Monorepo for Tangled

spindle/microvm: dont enable sandboxing in slirp4netns master

slirp4netns has a bug where it will break host devices on root user if this is enabled. so to avoid this, let's disable it. the sandboxing doesn't matter here because slirp4netns runs next to spindle anyway so if slirp is compromised you have bigger issues, and seccomp is still enabled, and if you really care your spindle should be a hardened systemd service anyway. Signed-off-by: dawn <dawn@tangled.org>


+19 -14
1 changed file