]> git.proxmox.com Git - mirror_lxc.git/shortlog
mirror_lxc.git
2021-02-03 Stéphane GraberMerge pull request #3648 from brauner/2021-02-03/fixes
2021-02-03 Stéphane GraberMerge pull request #3649 from brauner/2021-02-03/attach...
2021-02-03 Christian Braunerattach: attach to namespaces via pidfds
2021-02-03 Christian Braunerconf: fd-only devtps setup
2021-02-03 Christian Braunerconf: fd-only pivot root
2021-02-03 Christian Braunerconf: restrict open for lxc_mount_rootfs()
2021-02-03 Christian Braunerconf: fd-only operations in lxc_setup_dev_symlinks()
2021-02-03 Christian Braunerconf: harden open in lxc_fill_autodev()
2021-02-03 Christian Braunerconf: restrict open of dev/
2021-02-03 Christian Braunerconf: remove unnecessary syscall
2021-02-03 Christian Braunerrexec: mark all fds as close-on-exec if possible
2021-02-03 Christian Braunersyscalls: add close_range()
2021-02-03 Christian Braunerrexec: check lseek() return value
2021-02-03 Christian Braunertests: check for NULL in device_add_remove
2021-02-02 Stéphane GraberMerge pull request #3647 from brauner/2021-02-02/fixes
2021-02-02 Christian Braunercgroups: improve parameter vetting
2021-02-02 Christian Braunertests: support pure unified cgroup layouts in cgpath...
2021-02-02 Christian Braunertest: add logging to device_add_remove
2021-02-02 Christian Braunerfreezer: remove lxc_cmd_freeze() and lxc_cmd_unfreeze...
2021-02-02 Christian Braunercommands: use __cgroup_unfreeze() directly
2021-02-02 Christian Braunercgroups: export __cgroup_unfreeze() for use in commands
2021-02-02 Christian Braunercgroups: use lxc_cmd_get_limiting_cgroup2_fd()
2021-02-02 Christian Braunercommands: add missing lxc_cmd_get_limiting_cgroup2_fd...
2021-02-02 Christian Braunercgpath: add logging
2021-02-02 Christian Braunerattach: explicitly close seccomp notifier fd
2021-02-02 Christian Braunercgroups: switch back to returning ints
2021-02-02 Christian Braunerattach: check for ENOCGROUP2 explicitly
2021-02-02 Christian Braunercgroups: return ENOCGROUP2 from cgroup_attach()
2021-02-02 Christian Braunercgroups: stricter argument vetting for cgroup_attach()
2021-02-02 Christian Braunercgroups: move down cgroup_attach()
2021-02-02 Christian Braunerlxccontainer: use correct error checks
2021-02-02 Christian Braunercgroups: vet parameters
2021-02-02 Christian Braunercgroups: remove unused conf argument
2021-02-02 Christian Braunercgroups: rewind() file before polling again
2021-02-02 Christian Braunerlxccontainer: use cgroup_freeze() and cgroup_unfreeze()
2021-02-02 Christian Braunerfreezer: make methods return bool
2021-02-02 Christian Braunercgroups: add cgroup_freeze() and cgroup_unfreeze()
2021-02-02 Christian Braunerfreezer: use lxc_cmd_notify_state_listeners()
2021-02-02 Christian Braunercommands_utils: add lcx_cmd_notify_state_listeners()
2021-02-02 Christian Braunercgroups: annotate cgroup_get()/cgroup_set()
2021-02-02 Christian Braunercgroups: move functions after methods
2021-02-02 Christian Braunerlxccontainer: use cgroup_set()
2021-02-02 Christian Braunerlxccontainer: use correct variable ordering
2021-02-02 Christian Braunercgroups: add croup_set()
2021-02-02 Christian Braunercgroups: reorder cgroup_get() arguments
2021-02-02 Christian Braunerlxccontainer: use cgroup_get()
2021-02-02 Christian Braunercgroups: add cgroup_get()
2021-02-02 Christian Braunerfile_utils: add lxc_read_try_buf_at()
2021-02-02 Christian Braunermacro: abuse ENOMEDIUM as ENOCGROUP2
2021-02-02 Stéphane GraberMerge pull request #3646 from brauner/2021-02-02/fixes
2021-02-02 Christian Braunercgroups: switch controller delegation to fd-only operations
2021-02-02 Christian Braunercgroups: add unified_cgroup_fd() helper
2021-02-02 Christian Braunerfile_utils: harden lxc_writeat()
2021-02-02 Christian Braunerfile_utils: harden lxc_open_dirfd()
2021-02-02 Christian Braunersyscall_wrappers: add PROTECT_OPEN_W_* variants
2021-02-02 Christian Braunermemory_utils: add close_prot_errno_mov()
2021-02-02 Christian Braunerattach: move loading seccomp as late as possible
2021-02-02 Christian Braunerattach: move file descriptor closing into attach_contex...
