The --landlock and --landlock-rules arguments were in the "vm-config" argument group, which requires the "vm-payload" group (--kernel or --firmware). This prevented using --landlock with API-socket-only mode, where the VM is configured later via the REST API. Remove these arguments from the "vm-config" group so that landlock process hardening can be enabled independently of VM payload configuration. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| src | ||
| tests | ||
| build.rs | ||
| Cargo.toml | ||