iputils: sandbox with bunpen
This commit is contained in:
@@ -801,9 +801,10 @@ in
|
|||||||
# iptables.sandbox.capabilities = [ "net_admin" ];
|
# iptables.sandbox.capabilities = [ "net_admin" ];
|
||||||
|
|
||||||
# iputils provides `ping` (and arping, clockdiff, tracepath)
|
# iputils provides `ping` (and arping, clockdiff, tracepath)
|
||||||
iputils.sandbox.method = "landlock";
|
iputils.sandbox.method = "bunpen";
|
||||||
iputils.sandbox.net = "all";
|
iputils.sandbox.net = "all";
|
||||||
iputils.sandbox.capabilities = [ "net_raw" ];
|
iputils.sandbox.capabilities = [ "net_raw" ];
|
||||||
|
iputils.sandbox.tryKeepUsers = true; # for `sudo arping 10.78.79.1`
|
||||||
|
|
||||||
iw.sandbox.method = "landlock";
|
iw.sandbox.method = "landlock";
|
||||||
iw.sandbox.net = "all";
|
iw.sandbox.net = "all";
|
||||||
|
Reference in New Issue
Block a user