forked from security/hakurei
internal/pkg: use short wait delay
The cure is condemned at the point of cancellation and all of its state is destroyed by the deferred cleanup, so it makes little sense to wait for it much. Signed-off-by: Ophestra <cat@gensokyo.uk>
This commit is contained in:
@@ -194,7 +194,7 @@ func (a *execArtifact) Cure(c *CureContext) (err error) {
|
||||
|
||||
const (
|
||||
// execWaitDelay is passed through to [container.Params].
|
||||
execWaitDelay = 15 * time.Second
|
||||
execWaitDelay = time.Nanosecond
|
||||
)
|
||||
|
||||
// cure is like Cure but allows optional host net namespace. This is used for
|
||||
@@ -294,7 +294,6 @@ func (a *execArtifact) cure(c *CureContext, hostNet bool) (err error) {
|
||||
defer cancel()
|
||||
|
||||
z := container.New(ctx, a.msg)
|
||||
z.ForwardCancel = true
|
||||
z.WaitDelay = execWaitDelay
|
||||
z.SeccompPresets |= std.PresetStrict
|
||||
z.ParentPerm = 0700
|
||||
|
||||
Reference in New Issue
Block a user