]>
2021-02-05 | Christian Brauner | tree-wide: use lxc_drop_groups() instead of lxc_setgroups... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-05 | Christian Brauner | utils: add lxc_drop_groups() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | cgroups: check for correct error in __cg_unified_attach... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | tree-wide: s/dfd_root_host/dfd_host/g ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | tree-wide: s/mntpt_fd/dfd_mnt/g ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | tree-wide: s/dev_mntpt_fd/dfd_dev/g ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | syscall_wrappers: fix PROTECT_OPEN_W macro ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | conf: restricted fd-only lxc_fill_autodev() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | conf: start stashing dfd to host's / during container... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | conf: fix lxc_setup_dev_console() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | utils: add mount_from_at() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | cgroups: restrict open calls in cgroup_attach_create_leaf() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | cgroups: improve error handling and logging in cgroup_attach... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | cgroups: fix argument vetting in cgroup_attach() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | attach: fix fallback logic when attaching to cgroups ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | cgroups: switch to fd-based cgroup mounting ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | cgroups: restricted fd-only controller mountpoint creation ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-04 | Christian Brauner | cgroups: fix cgroup mounting ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | utils: harden __safe_mount_beneath_at() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: refactor transient procfs mounting ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: restrict open call in lxc_mount_rootfs() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: make lxc_create_tmp_proc_mount() static ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: coding style ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | attach: attach to namespaces via pidfds ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: fd-only devtps setup ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: fd-only pivot root ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: restrict open for lxc_mount_rootfs() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: fd-only operations in lxc_setup_dev_symlinks() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: harden open in lxc_fill_autodev() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: restrict open of dev/ ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: remove unnecessary syscall ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | rexec: mark all fds as close-on-exec if possible ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | syscalls: add close_range() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | rexec: check lseek() return value ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | tests: check for NULL in device_add_remove ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: improve parameter vetting ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | tests: support pure unified cgroup layouts in cgpath... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | test: add logging to device_add_remove ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | freezer: remove lxc_cmd_freeze() and lxc_cmd_unfreeze... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | commands: use __cgroup_unfreeze() directly ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: export __cgroup_unfreeze() for use in commands ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: use lxc_cmd_get_limiting_cgroup2_fd() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | commands: add missing lxc_cmd_get_limiting_cgroup2_fd... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgpath: add logging ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | attach: explicitly close seccomp notifier fd ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: switch back to returning ints ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | attach: check for ENOCGROUP2 explicitly ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: return ENOCGROUP2 from cgroup_attach() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: stricter argument vetting for cgroup_attach() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: move down cgroup_attach() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | lxccontainer: use correct error checks ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: vet parameters ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: remove unused conf argument ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: rewind() file before polling again ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | lxccontainer: use cgroup_freeze() and cgroup_unfreeze() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | freezer: make methods return bool ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: add cgroup_freeze() and cgroup_unfreeze() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | freezer: use lxc_cmd_notify_state_listeners() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | commands_utils: add lcx_cmd_notify_state_listeners() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: annotate cgroup_get()/cgroup_set() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: move functions after methods ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | lxccontainer: use cgroup_set() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | lxccontainer: use correct variable ordering ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: add croup_set() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: reorder cgroup_get() arguments ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | lxccontainer: use cgroup_get() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: add cgroup_get() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | file_utils: add lxc_read_try_buf_at() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | macro: abuse ENOMEDIUM as ENOCGROUP2 ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: switch controller delegation to fd-only operations ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: add unified_cgroup_fd() helper ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | file_utils: harden lxc_writeat() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | file_utils: harden lxc_open_dirfd() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | syscall_wrappers: add PROTECT_OPEN_W_* variants ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | memory_utils: add close_prot_errno_mov() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | attach: move loading seccomp as late as possible ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | attach: move file descriptor closing into attach_context_con... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | attach: stricter lookup semantics for fdopen_at() calls ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | confile_utils: use lxc_log_trace() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | conf: use lxc_log_trace() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | commands_utils: don't leak memory ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: use correct put method ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: prevent UAF ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: file descriptor based fdinfo handling ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | file_utils: remove O_NOFOLLOW from open_at() defaults ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | lsm: harden read_file_at() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | tree-wide: extend read_file_at() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: harden open calls ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | syscall_wrappers: add PROTECT_LOOKUP, PROTECT_OPEN... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | file_utils: add open_at() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | cgroups: initialize variable ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | cgroups: remove pointless NULL checks ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: stash host uid and host gid in attach_context ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: fix error checking for dup2() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: fix logging for stdfd replacement ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: log failues to dup2() with SYSDEBUG() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | utils: use SYSTRACE() when logging stdio permission... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: document attach_context ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: simplify opening of /proc/self ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: move uid and gid handling to get_attach_context() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
next |