Ophestra cat
cat pushed to seccomp at security/hakurei 2025-01-23 17:04:32 +09:00
134247b57d nix: configure target users via nixos
cat pushed to seccomp at security/hakurei 2025-01-23 16:08:36 +09:00
b5bb7654da nix: redirect sway output to journal
cat pushed to seccomp at security/hakurei 2025-01-22 12:09:31 +09:00
cc1efa22e2 fst: add missing fields to template
cat pushed to seccomp at security/hakurei 2025-01-22 12:01:36 +09:00
580128922b cmd/fpkg: expose syscall policy options
cat pushed to seccomp at security/hakurei 2025-01-22 11:54:22 +09:00
23e1152baa app/share: clean BaseError message
cat pushed to seccomp at security/hakurei 2025-01-22 11:50:09 +09:00
8c51012ef5 dbus: enable syscall filter
cat pushed to seccomp at security/hakurei 2025-01-22 02:01:06 +09:00
5e90b08406 dbus: enable syscall filter
cat pushed to seccomp at security/hakurei 2025-01-22 02:00:55 +09:00
5a64cdaf4f ldd: enable syscall filter
cat pushed to seccomp at security/hakurei 2025-01-22 01:59:00 +09:00
a30f5e1226 fortify: set up seccomp verbose logging early
cat pushed to seccomp at security/hakurei 2025-01-22 01:53:04 +09:00
9a239fa1a5 helper/bwrap: integrate seccomp into helper interface
cat pushed to seccomp at security/hakurei 2025-01-21 12:51:47 +09:00
82029948e6 proc: append to ExtraFiles slice pointer
cat pushed to seccomp at security/hakurei 2025-01-21 12:11:23 +09:00
dfcdc5ce20 state: store config in separate gob stream
cat pushed to seccomp at security/hakurei 2025-01-21 12:05:46 +09:00
fa0616b274 fortify: print permissive defaults warning early
cat pushed to seccomp at security/hakurei 2025-01-21 12:04:27 +09:00
a5a4160073 fortify: print permissive defaults warning early
cat pushed to seccomp at security/hakurei 2025-01-21 11:59:24 +09:00
82c483863c fortify: print permissive defaults warning early
cat pushed to seccomp at security/hakurei 2025-01-20 23:53:04 +09:00
20a3d4c458 proc/priv/shim: resolve and load seccomp rules
cat pushed to seccomp at security/hakurei 2025-01-20 23:43:52 +09:00
3df344828f proc/priv/shim: seccomp bpf filter via libseccomp
cat pushed to seccomp at security/hakurei 2025-01-20 21:17:50 +09:00
27f5922d5c fst: include syscall filter configuration
cat pushed to seccomp at security/hakurei 2025-01-20 21:10:33 +09:00
2cf1f46ea2 nix: test show without --short
cat pushed to seccomp at security/hakurei 2025-01-20 19:51:42 +09:00
3c55fc8e86 proc/priv/shim: do not log bwrap args