2021-02-02 Christian Braunerattach: stricter lookup semantics for fdopen_at() calls
2021-02-01 Stéphane GraberMerge pull request #3645 from brauner/2021-02-01/fixes_4
2021-02-01 Christian Braunerconfile_utils: use lxc_log_trace()
2021-02-01 Christian Braunerconf: use lxc_log_trace()
2021-02-01 Christian Braunercommands_utils: don't leak memory
2021-02-01 Christian Braunerattach: use correct put method
2021-02-01 Christian Braunerattach: prevent UAF
2021-02-01 Stéphane GraberMerge pull request #3644 from brauner/2021-02-01/fixes_3
2021-02-01 Christian Braunerattach: file descriptor based fdinfo handling
2021-02-01 Christian Braunerfile_utils: remove O_NOFOLLOW from open_at() defaults
2021-02-01 Christian Braunerlsm: harden read_file_at()
2021-02-01 Christian Braunertree-wide: extend read_file_at()
2021-02-01 Christian Braunerattach: harden open calls
2021-02-01 Christian Braunersyscall_wrappers: add PROTECT_LOOKUP, PROTECT_OPEN...
2021-02-01 Christian Braunerfile_utils: add open_at()
2021-02-01 Stéphane GraberMerge pull request #3642 from brauner/2021-02-01/fixes
2021-02-01 Stéphane GraberMerge pull request #3643 from brauner/2021-02-01/fixes_2
2021-02-01 Christian Braunercgroups: initialize variable
2021-02-01 Christian Braunercgroups: remove pointless NULL checks
2021-02-01 Christian Braunerattach: stash host uid and host gid in attach_context
2021-02-01 Christian Braunerattach: fix error checking for dup2()
2021-02-01 Christian Braunerattach: fix logging for stdfd replacement
2021-02-01 Christian Braunerattach: log failues to dup2() with SYSDEBUG()
2021-02-01 Christian Braunerutils: use SYSTRACE() when logging stdio permission...
2021-02-01 Christian Braunerattach: document attach_context
2021-02-01 Christian Braunerattach: simplify opening of /proc/self
2021-02-01 Christian Braunerattach: move uid and gid handling to get_attach_context()
2021-02-01 Christian Braunerattach: initialize init_pid field to -ESRCH
2021-02-01 Christian Braunerattach: unifiy /proc/<init-pid>/status parsing
2021-02-01 Christian Braunerfile_utils: add fdopenat()
2021-01-31 Stéphane GraberMerge pull request #3641 from brauner/2021-01-30/fixes
2021-01-31 Christian Braunerlsm/apparmor: cleanup apparmor_process_label_set()
2021-01-31 Christian Braunerattach: hardening through use of pidfds
2021-01-31 Christian Braunerattach: file descriptors based LSM handling
2021-01-31 Christian Braunercgroups: align methods
2021-01-30 Stéphane GraberMerge pull request #3639 from brauner/2021-01-28/fixes
2021-01-30 Christian Braunercgroups: use PTR_TO_U64()
2021-01-30 Christian Braunerattach: don't needless check for NULL
2021-01-30 Christian Braunerlog: add lxc_log_trace() helper
2021-01-30 Christian Braunercgroups: use bpf log when logging at trace level
2021-01-30 Christian Braunerseccomp: use lxc_log_get_level()
2021-01-30 Christian Braunerlog: rework lxc_log_get_level()
next