s) failed", s.SeccompProfilePath) - } - } - - return seccompConfig, nil -} -- cgit v1.2.3-54-g00ecf