Daniel Golle
|
6963d5032b
jail: relax seccomp unknown syscall handling
|
4 years ago |
Daniel Golle
|
bba6de7531
jail: handle mount propagation flags
|
4 years ago |
Daniel Golle
|
602b8fa14a
jail: add option for pidfile
|
4 years ago |
Daniel Golle
|
2f381fe51c
jail: guard boolean blobmsg attributes
|
4 years ago |
Daniel Golle
|
33b799b94c
ujail: elf: work around GCC bug on MIPS64
|
4 years ago |
Daniel Golle
|
ec461ffea8
jail: mount more stuff read-only
|
4 years ago |
Daniel Golle
|
6c5233a16a
jail: capabilities: apply in two phases
|
4 years ago |
Daniel Golle
|
ebc5a7fe03
jail: nuke old capabilities code in favour of reusing OCI code
|
4 years ago |
Daniel Golle
|
788d144ec5
instance: actually wire up capabilities filename
|
4 years ago |
Daniel Golle
|
12a5b97711
jail: adapt to new ubus socket path
|
4 years ago |
Daniel Golle
|
3121467454
early: run ubusd non-root as user ubus, group ubus
|
4 years ago |
Daniel Golle
|
5ade5673d9
cgroups: memory controller fixes
|
4 years ago |
Daniel Golle
|
80c951668c
cgroups: restrict allowed keys in 'unified' section
|
4 years ago |
Thomas Petazzoni
|
fad899769e
initd/init: add minimal SELinux policy loading support
|
4 years ago |
Daniel Golle
|
ab55357dfe
jail: fix freeing cgroups avl
|
4 years ago |
Daniel Golle
|
282ff0c9a6
jail: only free cgroups if they were allocated
|
4 years ago |
Daniel Golle
|
16159bb1f7
jail: parse OCI cgroups resources
|
4 years ago |
Daniel Golle
|
83053b6a59
instance: add instances into unified cgroup hierarchy
|
4 years ago |
Daniel Golle
|
759e9f8b20
jail: make use of BLOBMSG_CAST_INT64 for OCI rlimits
|
4 years ago |
Daniel Golle
|
ead60fe102
jail: use pidns semantics also for timens
|
4 years ago |
Daniel Golle
|
afbaba926d
initd: attempt to mount cgroup2
|
4 years ago |
Daniel Golle
|
47a9f0d652
service: add method to query available container features
|
4 years ago |
Daniel Golle
|
2ae5cbcf1d
uxc: remove debugging left-over
|
4 years ago |
Daniel Golle
|
28be01131d
instance: make sure values are not inherited from previous runs
|
4 years ago |
Daniel Golle
|
08133b8e1d
uxc: use new container.%s kill ubus API
|
4 years ago |
Daniel Golle
|
2d811a4b88
jail: add 'kill' method to container.%s object
|
4 years ago |
Daniel Golle
|
12740336b3
uxc: fix create operation
|
4 years ago |
Daniel Golle
|
9d5fa0ae99
uxc: behave more like a compliant OCI run-time
|
4 years ago |
Daniel Golle
|
8ff89701c1
jail: add some remaining OCI features
|
4 years ago |
Daniel Golle
|
c3ca99f111
jail: serialize hook execution
|
4 years ago |