Ophestra cat
cat pushed to bwrap at security/fortify 2025-03-14 02:10:53 +09:00
e94b09d337 sandbox/mount: fix source flag path
cat pushed to bwrap at security/fortify 2025-03-14 00:21:34 +09:00
5d9e669d97 sandbox: separate tmpfs function from op
cat pushed to bwrap at security/fortify 2025-03-14 00:16:47 +09:00
f1002157a5 sandbox: separate bind mount function from op
cat pushed to bwrap at security/fortify 2025-03-13 21:57:59 +09:00
4133b555ba internal/app: rename init to init0
cat pushed to bwrap at security/fortify 2025-03-13 21:38:06 +09:00
9b1a60b5c9 sandbox: native container tooling
cat pushed to bwrap at security/fortify 2025-03-13 21:12:04 +09:00
9f43c2a263 sandbox: native container tooling
cat pushed to bwrap at security/fortify 2025-03-13 20:58:01 +09:00
beb3918809 test: run go test under regular user
cat pushed to bwrap at security/fortify 2025-03-13 16:40:24 +09:00
2871426df2 test: print output of failed test
cat pushed to bwrap at security/fortify 2025-03-13 16:39:27 +09:00
cat pushed to bwrap at security/fortify 2025-03-13 01:06:28 +09:00
8eef266d31 sandbox: implement native container tool
cat pushed to bwrap at security/fortify 2025-03-13 00:59:20 +09:00
60bce2f94b sandbox: implement native container tool
cat pushed to bwrap at security/fortify 2025-03-13 00:42:51 +09:00
e048f31baa internal: pull EINTR loop from stdlib
cat pushed to bwrap at security/fortify 2025-03-13 00:41:44 +09:00
6af8b8859f sandbox: read overflow ids
cat pushed to bwrap at security/fortify 2025-03-13 00:01:04 +09:00
f38ba7e923 test/sandbox: bypass fields
cat pushed to bwrap at security/fortify 2025-03-12 23:30:02 +09:00
d22145a392 ldd: handle musl static behaviour
cat pushed to bwrap at security/fortify 2025-03-12 15:52:54 +09:00
29c3f8becb helper/seccomp: improve error handling
cat pushed to bwrap at security/fortify 2025-03-12 15:21:42 +09:00
be16970e77 helper/seccomp: seccomp_load on negative fd
cat pushed to bwrap at security/fortify 2025-03-12 15:16:59 +09:00
df266527f1 test/sandbox/mount: work around nondeterminism
cat pushed to bwrap at security/fortify 2025-03-12 15:01:34 +09:00
d2c3d1bfbd test/sandbox/mount: work around /run tmpfs nondeterminism
cat pushed to bwrap at security/fortify 2025-03-12 14:12:26 +09:00
fdef9567a7 helper/seccomp: call seccomp_load on negative fd