projects
/
project
/
procd.git
/ search
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
first ⋅ prev ⋅
next
treewide: replace local mkdir_p implementations
2020-12-12
Daniel Golle
treewide: replace local mkdir_p implementations
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-12-09
Daniel Golle
jail: remove unreachable code
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-12-04
Daniel Golle
early: fall-back to run ubus as root if user can't...
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-12-01
Daniel Golle
jail: improve seccomp log output
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-30
Daniel Golle
jail: seccomp: improve code readability
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-30
Daniel Golle
jail: always call cgroups_free()
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-30
Daniel Golle
jail: improve seccomp BPF generator
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: properly initialize timens_fd
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: enter existing cgroups namespace if given
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: don't attempt to mount /sys with noatime
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: fix typo in usage output
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: seteuid before clone(CLONE_NEWUSER)
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: don't fail if can't mount-bind /etc/resolv.conf
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: don't use NULL arguments for mount syscall
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: relax /etc/resolv.conf creation
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: fix and simplify userns uid/gid maps from OCI
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: fix segfault on missing name and refactor
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-27
Daniel Golle
jail: leak less memory
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-22
Daniel Golle
jail: add 'debug' extern variable to preload_seccomp
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-22
Daniel Golle
uxc: also delete procd runtime state on 'delete'
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-22
Daniel Golle
uxc: fix incomplete commit
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-21
Daniel Golle
jail: cgroup hack: rewrite cgroup -> cgroup2
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-21
Daniel Golle
seccomp: silence 'unknown syscall' warnings
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-21
Daniel Golle
uxc: make force-delete kill container process
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-17
Daniel Golle
trace: switch to OCI seccomp JSON output
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-15
Daniel Golle
seccomp: switch to new OCI compliant parser
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-15
Daniel Golle
seccomp: specifying architectures is optional
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-11-07
Daniel Golle
jail: fix capabilities
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-28
Daniel Golle
uxc: mimic runc cmdline by using getopt_long
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-28
Daniel Golle
jail: don't fail if maskedPath cannot be found
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-28
Daniel Golle
jail: add support for absolute root path in OCI spec
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-28
Daniel Golle
jail: relax seccomp unknown syscall handling
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-28
Daniel Golle
jail: handle mount propagation flags
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-28
Daniel Golle
jail: add option for pidfile
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-28
Daniel Golle
jail: guard boolean blobmsg attributes
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-23
Daniel Golle
ujail: elf: work around GCC bug on MIPS64
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-22
Daniel Golle
jail: mount more stuff read-only
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-21
Daniel Golle
jail: capabilities: apply in two phases
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-19
Daniel Golle
jail: nuke old capabilities code in favour of reusing...
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-19
Daniel Golle
instance: actually wire up capabilities filename
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-19
Daniel Golle
jail: adapt to new ubus socket path
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-10-19
Daniel Golle
early: run ubusd non-root as user ubus, group ubus
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-08-13
Daniel Golle
cgroups: memory controller fixes
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-08-13
Daniel Golle
cgroups: restrict allowed keys in 'unified' section
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-08-10
Thomas Petazzoni
initd/init: add minimal SELinux policy loading support
commit
|
commitdiff
|
tree
2020-08-06
Daniel Golle
jail: fix freeing cgroups avl
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-08-06
Daniel Golle
jail: only free cgroups if they were allocated
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-08-06
Daniel Golle
jail: parse OCI cgroups resources
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-08-06
Daniel Golle
instance: add instances into unified cgroup hierarchy
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-08-06
Daniel Golle
jail: make use of BLOBMSG_CAST_INT64 for OCI rlimits
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-08-06
Daniel Golle
jail: use pidns semantics also for timens
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-08-06
Daniel Golle
initd: attempt to mount cgroup2
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-30
Daniel Golle
service: add method to query available container features
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-30
Daniel Golle
uxc: remove debugging left-over
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-30
Daniel Golle
instance: make sure values are not inherited from previous...
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-29
Daniel Golle
uxc: use new container.%s kill ubus API
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-29
Daniel Golle
jail: add 'kill' method to container.%s object
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-29
Daniel Golle
uxc: fix create operation
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-28
Daniel Golle
uxc: behave more like a compliant OCI run-time
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-28
Daniel Golle
jail: add some remaining OCI features
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-25
Daniel Golle
jail: serialize hook execution
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-25
Daniel Golle
jail: fix build on glibc and uclibc
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-21
Daniel Golle
jail: add support for referencing existing namespaces
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-20
Rosen Penev
jail: fix wrong format for 32-bit
commit
|
commitdiff
|
tree
2020-07-20
Rosen Penev
rcS: cast format string to int64_t
commit
|
commitdiff
|
tree
2020-07-20
Daniel Golle
jail: re-implement /proc/sys/net read-write in netns...
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-20
Daniel Golle
jail: refactor default mounts into new structure
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-20
Daniel Golle
jail: actually apply filesystem-specific mount options
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-20
Daniel Golle
jail: add support for defining devices
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-20
Daniel Golle
jail: move /tmp/resolv.conf.d to /dev/resolv.conf.d
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-19
Daniel Golle
jail: /proc/$pid/oom_score_adj to OCI defined oomScoreAdj
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-19
Daniel Golle
jail: parse and apply POSIX rlimits
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-19
Daniel Golle
jail: read and apply umask from OCI if defined
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-19
Daniel Golle
jail: implement OCI user additionalGIDs
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-19
Daniel Golle
jail: parse and apply OCI sysctl values
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-19
Daniel Golle
jail: fix hooks
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-17
Daniel Golle
jail: add support for maskedPaths and readonlyPaths
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-16
Daniel Golle
jail: fix some more mount options
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-15
Daniel Golle
jail: fs: fix build on uClibc-ng
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-15
Daniel Golle
procd: fix compile if procd-ujail is not selected
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-13
Daniel Golle
jail: fix false return in case of nofail mount
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-13
Daniel Bailey
procd: add service instance watchdog
commit
|
commitdiff
|
tree
2020-07-13
Daniel Golle
uxc: fix build with uClibc-ng
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-13
Daniel Golle
uxc: fix 'stop' command
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-13
Daniel Golle
jail: don't make mount source read-only
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-13
Daniel Golle
jail: refactor mount support to cover OCI spec
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-13
Daniel Golle
jail: memory allocation fixes
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-13
Daniel Golle
jail: parse and run OCI hooks
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-13
Daniel Golle
jail: actually chdir into OCI defined CWD
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-13
Daniel Golle
jail: consider PATH for argv in OCI container
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-13
Daniel Golle
jail: fix segfault with len(uidmap/gidmap) > 1
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-11
Daniel Golle
jail: use linux/capability.h instead of sys/capability.h
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-11
Daniel Golle
ujail: add dependency on syscall-names-h
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-10
Daniel Golle
jail: fix build on platforms without seccomp support
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-10
Daniel Golle
uxc: add container management CLI tool
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-07-10
Daniel Golle
jail: add support for running OCI bundle
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-05-28
Daniel Golle
jail: handle containers seperately
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-05-28
Daniel Golle
jail: use sane termios settings for console pts
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-05-15
Daniel Golle
jail: add option to provide /dev/console to containers
Signed-off-by:
Daniel Golle
<daniel@makrotopia.org>
commit
|
commitdiff
|
tree
2020-05-15
Leonardo Mörlein
jail: unnamed jails can not have netns (fix segfault)
commit
|
commitdiff
|
tree
next