M3b review fixes by the design model: curl --globoff, podman --pull=never
Review findings 1 and 2, both plan defects. curl gains --globoff and a leading --disable; both podman runs gain --pull=never. The given fetch.rs and the six golden files change with them. Checked on straylight with a rebuilt image: a glob URL is one request, a missing image fails at once. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -23,6 +23,9 @@ pub fn container_name(session: &SessionId, call: CallId, n: u64) -> String {
|
||||
/// takes the runner's, the proxy its fixed limits.
|
||||
fn hardening(pids: u32, memory: &str) -> Vec<OsString> {
|
||||
[
|
||||
// A missing image is an error at once, never a pull: a pull is egress, and what runs must
|
||||
// be exactly the image built for it.
|
||||
"--pull=never",
|
||||
"--read-only",
|
||||
"--cap-drop=all",
|
||||
"--security-opt=no-new-privileges",
|
||||
|
||||
Reference in New Issue
Block a user