Daniel Golle
|
111416d10b
jail: remove unreachable code
|
3 年之前 |
Daniel Golle
|
6acc48c7a2
early: fall-back to run ubus as root if user can't be found
|
3 年之前 |
Daniel Golle
|
09478ba230
jail: improve seccomp log output
|
4 年之前 |
Daniel Golle
|
4625350465
jail: seccomp: improve code readability
|
4 年之前 |
Daniel Golle
|
f67a66f196
jail: always call cgroups_free()
|
4 年之前 |
Daniel Golle
|
f3c35632a1
jail: improve seccomp BPF generator
|
4 年之前 |
Daniel Golle
|
31e0a46ded
jail: properly initialize timens_fd
|
4 年之前 |
Daniel Golle
|
b275b11d89
jail: enter existing cgroups namespace if given
|
4 年之前 |
Daniel Golle
|
b87984baf3
jail: don't attempt to mount /sys with noatime
|
4 年之前 |
Daniel Golle
|
e40828fa3f
jail: fix typo in usage output
|
4 年之前 |
Daniel Golle
|
acf36f2777
jail: seteuid before clone(CLONE_NEWUSER)
|
4 年之前 |
Daniel Golle
|
19ac9df877
jail: don't fail if can't mount-bind /etc/resolv.conf
|
4 年之前 |
Daniel Golle
|
db5ef86649
jail: don't use NULL arguments for mount syscall
|
4 年之前 |
Daniel Golle
|
4ba72ecf3a
jail: relax /etc/resolv.conf creation
|
4 年之前 |
Daniel Golle
|
5abee8f690
jail: fix and simplify userns uid/gid maps from OCI
|
4 年之前 |
Daniel Golle
|
7e01453752
jail: fix segfault on missing name and refactor
|
4 年之前 |
Daniel Golle
|
3019f50f62
jail: leak less memory
|
4 年之前 |
Daniel Golle
|
e935c0c043
jail: add 'debug' extern variable to preload_seccomp
|
4 年之前 |
Daniel Golle
|
d4d78dbe5e
uxc: also delete procd runtime state on 'delete'
|
4 年之前 |
Daniel Golle
|
df7fa7bae6
uxc: fix incomplete commit
|
4 年之前 |
Daniel Golle
|
b22e6254df
jail: cgroup hack: rewrite cgroup -> cgroup2
|
4 年之前 |
Daniel Golle
|
be6da628b1
seccomp: silence 'unknown syscall' warnings
|
4 年之前 |
Daniel Golle
|
04a2eddcb1
uxc: make force-delete kill container process
|
4 年之前 |
Daniel Golle
|
c110405181
trace: switch to OCI seccomp JSON output
|
4 年之前 |
Daniel Golle
|
d352e6e97f
seccomp: switch to new OCI compliant parser
|
4 年之前 |
Daniel Golle
|
d8f36f5378
seccomp: specifying architectures is optional
|
4 年之前 |
Daniel Golle
|
b0de894830
jail: fix capabilities
|
4 年之前 |
Daniel Golle
|
75f2374f16
uxc: mimic runc cmdline by using getopt_long
|
4 年之前 |
Daniel Golle
|
257f29b867
jail: don't fail if maskedPath cannot be found
|
4 年之前 |
Daniel Golle
|
e1fcfdcd88
jail: add support for absolute root path in OCI spec
|
4 年之前 |