Ophestra cat
cat closed issue security/hakurei#11 2025-10-08 22:42:15 +09:00
Consider using container.Absolute in system
cat closed issue security/hakurei#3 2025-10-08 22:42:15 +09:00
Move container params building to shim
cat pushed to develop at security/hakurei 2025-10-08 22:40:12 +09:00
a40d182706 internal/app: build container state in shim
e5baaf416f internal/app: check transmitted ops
ee6c471fe6 internal/app: relocate ops condition
16bf3178d3 internal/app: relocate dynamic exported state
034c59a26a internal/app: relocate late sys/params outcome
Compare 35 commits »
cat pushed to staging at security/hakurei 2025-10-08 22:32:45 +09:00
a40d182706 internal/app: build container state in shim
cat pushed to staging at security/hakurei 2025-10-08 20:02:14 +09:00
e5baaf416f internal/app: check transmitted ops
cat pushed to staging at security/hakurei 2025-10-08 19:39:17 +09:00
ee6c471fe6 internal/app: relocate ops condition
cat pushed to staging at security/hakurei 2025-10-08 18:34:22 +09:00
16bf3178d3 internal/app: relocate dynamic exported state
cat pushed to staging at security/hakurei 2025-10-08 18:27:13 +09:00
034c59a26a internal/app: relocate late sys/params outcome
cat pushed to staging at security/hakurei 2025-10-08 18:22:38 +09:00
5bf28901a4 cmd/hsu: check against setgid bit
cat pushed to staging at security/hakurei 2025-10-08 04:57:28 +09:00
9b507715d4 hst/dbus: validate interface strings
cat pushed to staging at security/hakurei 2025-10-08 00:02:03 +09:00
12ab7ea3b4 hst/fs: access ops through interface
cat pushed to staging at security/hakurei 2025-10-07 23:56:32 +09:00
1f0226f7e0 container/check: relocate overlay escape
cat pushed to staging at security/hakurei 2025-10-07 21:38:38 +09:00
584ce3da68 container/bits: move bind bits
cat pushed to staging at security/hakurei 2025-10-07 21:29:22 +09:00
5d18af0007 container/fhs: move pathname constants
cat pushed to staging at security/hakurei 2025-10-07 20:58:04 +09:00
0e6c1a5026 container/check: move absolute pathname
cat pushed to staging at security/hakurei 2025-10-07 19:03:58 +09:00
d23b4dc9e6 hst/dbus: move dbus config struct
cat pushed to staging at security/hakurei 2025-10-07 19:01:30 +09:00
be194272d9 hst/dbus: move dbus config struct
cat pushed to staging at security/hakurei 2025-10-07 18:28:29 +09:00
3ce63e95d7 container: move seccomp preset bits
cat pushed to staging at security/hakurei 2025-10-07 17:58:33 +09:00
2489766efe hst/config: identity bounds check early
cat pushed to staging at security/hakurei 2025-10-07 04:25:09 +09:00
9e48d7f562 hst/config: move container fields from toplevel