]>
2021-02-03 | Christian Brauner | conf: restrict open for lxc_mount_rootfs() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: fd-only operations in lxc_setup_dev_symlinks() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: harden open in lxc_fill_autodev() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: restrict open of dev/ ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | conf: remove unnecessary syscall ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | rexec: mark all fds as close-on-exec if possible ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | syscalls: add close_range() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | rexec: check lseek() return value ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-03 | Christian Brauner | tests: check for NULL in device_add_remove ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: improve parameter vetting ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | tests: support pure unified cgroup layouts in cgpath... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | test: add logging to device_add_remove ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | freezer: remove lxc_cmd_freeze() and lxc_cmd_unfreeze... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | commands: use __cgroup_unfreeze() directly ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: export __cgroup_unfreeze() for use in commands ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: use lxc_cmd_get_limiting_cgroup2_fd() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | commands: add missing lxc_cmd_get_limiting_cgroup2_fd... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgpath: add logging ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | attach: explicitly close seccomp notifier fd ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: switch back to returning ints ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | attach: check for ENOCGROUP2 explicitly ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: return ENOCGROUP2 from cgroup_attach() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: stricter argument vetting for cgroup_attach() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: move down cgroup_attach() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | lxccontainer: use correct error checks ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: vet parameters ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: remove unused conf argument ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: rewind() file before polling again ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | lxccontainer: use cgroup_freeze() and cgroup_unfreeze() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | freezer: make methods return bool ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: add cgroup_freeze() and cgroup_unfreeze() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | freezer: use lxc_cmd_notify_state_listeners() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | commands_utils: add lcx_cmd_notify_state_listeners() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: annotate cgroup_get()/cgroup_set() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: move functions after methods ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | lxccontainer: use cgroup_set() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | lxccontainer: use correct variable ordering ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: add croup_set() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: reorder cgroup_get() arguments ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | lxccontainer: use cgroup_get() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: add cgroup_get() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | file_utils: add lxc_read_try_buf_at() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | macro: abuse ENOMEDIUM as ENOCGROUP2 ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: switch controller delegation to fd-only operations ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | cgroups: add unified_cgroup_fd() helper ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | file_utils: harden lxc_writeat() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | file_utils: harden lxc_open_dirfd() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | syscall_wrappers: add PROTECT_OPEN_W_* variants ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | memory_utils: add close_prot_errno_mov() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | attach: move loading seccomp as late as possible ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | attach: move file descriptor closing into attach_context_con... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-02 | Christian Brauner | attach: stricter lookup semantics for fdopen_at() calls ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | confile_utils: use lxc_log_trace() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | conf: use lxc_log_trace() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | commands_utils: don't leak memory ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: use correct put method ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: prevent UAF ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: file descriptor based fdinfo handling ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | file_utils: remove O_NOFOLLOW from open_at() defaults ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | lsm: harden read_file_at() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | tree-wide: extend read_file_at() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: harden open calls ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | syscall_wrappers: add PROTECT_LOOKUP, PROTECT_OPEN... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | file_utils: add open_at() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | cgroups: initialize variable ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | cgroups: remove pointless NULL checks ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: stash host uid and host gid in attach_context ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: fix error checking for dup2() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: fix logging for stdfd replacement ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: log failues to dup2() with SYSDEBUG() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | utils: use SYSTRACE() when logging stdio permission... ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: document attach_context ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: simplify opening of /proc/self ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: move uid and gid handling to get_attach_context() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: initialize init_pid field to -ESRCH ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | attach: unifiy /proc/<init-pid>/status parsing ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-02-01 | Christian Brauner | file_utils: add fdopenat() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-31 | Christian Brauner | lsm/apparmor: cleanup apparmor_process_label_set() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-31 | Christian Brauner | attach: hardening through use of pidfds ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-31 | Christian Brauner | attach: file descriptors based LSM handling ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-31 | Christian Brauner | cgroups: align methods ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | cgroups: use PTR_TO_U64() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | attach: don't needless check for NULL ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | log: add lxc_log_trace() helper ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | cgroups: use bpf log when logging at trace level ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | seccomp: use lxc_log_get_level() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | log: rework lxc_log_get_level() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | cgroups: use cleanup macro for consistency ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | cgroups: vet parameters more strictly ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | seccomp: use lxc_log_get_fd() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | log: add lxc_log_get_fd() ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | log: remove pointless inline ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | cgroups: tweak cgroup initialization ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | cgroups: use zalloc ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | cgroups: ensure all memory is zeroed ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | cgroups: don't initiliaze NULL log ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | cgroups: coding style fixes ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | croups: improve __do_bpf_program_free ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-30 | Christian Brauner | cgroups: bpf fixes ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
2021-01-29 | Christian Brauner | attach: init file descriptors to -EBADF ...off-by: Christian Brauner <christian.brauner@ubuntu.com> |
commit | commitdiff | tree |
next |