procd: jail fixes and improvements
authorDaniel Golle <daniel@makrotopia.org>
Tue, 14 Apr 2020 15:11:05 +0000 (16:11 +0100)
committerDaniel Golle <daniel@makrotopia.org>
Tue, 14 Apr 2020 15:16:06 +0000 (16:16 +0100)
commit7c2e0fa5865406d0f2d1987bdd2180c1d1913bf2
tree633d588eb3dea7382ed696201dd65b25a0782dd7
parente23de62845adaae0ac9a474a4f3a333ac890fc44
procd: jail fixes and improvements

 32c717e jail: only mess with rootfs if CLONE_NEWNS was set
 b275a62 instance: harmonize instance API
 511fd97 jail: make /proc more secure
 4953b7c jail: mount /sys read-only
 a4d6442 jail: replace /etc/resolv.conf with symlink in extroot+overlay
 a4cc165 jail: always mount /dev as additional tmpfs

Signed-off-by: Daniel Golle <daniel@makrotopia.org>
package/system/procd/Makefile