Ophestra cat
cat closed issue security/hakurei#4 2025-08-20 00:44:00 +09:00
Call prctl(PR_SET_PTRACER, 0); from monitor, shim, init
cat pushed to staging at security/hakurei 2025-08-20 00:44:00 +09:00
13c7083bc0 container: ptrace protection via Yama LSM
cat pushed to staging at security/hakurei 2025-08-20 00:38:53 +09:00
4ba963535d container: ptrace protection via Yama LSM
cat pushed to staging at security/hakurei 2025-08-20 00:33:10 +09:00
cf3d18c4cd container: ptrace protection via Yama LSM
cat pushed to staging at security/hakurei 2025-08-20 00:30:20 +09:00
3d004e2916 container: ptrace protection via Yama LSM
cat pushed to staging at security/hakurei 2025-08-20 00:28:23 +09:00
1ed4549b98 container: ptrace protection via Yama LSM
cat pushed to staging at security/hakurei 2025-08-19 23:39:21 +09:00
6947ff04e0 system/dbus/proc: host abstract only when not binding
cat pushed to staging at security/hakurei 2025-08-18 22:31:30 +09:00
140fe21237 container/params: check setup/receive behaviour
cat pushed to staging at security/hakurei 2025-08-18 21:30:46 +09:00
f52d2c7db6 container/path: check create and mountinfo helpers
cat pushed to staging at security/hakurei 2025-08-18 17:00:33 +09:00
3c9e547c4a cmd/hpkg: add deprecation notice
cat pushed to staging at security/hakurei 2025-08-18 16:48:09 +09:00
a3988c1a77 hst: rename net and abstract fields
cat pushed to staging at security/hakurei 2025-08-18 16:33:55 +09:00
5db0714072 container: optionally isolate host abstract UNIX domain sockets via landlock
cat pushed to netadr-landlock-lsm at security/hakurei 2025-08-18 16:28:31 +09:00
5db0714072 container: optionally isolate host abstract UNIX domain sockets via landlock
cat pushed to netadr-landlock-lsm at security/hakurei 2025-08-18 16:18:42 +09:00
75c260cd8d container: optionally isolate host abstract UNIX domain sockets via landlock
cat pushed to netadr-landlock-lsm at security/hakurei 2025-08-18 16:15:11 +09:00
ff58de323a container: optionally isolate host abstract UNIX domain sockets via landlock
cat pushed to netadr-landlock-lsm at security/hakurei 2025-08-18 14:35:56 +09:00
40028f3c03 container: optionally isolate host abstract UNIX domain sockets via landlock
cat pushed to netadr-landlock-lsm at security/hakurei 2025-08-18 12:06:23 +09:00
1fa1ea5cbb container: optionally isolate host abstract UNIX domain sockets via landlock
cat pushed to netadr-landlock-lsm at security/hakurei 2025-08-18 12:01:04 +09:00
a6b2b9df22 container: optionally isolate host abstract UNIX domain sockets via landlock
cat pushed to netadr-landlock-lsm at security/hakurei 2025-08-18 11:57:35 +09:00
2cf3077c07 container: optionally isolate host abstract UNIX domain sockets via landlock
e4801d0e23 app: set up acl on X11 socket
Compare 2 commits »
cat pushed to netadr-landlock-lsm at security/hakurei 2025-08-18 11:50:20 +09:00
c9eeafbbf0 container: optionally isolate host abstract UNIX domain sockets via landlock
2f1d42c8dd app: set up acl on X11 socket
Compare 2 commits »