M3b review fixes by the design model: curl --globoff, podman --pull=never

Review findings 1 and 2, both plan defects. curl gains --globoff and a
leading --disable; both podman runs gain --pull=never. The given fetch.rs and
the six golden files change with them. Checked on straylight with a rebuilt
image: a glob URL is one request, a missing image fails at once.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-09-23 15:25:51 -07:00
co-authored by Claude Opus 5.5
parent 75c2f1adbf
commit c3aaecdae2
19 changed files with 37 additions and 5 deletions
+3
View File
@@ -23,6 +23,9 @@ pub fn container_name(session: &SessionId, call: CallId, n: u64) -> String {
/// takes the runner's, the proxy its fixed limits.
fn hardening(pids: u32, memory: &str) -> Vec<OsString> {
[
// A missing image is an error at once, never a pull: a pull is egress, and what runs must
// be exactly the image built for it.
"--pull=never",
"--read-only",
"--cap-drop=all",
"--security-opt=no-new-privileges",