Ophestra cat
cat pushed to staging at security/hakurei 2025-08-20 02:22:27 +09:00
e463faf649 container/initbind: check path equivalence by value
cat pushed to staging at security/hakurei 2025-08-20 02:14:50 +09:00
375acb476d container/autoroot: check host path equivalence by value
cat pushed to staging at security/hakurei 2025-08-20 02:05:01 +09:00
90267fadd7 container/autoroot: check host path equivalence by value
cat pushed to staging at security/hakurei 2025-08-20 02:03:23 +09:00
2666529e17 container/autoroot: check host path equivalence by value
cat pushed to staging at security/hakurei 2025-08-20 01:28:38 +09:00
c81c9a9d75 container/init: split setup ops into individual files
cat pushed to staging at security/hakurei 2025-08-20 01:26:52 +09:00
84549779e3 container/init: split setup ops into individual files
cat pushed to staging at security/hakurei 2025-08-20 01:11:35 +09:00
339e4080dc container/ops: move Op type to init file
cat pushed to staging at security/hakurei 2025-08-20 01:04:04 +09:00
e0533aaa68 container/autoroot: filter dentry with empty name
cat closed issue security/hakurei#4 2025-08-20 00:44:00 +09:00
Call prctl(PR_SET_PTRACER, 0); from monitor, shim, init
cat pushed to staging at security/hakurei 2025-08-20 00:44:00 +09:00
13c7083bc0 container: ptrace protection via Yama LSM
cat pushed to staging at security/hakurei 2025-08-20 00:38:53 +09:00
4ba963535d container: ptrace protection via Yama LSM
cat pushed to staging at security/hakurei 2025-08-20 00:33:10 +09:00
cf3d18c4cd container: ptrace protection via Yama LSM
cat pushed to staging at security/hakurei 2025-08-20 00:30:20 +09:00
3d004e2916 container: ptrace protection via Yama LSM
cat pushed to staging at security/hakurei 2025-08-20 00:28:23 +09:00
1ed4549b98 container: ptrace protection via Yama LSM
cat pushed to staging at security/hakurei 2025-08-19 23:39:21 +09:00
6947ff04e0 system/dbus/proc: host abstract only when not binding
cat pushed to staging at security/hakurei 2025-08-18 22:31:30 +09:00
140fe21237 container/params: check setup/receive behaviour
cat pushed to staging at security/hakurei 2025-08-18 21:30:46 +09:00
f52d2c7db6 container/path: check create and mountinfo helpers
cat pushed to staging at security/hakurei 2025-08-18 17:00:33 +09:00
3c9e547c4a cmd/hpkg: add deprecation notice
cat pushed to staging at security/hakurei 2025-08-18 16:48:09 +09:00
a3988c1a77 hst: rename net and abstract fields
cat pushed to staging at security/hakurei 2025-08-18 16:33:55 +09:00
5db0714072 container: optionally isolate host abstract UNIX domain sockets via landlock